Windows Hello for apps/passkeys randomly defaults to fingerprint instead of face — login screen has no such issue

ChrisSchroeder-3270 61 Reputation points
2026-07-26T10:54:30.7733333+00:00

On Windows 11, Windows Hello at the PC login/lock screen works correctly and consistently — it always defaults to face recognition (camera) first, every time, without fail.

However, when Windows Hello is used for authentication inside applications (password managers, browsers, Okta, or any app using the Windows Security "Sign in with Windows Hello or security key" / WebAuthn passkey prompt), the behavior is inconsistent:

  • Sometimes it defaults to face
    • Sometimes it defaults to fingerprint
      • It does not consistently follow the last-used method
        • This happens across all apps that use this prompt, not just one specific app, so it is not an app-side issue
          • Both face and fingerprint work fine individually when manually selected, so this is not a hardware or enrollment problem — the issue is purely which one the OS chooses to present by default
        • This has been reported by multiple people going back to at least 2023 (e.g. a Microsoft Q&A thread now locked: https://learn.microsoft.com/en-us/answers/questions/4143535/default-authentication-choice-of-windows-security), with a response suggesting it may be by design, but no official fix or documented setting has been provided since.
      • I'm running Windows 11 Pro on my own personal PC — it's not joined to a domain or managed by any company/corporate group policy. Login authentication has worked reliably for years, always defaulting to face, which is exactly the behavior I want (I can still manually choose fingerprint when I want to). I'd just like that same behavior everywhere Windows Hello is used, not only at login.
    • Is there a supported way to set face as the default for the app/passkey prompt specifically, matching the reliability of the lock screen?
Windows for home | Windows 11 | Security and privacy
0 comments No comments

1 answer

Sort by: Most helpful
  1. Lychee-Ng 26,035 Reputation points Microsoft External Staff Moderator
    2026-07-27T08:39:20.63+00:00

    Hi ChrisSchroeder-3270,

    I totally understand how confusing it feels when app and passkey prompts seem to choose Windows Hello methods inconsistently, while sign-in is working normal. However, as you've likely already discovered from your research, there is currently no known supported way to force Face Recognition as the default method.

    One possible explanation for this behavior is that lock screen prioritizes Face recognition consistently because it follows the system order in Settings > Accounts > Sign-in options. Meanwhile, the passkey / WebAuthn dialog uses external authentication path, so they don't always follow that same ordering and appear inconsistent.

    There is also community theory that since most modern consumer PCs natively support either an IR camera or a fingerprint reader, Windows may not have been optimized for devices that offer multiple biometric options. However, some users also reported that actually all three were available, even if only one shown, so you can try:

    1. Move your face in front of the camera during passkey request to see if it still triggers Face recognition.
    2. Remove both Face Recognition and Fingerprint then restart your PC. Re-add Fingerprint, then Face Recognition.
    3. Test with the vice versa: setting up only Facial Recognition and using it for a few days before re-enrolling Fingerprint.

    If the behavior remains the same throughout every scenario, I think it's best to submit your request through Feedback Hub (Win + F). Clearly explain your idea about a setting to choose the preferred Windows Hello method, including the details you've shared above, and screenshots/recording if possible.

    I know this is not the definite answer you're looking for, but Microsoft has not published a document on this specific mechanism. Unfortunately, since Microsoft Q&A is just a community forum and contributors are fellow users, we don't have access to internal processes and back-end documents to confirm a reason or solution.


    If you think the answer is helpful to you, please click "Yes" below. If you have extra questions about this answer, feel free to click "Add Comment" and ask! 

    Note: Follow the steps in our documentation if you want to enable and receive the related email notifications for this thread.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.