Windows Hello for Business (Cloud Kerberos Trust) – sporadic PIN login failures after screen lock/unlock
Hello,
we are encountering a recurring issue with Windows Hello for Business (WHfB) using Cloud Kerberos Trust in a hybrid Azure AD-joined environment. Despite following all best practices and implementing relevant workarounds, we are still unable to fully resolve the problem.
Problem Description
After locking the screen, users are unable to unlock using their PIN. They receive a generic "wrong PIN" message. In some cases, password login also fails or loops back to the PIN prompt. A reboot reliably resolves the issue, and the same PIN then works as expected.
Environment Details
- Devices are Hybrid Azure AD joined
Provisioned via Windows Autopilot
Running Windows 11 24H2
Affected hardware:
Dell OptiPlex desktops (recent models)
Dell Latitude laptops (various models)
Always-On VPN (GlobalProtect) is connected at unlock time
Issue affects multiple users and hardware types, but not consistently
Technical Observations
After successful login, the following values are seen using dsregcmd /status:
AzureAdJoined: YES
NgcSet: YES
AzureAdPrt: YES
CloudTGT: YES
OnPremTGT: YES
Additional notes:
Cloud Trust is enabled via Intune policy
Certificate-based WHfB authentication is explicitly disabled
The issue only occurs after screen lock or resume from sleep (WHfB login at boot works without issues)
Event Log Entries
From the Microsoft-Windows-HelloForBusiness/Operational log:
Event ID 7001
Username: SYSTEM
Authentication status: 0xC000006D
CVE-2025-26647 fix applied:
`AllowNtAuthPolicyBypass = 1` registry key on all domain controllers
KDC service restarted
Intune WHfB configuration verified:
Use Cloud Trust = Enabled
`Use certificate for on-premises authentication` = Disabled
Created proactive remediation script:
Checks and refreshes the PRT if it is within 3 days of expiry
WHfB keys re-registered
TPM health verified (no ownership or attestation issues)
VPN and network connectivity are confirmed to be available at unlock time
Has anyone else experienced this issue in a Cloud Kerberos Trust setup?
Is there a way to ensure the Partial TGT is reliably available during unlock?
Could this be a regression introduced in Windows 11 24H2 or related to firmware/TPM behavior?
Are there any additional workarounds to avoid requiring a reboot or password login?
We would appreciate any advice, confirmation of similar behavior, or further troubleshooting recommendations. Thanks in advance for your support.
Edit: Just had the issue again with a colleague – even after re-registering WHfB and fully resetting the setup, the PIN was still rejected. This time we received error code ending in 0xC000005E, which indicates STATUS_NO_LOGON_SERVERS – meaning the device was unable to contact a domain controller at the time of unlock.
This confirms that the problem can still occur even on clean setups, and may be related to network timing or DC reachability, despite Always-On VPN being active.