windows hello for business failing with error 0x801c03f2
Resolves Windows Hello for Business enrollment failures with error 0x801c03f2 on Entra-joined devices. Checks Entra join state, TPM readiness, and WHfB policy assignment, then clears the stale Hello container and re-provisions. Use when a user cannot set up a Hello PIN or biometrics and the 0x801c03f2 code appears. Not for forgotten-PIN resets on already working Hello setups.
TL;DR
Error 0x801c03f2 almost always means the device cannot prove to Entra ID that it is allowed to provision Windows Hello for Business. Run dsregcmd /status and confirm AzureAdJoined reads YES, confirm the TPM is ready, then delete the stale Hello container and retry enrollment from Settings / Accounts / Sign-in options. If the join state is healthy, the WHfB policy assignment is the next suspect.
The error
0x801c03f2Seen during PIN or biometric setup, usually right after the user clicks through the Hello provisioning screens.
Steps
- On the device, open an elevated command prompt and run
dsregcmd /status. Expected:AzureAdJoined : YES. If it reads NO, the device is not Entra joined and Hello cannot provision; rejoin first. - Check the TPM: run
Get-Tpmin PowerShell. Expected:TpmPresent : TrueandTpmReady : True. Hello needs a ready TPM 2.0; a cleared or disabled TPM produces this exact code. - Confirm the WHfB policy reaches the device. On Intune: admin center / Devices / the device / check applied configuration policies. On hybrid: run
gpresult /rand look for the Hello for Business provisioning policy. Expected: the policy shows as assigned. A missing policy is the most common cause on tenants where Hello was never enabled. - Delete the stale Hello container: remove the
Ngcfolder atC:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc, then reboot. Expected: the folder is gone after the reboot. - Have the user go to Settings / Accounts / Sign-in options / PIN (Windows Hello) and set up again. Expected: setup completes with no error code.
Use this when
- Error 0x801c03f2 appears during Hello PIN or biometric enrollment
- Hello setup fails on a freshly Entra-joined device
- Hello broke after a Windows feature update
Not for this skill when
- The user forgot an existing Hello PIN (use the PIN-reset flow instead)
- Hello enrolls fine but the fingerprint reader is not detected (driver or hardware issue)
- The device is Azure Virtual Desktop or a VM without a virtual TPM (Hello cannot provision there)
Compatibility
- Windows 10 1703+ and Windows 11, Entra joined or hybrid Entra joined
- TPM 2.0 required; Intune-managed or Group Policy-managed WHfB policy
Variants
0x801c03f2 right after a feature update
The upgrade usually corrupted the NGC container. Step 4 alone (delete the folder, reboot, re-enroll) fixes most of these.
Hybrid-joined device
Confirm the device has line of sight to a domain controller during provisioning. Hybrid Hello also needs the cloud Kerberos trust in place; without it, enrollment fails with this code.
Why it happens
Hello provisioning is a key ceremony: the device asks Entra ID for permission, generates keys inside the TPM, and stores them in the NGC container. Code 0x801c03f2 fires when the request is rejected before the ceremony finishes, which is why the checklist starts at join state and TPM rather than at the PIN screen.
Edge cases
- Loaner or reassigned laptops: the previous user's NGC container blocks the new user's enrollment. Clear the container between users.
- Recently reimaged machines can leave a stale device object in Entra ID. Delete the duplicate and rejoin.
- If the tenant scope for Hello excludes the user, enablement looks fine in Intune but enrollment still fails. Check the Entra ID Hello scope, not just the device policy.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_ObhmiSyaMrugS7qHanrAHw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.