Windows hello pin not working on a Device Joined to Azure AD for a users whose email address was changed.

69779766 0 Reputation points
2023-08-13T14:20:31.1+00:00

During the set up of a couple of computers for a client we ran into an issue. The process for setting up the computers involves joining the computer to the Azure Active Directory with a local admin account and then logging into each account and setting a windows hello pin for the users as well as the applications they need on a daily basis. A few hours into this process we realized that that one of the users had a misspelling in there Microsoft email address and we changed this in the Azure AD admin portal. Upon returning to the laptop we were able to login with the password but not the pin we had set up. We could log in with the pin if we logged in with the password first and then logged out and immediately logged back in; however, we could not log in with the pin if we logged into another users account and then tried to go back into this user which would be a much more likely scenario. We tried changing the pin, using forgot my pin, and deleting the user account locally on the laptop (using System > About > Advanced System settings > User profile Settings). We could not try to remove the pin entirely as it was greyed out in the settings and there was no option to disable windows hello without making a registry edit or using group policy which would have affected all users on this machine and each machine we had to do this on and would not have been practical to go through and reassign a new pin for over 20 users. As none of these solutions worked we ended up having to delete his account entirely in Azure AD Admin portal and recreate it from scratch. This is not an acceptable solution for the problem though as we then had to delete his account on 20 other computers and reset up his account from scratch which for reference takes about 4 hours. If we were to run into this issue again is there any know fix or suggestions for this scenario.

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
12,075 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,237 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.