Windows Hello for Business Container Load Failure

Kevin Cooke 5 Reputation points
2026-10-08T18:29:45.43+00:00

OS: Windows 11 Enterprise 25H2, build 26200.9457

Hardware: HP EliteBook 6 G1i 14 inch Notebook AI PC

Primary error: 0xD000A002

This computer model intermittently fails to load its Windows Hello for Business container during boot. Failed boots record ProtectorDiskIo Event 5701 with PIN=False and Recovery=False, followed by ContainerLoad Event 7002 with error 0xD000A002. Working boots traverse the same path with PIN=True and Recovery=True.

Boot-time RPC ETW and WinDbg public-symbol disassembly isolate the first confirmed A/B difference to c_NgcIsoContainerImportBuffer (OpNum 0x0B). Preceding CreateBuffer, ImportData, and OpenContainer RPC calls succeed in both traces.

Same user on a different model of HP Elitebook does not run into issues. Different users on 4 different HP EliteBook 6 G1i 14 inch Notebook AI PC intermittently experience this issue. Same settings to all computers via GPO.

We have already attempted certutil -deletehellocontainer, deleting the NGC folder, and wiping and re-imaging the computers. The intermittent error returns regardless.

Troubleshooting was done with the help of Co-Pilot, as was this summary, so excuse the potential AI Slop.

Hoping either someone has seen this before, or someone on the Microsoft side sees it and can direct the appropriate people to it. We are attempting to open an MS case, but it's not been a fun process. Our CSP is dragging their feet doing it, and we can't purchase a support case from MS as the purchase window doesn't allow the use of a business credit card on a personal microsoft account, and it says my M365 account cannot purchase any.

System and build details

Manufacturer / model: HP / HP EliteBook 6 G1i 14 inch Notebook AI PC

BIOS: X74 Ver. 01.05.03; release date 13 July 2026

TPM manufacturer / firmware: Nuvoton Technology; NTC; ManufacturerId 1314145024; firmware 7.2.4.1

TPM specifications: TPM 2.0; PPI 1.3

TPM operational state: Present, Ready, Enabled, Activated, Owned; no restart pending

TPM provisioning: AutoProvisioning Enabled; ManagedAuthLevel Full; OwnerClearDisabled=False

TPM lockout: LockedOut=False; LockoutCount=0; LockoutMax=31; heal time 10 minutes

WHfB container service: NgcCtnrSvc hosted in svchost.exe

GOOD process/thread: PID 7172 / TID 7656

FAIL process/thread: PID 6320 / TID 6368

Container ID: 588ee5d9-f533-4825-acd7-f687c562749a

Reproduction and impact

·         Failure occurs intermittently during boot on the same device.

·         Failed boot prevents the Windows Hello PIN protector from becoming available.

·         A PIN reset, NGC reset, or TPM reset may destroy the state needed for product-group analysis; guidance is requested before remediation.

Key A/B evidence

RPC call sequence

Method OpNum GOOD FAIL

c_NgcIsoCreateBuffer 0x09 0x00000000 0x00000000

c_NgcIsoImportData 0x0A 0x00000000 0x00000000

c_NgcIsoOpenContainer 0x00 0x00000000 0x00000000

c_NgcIsoContainerImportBuffer 0x0B 0x00000000 0xD000A002

c_NgcIsoCloseContainer 0x05 0x00000000 0x00000000

c_NgcIsoCloseBuffer 0x0E 0x00000000 0x00000000

WinDbg method mapping

Public-symbol disassembly maps OpNum 0x0B directly to the generated RPC client stub:

NgcIsoCtnr!c_NgcIsoContainerImportBuffer    

lea     edx,[r8+0Bh]    

call    qword ptr [NgcIsoCtnr!_imp_NdrClientCall3]

Failed boot timeline

Trace time Evidence

110.3929660 s RPC Start: NgcTrustletChannel OpNum 0x0B

110.3943043 s RPC EEINFO contains 0xD000A002

110.3943210 s RPC Stop status 0xD000A002

110.3943256 s RpcRaiseException status 0xD000A002

110.3967415 s Event 5701: PIN=False; Recovery=False

110.5582063 s Event 7002: 0xD000A002

Working boot control

109.6968608 s RPC Start: NgcTrustletChannel OpNum 0x0B

109.6978810 s RPC Stop status 0x00000000

Following protector result Event 5701 reports PIN=True; Recovery=True

Persisted-state comparisons

·         TPM SRK public blob remained 283 bytes with SHA-256 f82b7a82924df4096d7763e81645fe4f1825a1152ef4ee270e12c86f4d81d4a1 across compared GOOD and FAIL captures.

·         SYSTEM-context comparisons found Container.json, Protectors.json, and the targeted Keys*.json files byte-identical between known-good and failed boots.

·         No claim is made about trustlet-private transient state because it is not exposed by these artifacts.

Available evidence

Artifact Purpose

Failed RPC-enabled boot ETL Contains failing OpNum 0x0B plus Events 5701/7002.

Working RPC-enabled boot ETL Control where OpNum 0x0B succeeds.

Focused GOOD/FAIL RPC exports Compact call-level evidence.

WinDbg stub log Public-symbol mapping of OpNums to client stubs.

SRK captures Stable SRK blob hash comparison.

NGC file hash comparison Byte-level persisted-file control.

Custom RPC-enabled WPRP Reproduction profile.

Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Allan Solomon Mejia 10,385 Reputation points
    2026-10-08T20:29:12.9066667+00:00

    Hi @Kevin Cooke

    Your A/B evidence narrows this well beyond a normal PIN-provisioning problem. The first confirmed failure occurs while Windows is importing the persisted Hello container into the isolated NgcIso environment. Microsoft documents that the Hello container holds the user’s key material and that hardware-backed keys are protected by the TPM.

    Given that:

    • Multiple users are affected on four units of the same HP model.
    • The same users and policies work on a different EliteBook model.
    • Reimaging and container recreation don’t prevent recurrence.
    • TPM status appears healthy outside the failed boot.
    • Persisted container files and the TPM SRK blob remain unchanged between working and failed boots.

    the evidence points toward an intermittent platform-specific interaction involving Windows, the TPM/firmware stack, or the isolated Hello container-loading path. This is an inference from the supplied evidence, not a confirmed Microsoft root cause.

    There's no verified Microsoft documentation mapping 0xD000A002 from c_NgcIsoContainerImportBuffer, or Events 5701/7002 in this specific sequence, to a documented customer-correctable condition. It also doesn’t match any currently documented Windows Hello for Business deployment issue.

    I agree that further container deletion, NGC-folder removal, TPM clearing, or reimaging should be paused on at least one affected device. Those actions recreate or remove the credential state Microsoft would need to examine.

    For escalation, provide Microsoft and HP with:

    • A working and failed boot trace from the same device.
    • The RPC EEINFO and the exact c_NgcIsoContainerImportBuffer failure.
    • Events 5701 and 7002 with timestamps and full event XML.
    • BIOS, TPM firmware, Windows build, and installed driver versions.
    • Persisted-state hashes from the working and failed boots.
    • Confirmation that four identical systems reproduce the issue while another EliteBook model doesn’t.
    • Whether changing only the BIOS or TPM firmware changes the reproduction rate.

    Microsoft confirms that the TPM is used to protect Windows Hello for Business credentials, so opening a parallel HP enterprise case for BIOS/TPM firmware analysis is appropriate.

    This appears to require Microsoft product-group and OEM engineering analysis. I don't recommend another generic PIN reset as the primary remediation because you’ve already demonstrated that recreating the container doesn’t prevent the failure.

    References:

    How Windows Hello for Business works

    Windows Hello for Business known deployment issues

    TPM recommendations


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.