Hi @Kevin Cooke
Your A/B evidence narrows this well beyond a normal PIN-provisioning problem. The first confirmed failure occurs while Windows is importing the persisted Hello container into the isolated NgcIso environment. Microsoft documents that the Hello container holds the user’s key material and that hardware-backed keys are protected by the TPM.
Given that:
- Multiple users are affected on four units of the same HP model.
- The same users and policies work on a different EliteBook model.
- Reimaging and container recreation don’t prevent recurrence.
- TPM status appears healthy outside the failed boot.
- Persisted container files and the TPM SRK blob remain unchanged between working and failed boots.
the evidence points toward an intermittent platform-specific interaction involving Windows, the TPM/firmware stack, or the isolated Hello container-loading path. This is an inference from the supplied evidence, not a confirmed Microsoft root cause.
There's no verified Microsoft documentation mapping 0xD000A002 from c_NgcIsoContainerImportBuffer, or Events 5701/7002 in this specific sequence, to a documented customer-correctable condition. It also doesn’t match any currently documented Windows Hello for Business deployment issue.
I agree that further container deletion, NGC-folder removal, TPM clearing, or reimaging should be paused on at least one affected device. Those actions recreate or remove the credential state Microsoft would need to examine.
For escalation, provide Microsoft and HP with:
- A working and failed boot trace from the same device.
- The RPC EEINFO and the exact c_NgcIsoContainerImportBuffer failure.
- Events 5701 and 7002 with timestamps and full event XML.
- BIOS, TPM firmware, Windows build, and installed driver versions.
- Persisted-state hashes from the working and failed boots.
- Confirmation that four identical systems reproduce the issue while another EliteBook model doesn’t.
- Whether changing only the BIOS or TPM firmware changes the reproduction rate.
Microsoft confirms that the TPM is used to protect Windows Hello for Business credentials, so opening a parallel HP enterprise case for BIOS/TPM firmware analysis is appropriate.
This appears to require Microsoft product-group and OEM engineering analysis. I don't recommend another generic PIN reset as the primary remediation because you’ve already demonstrated that recreating the container doesn’t prevent the failure.
References:
How Windows Hello for Business works
Windows Hello for Business known deployment issues
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.