Windows Hello

Windows Hello works well right up until it doesn’t.

A user opens Settings → Accounts → Sign-in options, and the facial recognition and fingerprint options are greyed out with a single unhelpful line:

This option is currently unavailable.

Windows Hello

No error code. No indication of what changed. Just a user who can no longer sign in the way they have for the last six months.

The cause can be anything from a Windows update to a corrupted credential store to a Group Policy setting somebody changed three weeks ago. In my case, it turned out to be a misconfigured Group Policy setting, which is why that’s the first thing I check now rather than the last.

This article lists the fixes that work, in the order I’d actually try them.

Which one should you try first?

Someone asked me this in the comments years ago and the original version of this article never answered it properly, so here is the order I use.

  1. Check Group Policy if the device is domain joined or managed. This is the most common cause in a corporate environment and it’s the quickest to rule out.
  2. Delete the Hello container if the device is standalone, or if Group Policy looks correct. This fixes the majority of credential-corruption cases.
  3. Reset the biometric database if the PIN works but facial recognition or fingerprint doesn’t.
  4. Reinstall the camera or fingerprint drivers if the hardware isn’t appearing correctly in Device Manager.
  5. Turn off Fast Startup if the problem keeps coming back after a shutdown.

If you’re troubleshooting a single machine, start at 2. If you’re troubleshooting several machines at once, start at 1, because a policy change is far more likely than several devices corrupting at the same time.

Judging by the comments on this article over the years, Group Policy is the fix that resolves it for most people.

1. Check the Group Policy settings

If the device is domain joined or managed, this is where I’d start.

A policy change can disable biometrics without any obvious symptom other than the greyed-out option.

Opening the Group Policy Editor

Several readers have asked how to get to these settings, so before the policy list itself.

Press Win + R, type gpedit.msc and press Enter.

If you get an error saying Windows cannot find gpedit.msc, you’re running Windows Home, which doesn’t include the Group Policy Editor. The equivalent settings can be applied through the registry instead, or the device needs a Pro licence.

If the machine is domain joined, be aware that a local policy change can be overwritten at the next policy refresh. In that case the change belongs in the domain GPO, not in local policy.

The settings to check

Microsoft documents the full set in Windows Hello for Business policy settings. These are the ones that matter for this error.

Convenience PIN sign-in

Computer Configuration → Administrative Templates → System → Logon → Turn on convenience PIN sign-in = Enabled

Windows Hello for Business

Computer Configuration → Administrative Templates → Windows Components → Windows Hello for Business → Use biometrics = Enabled

Computer Configuration → Administrative Templates → Windows Components → Windows Hello for Business → Use Windows Hello for Business = Not configured

Biometrics

Computer Configuration → Administrative Templates → Windows Components → Biometrics → Allow the use of biometrics = Enabled

Computer Configuration → Administrative Templates → Windows Components → Biometrics → Facial Features → Configure enhanced anti-spoofing = Disabled

Two settings worth understanding

Use Windows Hello for Business. Setting this to Enabled changes the whole enrolment model, because it switches the device to certificate or key-based Windows Hello for Business rather than the simpler convenience PIN and biometric sign-in. If you only want biometric sign-in working and aren’t deploying Windows Hello for Business properly, leave it Not configured.

Enhanced anti-spoofing. This requires the camera to support the feature. On hardware that doesn’t, enabling it can make facial recognition unavailable rather than more secure. Check whether the device’s IR camera actually supports it before turning it on.

Confirm what’s actually applying

Run this from an elevated command prompt:

gpresult /h C:\temp\gpresult.html

Open the resulting file and look at the applied policies rather than trusting what you think the GPO says. A policy from a different OU may be winning.

2. Delete the Hello container

This is the fix for a corrupted credential store, and it’s the one that resolves most single-device cases.

The supported way

Run this as the affected user, not as an administrator:

certutil.exe -deleteHelloContainer

Then sign out and back in.

This removes the user’s Windows Hello credentials cleanly. It’s considerably safer than working directly with the folder, and it’s what I’d use first on any modern build. Microsoft documents it in the Windows Hello for Business FAQ.

Two things to know before you run it.

It removes the Hello container for the user running the command, not for the machine. If several users share the device, each one needs to run it under their own account.

It also removes any passkeys stored in the Windows Hello container. If the user has saved passkeys for websites or applications, those go too and will need to be set up again. Worth mentioning to them first.

The manual method

If certutil doesn’t resolve it, the Ngc folder can be dealt with directly. This is the original fix and it still works.

First, make the folder visible:

  1. Open Control Panel → File Explorer Options.
  2. On the View tab, under Advanced Settings, select Show hidden files, folders and drives.
  3. On the same tab, untick Hide protected operating system files.

Now browse to this path in File Explorer:

C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft

Then take ownership of the Ngc folder:

  1. Right-click the Ngc folder and choose Properties.
  2. Go to the Security tab and click Advanced.
  3. At the top, next to Owner, click Change.
  4. In the From this location field, make sure it shows the computer name. Click Locations to change it if not.
  5. In Enter the object name to select, type Administrators, click Check Names, then OK.
  6. Tick Replace owner on subcontainers and objects, then click Apply and OK.

Now, a practical point that took me a while to work out.

Some of the contents cannot be deleted regardless of ownership. Rather than fighting it, rename the folder instead. Change Ngc to Old_Ngc, then create a new empty folder named Ngc alongside it.

Reboot. After the restart, the sign-in options should let you create a PIN and enrol a facial profile again.

That rename is the part most guides leave out, and it’s why this fix fails for people following the instructions elsewhere.

Be aware of what this removes. Deleting or renaming the Ngc folder clears the Windows Hello credentials for every user on that device. Each of them will need to set up their PIN and biometrics again. On an Entra-joined device using Windows Hello for Business, they’ll also need connectivity to Entra ID to re-enrol, so don’t do this to a remote user who’s about to get on a plane.

3. Reset the biometric database

If the PIN works but facial recognition or fingerprint doesn’t, the biometric database is the more likely culprit than the credential store.

Stop the service first:

  1. Press Win + R, type services.msc, press Enter.
  2. Find Windows Biometric Service, right-click it and choose Stop.

Then back up and clear the database. Open File Explorer and go to:

C:\Windows\System32\WinBioDatabase

Copy the contents of that folder somewhere safe. Call it WinBioBackup. Then delete the files from the original folder.

Take the backup. If the reset doesn’t help, you can put the files back and rule this out rather than having destroyed the enrolments for nothing.

Finally, restart the service and re-enrol:

  1. Back in Services, right-click Windows Biometric Service and choose Start.
  2. Go to Settings → Accounts → Sign-in options and enrol the biometric again.

Every user on the device has to re-enrol. On a shared machine, that’s a conversation to have before you start rather than after.

4. Reinstall the camera or fingerprint drivers

If Device Manager shows the hardware with a warning, or the camera isn’t listed at all, the driver is worth reinstalling.

On a Surface device:

  1. Open Device Manager.
  2. Expand System devices.
  3. Find Microsoft IR Camera Front and uninstall it. When prompted, don’t tick the option to delete the driver software.
  4. Do the same for Surface Camera Windows Hello.
  5. Restart the device twice.

The two restarts matter on Surface hardware. The first lets Windows redetect the devices, the second lets the biometric service pick them up properly.

On other manufacturers the device names differ, but the principle is the same. Look under System devices, Biometric devices and Cameras.

Also check that the camera isn’t disabled at a lower level:

  • Settings → Privacy & security → Camera – camera access enabled
  • Device Manager – no disabled devices
  • BIOS/UEFI – some business laptops allow the IR camera or fingerprint reader to be disabled in firmware

That last one catches people out after a firmware update resets the defaults.

5. Turn off Fast Startup

Fast Startup means the machine doesn’t fully shut down, and that can leave the biometric stack in a state it doesn’t recover from.

If the problem keeps returning after a shutdown but not after a restart, this is likely the cause.

Through Group Policy:

Computer Configuration → Policies → Administrative Templates → System → Shutdown → Require use of fast startup = Disabled

Locally:

Control Panel → Power Options → Choose what the power buttons do → Change settings that are currently unavailable, then untick Turn on fast startup.

Windows 11 and Entra-joined devices

The original version of this article was written for Windows 10 domain-joined devices. A few things have changed.

Settings has moved. The sign-in options are now under Settings → Accounts → Sign-in options, with Windows Hello Face, Windows Hello Fingerprint and Windows Hello PIN as separate entries. The greyed-out symptom looks the same.

Group Policy may not be the control. On an Entra-joined or Intune-managed device, the equivalent settings come from configuration policy rather than domain GPO. The relevant Intune identity protection settings sit under Devices → Configuration → Identity protection, and there’s an account protection policy for Windows Hello for Business at tenant level as well.

To check which applies, go to Settings → Accounts → Access work or school. If the device is Entra joined rather than domain joined, look at Intune before you look at Group Policy.

Windows Hello for Business enrolment can fail for reasons unrelated to this error, including certificate problems, missing licences and Conditional Access policies blocking registration. If certutil -deleteHelloContainer and re-enrolment fails with a specific error code, that’s a different problem from the greyed-out option this article covers.

If none of these work

A few things worth checking before you rebuild the machine.

TPM. Windows Hello depends on it. Run tpm.msc and confirm the TPM is present, ready for use, and not in a reduced-functionality state. A TPM that needs clearing will produce all sorts of odd authentication behaviour.

The user account type. Convenience PIN sign-in behaves differently for local accounts, Microsoft accounts and work accounts.

Windows updates. Both directions. A recent update can break biometrics, and a missing update can mean a fix never arrived.

System file corruption. Worth ruling out with sfc /scannow, and if that doesn’t help, DISM /Online /Cleanup-Image /RestoreHealth.

Event Viewer. Open eventvwr.msc and look under Applications and Services Logs → Microsoft → Windows, then check the Biometrics, User Device Registration and HelloForBusiness logs. Those will usually name the actual failure rather than leaving you with a greyed-out toggle.

The short version

Most of the time it’s one of two things.

On a managed device, it’s Group Policy or Intune configuration disabling biometrics, and no amount of deleting folders will fix a policy that’s actively turning the feature off.

On a standalone device, it’s a corrupted Hello container, and certutil -deleteHelloContainer followed by a sign-out and sign-in resolves it.

Everything else in this article is what you work through when those two don’t apply.

References

24 thought on “Windows Hello “This option is currently unavailable” error”
  1. I was having an issue with the fingerprint reader (and all Hello options) not working as part of the Windows 11 Dev team and these steps worked wonders. The last part is what finally solved it for me. Not sure what changed to make it do that all of a sudden but you’re awesome! Thanks!

  2. I tried for days to resolve this. Editing the group policy settings did the trick! Thank you so much for this post!

  3. I’m Happy that it work for all of the above.
    Still not working.

    it’s was perfect with win 11 but suddenly – stop working.
    try all of the above but NADA

  4. I tried it all – even turned my normal account into an admin account just to make things easier. Fingerprint reader still grayed out. In the process I lost my PIN sign in, but managed to get that back without resorting to a system restore.

Leave a Reply

Your email address will not be published. Required fields are marked *