Windows Hello for Business (Cloud Kerberos Trust) – sporadic PIN login failures after screen lock/unlock

Stefan Wartenberg 5 Zuverlässigkeitspunkte
2025-07-29T06:11:38.7733333+00:00

Hello,

we are encountering a recurring issue with Windows Hello for Business (WHfB) using Cloud Kerberos Trust in a hybrid Azure AD-joined environment. Despite following all best practices and implementing relevant workarounds, we are still unable to fully resolve the problem.

Problem Description

After locking the screen, users are unable to unlock using their PIN. They receive a generic "wrong PIN" message. In some cases, password login also fails or loops back to the PIN prompt. A reboot reliably resolves the issue, and the same PIN then works as expected.

Environment Details

  • Devices are Hybrid Azure AD joined

Provisioned via Windows Autopilot

Running Windows 11 24H2

Affected hardware:

Dell OptiPlex desktops (recent models)

Dell Latitude laptops (various models)

Always-On VPN (GlobalProtect) is connected at unlock time

Issue affects multiple users and hardware types, but not consistently Technical Observations After successful login, the following values are seen using dsregcmd /status: AzureAdJoined: YES NgcSet: YES AzureAdPrt: YES CloudTGT: YES OnPremTGT: YES Additional notes: Cloud Trust is enabled via Intune policy Certificate-based WHfB authentication is explicitly disabled The issue only occurs after screen lock or resume from sleep (WHfB login at boot works without issues) Event Log Entries From the Microsoft-Windows-HelloForBusiness/Operational log: Event ID 7001 Username: SYSTEM

Authentication status: 0xC000006D


CVE-2025-26647 fix applied:

   `AllowNtAuthPolicyBypass = 1` registry key on all domain controllers
   

KDC service restarted

Intune WHfB configuration verified:

Use Cloud Trust = Enabled

`Use certificate for on-premises authentication` = Disabled

Created proactive remediation script:

   Checks and refreshes the PRT if it is within 3 days of expiry
   
   WHfB keys re-registered
   
   TPM health verified (no ownership or attestation issues)
   
   VPN and network connectivity are confirmed to be available at unlock time

Has anyone else experienced this issue in a Cloud Kerberos Trust setup? Is there a way to ensure the Partial TGT is reliably available during unlock? Could this be a regression introduced in Windows 11 24H2 or related to firmware/TPM behavior? Are there any additional workarounds to avoid requiring a reboot or password login? We would appreciate any advice, confirmation of similar behavior, or further troubleshooting recommendations. Thanks in advance for your support. Edit: Just had the issue again with a colleague – even after re-registering WHfB and fully resetting the setup, the PIN was still rejected. This time we received error code ending in 0xC000005E, which indicates STATUS_NO_LOGON_SERVERS – meaning the device was unable to contact a domain controller at the time of unlock. This confirms that the problem can still occur even on clean setups, and may be related to network timing or DC reachability, despite Always-On VPN being active.

Windows für Unternehmen | Windows-Client für IT-Profis | Verzeichnisdienste | Benutzeranmeldung und -profile
0 Kommentare Keine Kommentare

Ihre Antwort

Antworten können von Fragestellenden als „Angenommen“ und von Moderierenden als „Empfohlen“ gekennzeichnet werden, wodurch Benutzende wissen, dass diese Antwort das Problem des Fragestellenden gelöst hat.