Slow login issue after PIN setup when windows hello for business is enabled.

53716208 41 Reputation points
2020-12-10T12:39:29.287+00:00

Hi,

I have deployed and configured Windows Hello for Business -On Premises Certificate Trust for one customer on their Internal Only Network.
.
The infrastructure details are as follows:

  1. AD 2016 Domain Controllers.
  2. AD schema is Windows Server 2016.
  3. AD CS with windows server 2016.
  4. 2 x Windows Server 2019 AD FS with Certificate Authentication as MFA. Certificate used for ADFS is issued from Internal CA.
  5. Windows 10 1803 or above clients.

The Pilot users is able to setup the PIN and is able to login with the PIN when enabled for WHFB. All the Pilot users when login using PIN gets a delays for about 30 to 60 seconds as compared to normal password login which is approximately 3 to 4 seconds.

Please note that we are using Internal PKI Certificate as an additional Authentication method as MFA with ADFS.

Need guidance to troubleshoot the slow PIN login issues or is this the expected behavior?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,432 questions
Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,361 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,801 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,744 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,712 questions
0 comments No comments
{count} votes

1 additional answer

Sort by: Most helpful
  1. Petr Vones 41 Reputation points
    2020-12-10T13:34:51.783+00:00

    Probably unrelated but the same issue had happend on my personal tablet device (Windows Home) after upgrade from Windows 8.1 to 10. Unlocking by PIN took at least 20 seconds. I had to perform TPM clear to resolve it.

    0 comments No comments