Tech Entertainer

Windows Hello PIN Not Working After Every Reboot? Fix the KB5121003 Bug

By Tech Entertainer Team · 2026-08-18

Windows Hello PIN Not Working After Every Reboot? Fix the KB5121003 Bug

Why Does Windows Hello PIN Stop Working After Every Reboot on Windows 11?

Windows 11's August 2026 cumulative update, KB5121003 (OS builds 26200.9168 and 26100.9168), broke PIN credential storage for some users. After you restart, Windows drops the enrolled PIN and asks you to set it up again from scratch, every single time.

This started showing up within days of the update's August 11, 2026 release. Reports point to a change in how KB5121003 handles the Trusted Platform Module credential cache, the storage Windows Hello relies on to keep your PIN valid between sessions. Instead of reading the stored credential on boot, affected systems treat it as missing and fall back to first-time setup.

Not every PC hits this bug. It shows up more often on machines using a discrete TPM or a firmware TPM, updated with a new driver around the same patch cycle. If your PIN worked fine before August 11 and now demands re-enrollment after every restart, KB5121003 is the most likely cause.

Dell, Lenovo, and HP laptops with firmware TPM (fTPM) enabled in the BIOS show up most often in user reports so far. Desktop PCs with a discrete TPM chip on the motherboard report the bug less frequently, though it still happens. Knowing which TPM type your PC uses helps you gauge whether you're likely to hit this bug on future reboots too.

How Do I Sign In If My PIN Won't Work?

Use your Microsoft account password or, if you have one set up, Windows Hello face or fingerprint recognition. Both bypass the broken PIN check entirely and get you to the desktop normally.

At the lock screen, look for "Sign-in options" below the password field, the small link with a key or fingerprint icon. Select the key icon for password entry. If your webcam or fingerprint reader still works, it signs you in without touching the PIN at all. From there, decide whether to re-enroll the PIN right away or wait for a fix and skip the reboot hassle for a few days.

How Do I Re-Enroll My Windows Hello PIN?

Go to Settings, then Accounts, then Sign-in options, and select PIN (Windows Hello). Click "Set up" and follow the prompts to verify your identity and create a new PIN.

Here's the exact path:

  • Open Settings (Windows key + I)
  • Select Accounts
  • Select Sign-in options
  • Select PIN (Windows Hello) from the list
  • Click "I forgot my PIN" if a broken PIN is still listed, or "Set up" if none is
  • Verify with your Microsoft account password
  • Enter and confirm a new PIN

This takes under a minute once you're through it, but you'll repeat it after every restart until Microsoft ships a fix or you apply one of the workarounds below.

How Do I Stop Windows From Asking for a PIN Every Time?

Yes. Turn off Windows Hello PIN sign-in entirely from Settings, then Accounts, then Sign-in options, and set "PIN (Windows Hello)" to Remove. Windows falls back to your account password at every sign-in instead.

This is the fastest way to stop the repeated re-enrollment prompt if you don't want to deal with it until a patch arrives:

  1. Settings, then Accounts, then Sign-in options
  2. Select PIN (Windows Hello)
  3. Click Remove
  4. Confirm with your Microsoft account password

You lose the convenience of a short PIN, but you stop seeing the setup screen on every boot. Re-add the PIN later once Microsoft resolves the underlying bug.

Should I Check for a Newer Update Before Doing Anything Else?

Yes, check first. Microsoft has a track record of patching Windows Hello regressions with a follow-up cumulative update within two to four weeks of the original release.

Open Settings, then Windows Update, and click "Check for updates." If a build newer than 26200.9168 or 26100.9168 is available, install it and restart. Confirm your PIN survives a second and third reboot before assuming the bug is gone, since some early follow-up patches for Windows Hello issues in past cycles only partially fixed the problem on the first try.

Is Uninstalling KB5121003 Worth It?

Uninstalling removes the bug along with every security fix and feature in the update, so treat it as a last resort. KB5121003 shipped over 400 security fixes, and rolling it back leaves those unpatched until you reinstall a later cumulative update.

If the repeated PIN prompt disrupts work you don't want to put off, here's how to uninstall it:

  • Settings, then Windows Update, then Update history
  • Scroll to "Uninstall updates"
  • Find KB5121003 in the list
  • Click Uninstall and confirm
  • Restart your PC

Windows Update will try to reinstall KB5121003 again on its next scheduled check unless you pause updates temporarily. Go to Settings, then Windows Update, and use "Pause updates for 1 week" to buy time before Microsoft's fix lands, then resume updates and install whatever cumulative update comes after KB5121003.

What About Windows Hello Face or Fingerprint Sign-In?

Most reports show these methods staying unaffected by this specific bug. If your PC has a fingerprint reader or IR camera, switch to it as your primary sign-in method while the PIN issue gets sorted out.

Go to Settings, then Accounts, then Sign-in options, and set up Face Recognition or Fingerprint under Windows Hello if you haven't already. Both store credentials separately from the PIN's TPM cache, so they keep working through the reboots breaking PIN sign-in.

Why Does This Keep Happening on Some PCs and Not Others?

The pattern points to TPM firmware timing, not a universal Windows Hello failure. Machines where the TPM initializes after the credential provider checks for a stored PIN come up empty on boot, so Windows treats the account as never enrolled.

Laptop makers push their own firmware updates on separate schedules from Microsoft's patch cycle. When a BIOS or TPM firmware update lands close to KB5121003, the two changes interact in a way neither vendor tested against. This is a common source of driver-timing bugs after any large Windows update, and it explains why some users on the same Windows build see nothing wrong while others hit the PIN reset every reboot.

If you recently updated your BIOS, graphics drivers, or any security software touching credential storage (password managers with Windows Hello integration, for example), this combination is worth flagging in a Feedback Hub report. Open the Feedback Hub app, search "Windows Hello PIN," and add your device model and TPM type to an existing report rather than filing a duplicate. Microsoft's engineering teams prioritize bugs by report volume tied to a specific configuration, so a detailed report speeds up the fix.

Quick Checklist

  • Sign in with your Microsoft account password or Face/Fingerprint if your PIN fails
  • Re-enroll the PIN through Settings, Accounts, Sign-in options if you want to keep using it short-term
  • Remove PIN sign-in entirely if the repeated prompt is too disruptive
  • Check Windows Update for a build newer than 26200.9168 or 26100.9168
  • Uninstall KB5121003 only if you need the PIN working immediately and won't wait for a patch, and pause updates afterward so it doesn't reinstall right away

Most people affected by this bug get through it fine using their account password until Microsoft ships the fix. The re-enrollment step is annoying, not dangerous, so there's no urgency to uninstall a security update over it unless the interruption is genuinely blocking your work.

Frequently Asked Questions

Will Microsoft fix the KB5121003 PIN bug automatically?

Likely, through a follow-up cumulative update. Microsoft has patched similar Windows Hello regressions within a few weeks in past cycles. Check Settings, then Windows Update, for a newer update than KB5121003 (OS build 26200.9168 or 26100.9168) before trying more involved fixes.

Does re-enrolling my PIN every reboot put my account at risk?

No. Re-enrollment only confirms your identity again through your Microsoft account password or another Windows Hello method already on file. It does not weaken your account security, it adds an annoying extra step until the underlying bug gets patched.