How to Fix Windows Hello for Business error code 0x80090010

Zack 10 Reputation points
2025-08-04T09:45:12.9033333+00:00

We have been having issues when new users (some old users) try to add their Face Recognition and PIN for windows hello it comes up with this error message.

User's image

I have done research and it says it is caused by the July 2025 Windows Update, so I uninstalled that then I cleared the tpm. It worked for a while however it then started happening again after an hour. Is there any fix for this yet?

Windows for business | Windows 365 Business
{count} votes

4 answers

Sort by: Most helpful
  1. Oliveri Michaël 16 Reputation points
    2025-09-03T10:01:18.45+00:00

    On my side this link https://www.ibm.com/support/pages/node/7241360 given by @Chen Tran resolved my problem.

    Thanks.

    2 people found this answer helpful.

  2. Chen Tran 4,785 Reputation points Independent Advisor
    2025-08-05T10:42:12.9766667+00:00

    Hello Zack,

    Thank you for posting question on Microsoft Windows Forum.

    Based on your issue description as well as the provided error code 0x80090010 which typically translates to NTE_PERM and indicates a permissions issue with the cryptographic key container. In this context, the July 2025 update appears to cause a corruption or otherwise prevents Windows from properly accessing the Ngc (Next Generation Cryptography) folder, which is where PIN and biometric data are securely stored. Clearing the TPM or the Ngc folder forces a recreation of this container, which works until the faulty update logic interferes again.

    Your action of uninstalling the update and clearing the TPM provides a temporary fix because it removed the trigger (the faulty update) and reset the security container. The reason it failed after an hour is highly probably of because Windows automatically reinstalled the problematic update in the background. The following steps are a temporary workaround for the issue.

    1.Pause Windows Updates.

    1. Go to Settings > Update & Security > Windows Update.
    2. Click on Advanced options.
    3. Under the Pause updates section, select a date as far into the future as possible (usually up to 35 days). This will give Microsoft time to release a fix, which typically arrives with the next month's "Patch Tuesday" update.

    2.Uninstall the Problematic Update.

    • If the update has reinstalled itself, you need to remove it again.
    1. In Settings > Update & Security > Windows Update, click View update history.
    2. Click Uninstall updates.
    3. In the Control Panel window that opens, look for the update installed in July 2025. It will likely be named "Security Update for Microsoft Windows (KBXXXXXXX)" or "Cumulative Update for Windows (KBXXXXXXX)".
    4. Select it and click Uninstall.
    5. Restart your computer when prompted.

    By pausing your updates for a few weeks, you allow time for the official permanent fix to be released from Microsoft. Once you hear news that a patch is available, you can resume updates and install the new (fixed) cumulative update. You can check for news on the Windows Release Health dashboard or major tech news sites.

    You can refer to the following article for more information regarding the error code.

    Hope the above information is helpful!

    1 person found this answer helpful.

  3. Zack 10 Reputation points
    2025-08-19T08:34:52.2266667+00:00

    I found a fix,

    1. Go to Reg Editor go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Policies.
    2. Create a key called "PassportForWork" (if already there go to Step 6) Within the key create a new DWORD called UserPassportForWork
    3. Restart the computer.
    4. Once logged in, access Regedit again and check whether additional folders, such as eg, s1-5-3.. were created.
    5. If this is the case. Remove the DWORD called UserPassportForWork from the PassportForWork Access each of the subkeys created in PassportForWork and then access the key named “Policies” in each of them.
    6. For each of the keys, alter the UserPassportForWork in all Folders under Policies value from 0 to 1. Make sure to also do Device>Policy as well, which should then properly set up the Windows Hello PIN and Camera.
    7. Then make the user a Local Administrator by going to “Computer Management” (run as administrator)
    8. Then Reboot, and check if you can add the users Windows Hello. If so then remove the local administrator rights to the user.
    9. If still not working Repeat step 6 but logged in with the Users account, reboot then try again.
    1 person found this answer helpful.

  4. sumesh 0 Reputation points
    2025-08-13T06:15:40.3266667+00:00

    In the July patch, the tenant wide WHfB settings seems to take precedence over the user CSP WHfB policies. Even if WhfB is enabled via the user CSP, the global setting to disable WhfB will block pin setup. To Fix: Configure WHfB using the device CSP policy instead of the use CSP

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.