Windows Hello Business not working after DC upgrade to 2025
Hello, we upgraded all DCs to Win Server 2025 and after that update the domain structure from 2016 to 2025. It was a mix of 2019 and 2022 DCs. All of them were updated via inplace upgrade to 2025. Everything went smooth and after the update everything worked... But after we updated the domain structure to 2025 Windows Hello for business just doesnt work anymore.... cant login with fingerprint, face or pin anymore. Password of course still works.
Did somebody here also experience problems like that upgrading to 2025 DCs? Or has any tips how to fix it. Didn't find much about this problem except an article about KB5062553. But it should have been fixed by KB5060842 mentioned in this artivle if i see it correctly https://dori-uw-1.kuma-moon.com/en-us/windows/release-health/resolved-issues-windows-server-2025
I already tried to remove the AzureADKerberos computer account and add it back but it did nothing. (windows hello is configured with cloud trust to entra)
The error you get if you try to login with windows hello is: Login information could not be verified.
And the very weird thing is after trying to login with windows hello no other authentication methods works anymore (nothing happens if you press enter after inputting the password) the shutdown button also vanishes and the computer restarts itself after 1-2min. After restart the login works again with password but if you try windows hello again the same thing happens again
On the DCs i see this error in the Event Viewer:
Windows Hello for Business provisioning has encountered an error during policy evaluation. ExitCode: The RPC server is unavailable. Method: LsaGetSSOAccountType See https://go.microsoft.com/fwlink/?linkid=832647 for more details
Windows hello is as Kerberos Cloud trust configured and it was setup the same as in these articles:
All new Windows Updates are installed on the DCs and Client.
Anyone has any idea how to fix?
Windows for business | Windows Server | Directory services | User logon and profiles
1 answer
Sort by: Most helpful
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more