## TL;DR
Error 0x801c03f2 almost always means the device cannot prove to Entra ID that it is allowed to provision Windows Hello for Business. Run `dsregcmd /status` and confirm `AzureAdJoined` reads YES, confirm the TPM is ready, then delete the stale Hello container and retry enrollment from Settings / Accounts / Sign-in options. If the join state is healthy, the WHfB policy assignment is the next suspect.

## The error
```text
0x801c03f2
```
Seen during PIN or biometric setup, usually right after the user clicks through the Hello provisioning screens.

## Steps
1. On the device, open an elevated command prompt and run `dsregcmd /status`. Expected: `AzureAdJoined : YES`. If it reads NO, the device is not Entra joined and Hello cannot provision; rejoin first.
2. Check the TPM: run `Get-Tpm` in PowerShell. Expected: `TpmPresent : True` and `TpmReady : True`. Hello needs a ready TPM 2.0; a cleared or disabled TPM produces this exact code.
3. Confirm the WHfB policy reaches the device. On Intune: admin center / Devices / the device / check applied configuration policies. On hybrid: run `gpresult /r` and look for the Hello for Business provisioning policy. Expected: the policy shows as assigned. A missing policy is the most common cause on tenants where Hello was never enabled.
4. Delete the stale Hello container: remove the `Ngc` folder at `C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc`, then reboot. Expected: the folder is gone after the reboot.
5. Have the user go to Settings / Accounts / Sign-in options / PIN (Windows Hello) and set up again. Expected: setup completes with no error code.

## Use this when
- Error 0x801c03f2 appears during Hello PIN or biometric enrollment
- Hello setup fails on a freshly Entra-joined device
- Hello broke after a Windows feature update

## Not for this skill when
- The user forgot an existing Hello PIN (use the PIN-reset flow instead)
- Hello enrolls fine but the fingerprint reader is not detected (driver or hardware issue)
- The device is Azure Virtual Desktop or a VM without a virtual TPM (Hello cannot provision there)

## Compatibility
- Windows 10 1703+ and Windows 11, Entra joined or hybrid Entra joined
- TPM 2.0 required; Intune-managed or Group Policy-managed WHfB policy

## Variants
### 0x801c03f2 right after a feature update
The upgrade usually corrupted the NGC container. Step 4 alone (delete the folder, reboot, re-enroll) fixes most of these.
### Hybrid-joined device
Confirm the device has line of sight to a domain controller during provisioning. Hybrid Hello also needs the cloud Kerberos trust in place; without it, enrollment fails with this code.

## Why it happens
Hello provisioning is a key ceremony: the device asks Entra ID for permission, generates keys inside the TPM, and stores them in the NGC container. Code 0x801c03f2 fires when the request is rejected before the ceremony finishes, which is why the checklist starts at join state and TPM rather than at the PIN screen.

## Edge cases
- Loaner or reassigned laptops: the previous user's NGC container blocks the new user's enrollment. Clear the container between users.
- Recently reimaged machines can leave a stale device object in Entra ID. Delete the duplicate and rejoin.
- If the tenant scope for Hello excludes the user, enablement looks fine in Intune but enrollment still fails. Check the Entra ID Hello scope, not just the device policy.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_ObhmiSyaMrugS7qHanrAHw
