Skip to content
How‑To Guides

Setting Up Windows Hello on Windows 11

Windows Hello on Windows 11 replaces password sign-in with face recognition, fingerprint, or PIN — faster to use and more secure than a typed password. This guide covers setting up every Windows Hello method, how it works, troubleshooting recognition failures, and when each option is best.

Setting Up Windows Hello on Windows 11

Windows Hello replaces the password for logging into Windows with something faster and more convenient: your face, your fingerprint, or a PIN. Once set up, you sit down at the PC and it unlocks as you look at it — face recognition typically takes under a second. On a laptop with a fingerprint reader, a touch of the sensor unlocks it immediately. Even the PIN option, while not biometric, is faster to enter than a full password and tied to the specific device rather than your account credentials. For the bigger picture, our Complete Guide to Windows 11 pulls everything together.

The practical benefits go beyond convenience. A PIN on a device is more secure than a network password that can be stolen remotely — if someone captures your PIN, they still need physical access to that specific device to use it. Face and fingerprint data never leave the device; they’re stored in the TPM chip’s secure enclave, not in Microsoft’s cloud.

Setting up Windows Hello

Settings → Accounts → Sign-in options. The available options depend on hardware:

  • Facial recognition (Windows Hello Face): requires an IR (infrared) camera, not a standard webcam. IR cameras work in the dark and can’t be fooled by a photo. Most modern laptops include IR cameras; desktop machines rarely do without a dedicated accessory.
  • Fingerprint recognition: requires a fingerprint sensor. Common on mid-range to premium laptops; available as USB accessories for desktops.
  • PIN: works on any hardware. A 4-digit minimum (you can make it longer; a 6-digit PIN is stronger). Used as a fallback when biometric recognition fails and as a setup prerequisite for biometrics.
  • Security key: hardware token (YubiKey, etc.) — less common for personal use, more relevant in enterprise settings.

Important: you must set up a PIN before setting up biometrics. The PIN is the fallback when face/fingerprint recognition fails (camera covered, sensor dirty, different lighting). Biometrics unlock Windows; PIN is the backup that’s always available.

Setting up a PIN — the first step

Settings → Accounts → Sign-in options → PIN (Windows Hello) → Set up → enter your current Microsoft account password (or Windows password if using a local account) → create a PIN. The PIN is stored on the device in the TPM; it’s not stored in Microsoft’s account system and can’t be used to sign in remotely.

PIN requirements: minimum 4 digits by default. For stronger security: Settings → Accounts → Sign-in options → PIN → Include letters and symbols → enable this for a PIN that’s actually an alphanumeric passphrase rather than just digits. A 6+ digit numeric PIN is adequate for most uses; an alphanumeric one is stronger.

Setting up facial recognition

Settings → Accounts → Sign-in options → Facial recognition → Set up → follow the prompts to look at the camera while it scans your face. The scan takes about 30 seconds and captures an IR model of your face. After initial setup: “Improve recognition” is available to add additional scans in different lighting conditions, with glasses, or with facial hair — each additional scan improves recognition accuracy.

If you sometimes wear glasses and sometimes don’t: add both variations. Face recognition accuracy degrades slightly in very dark rooms and can be affected by major changes in appearance (significant facial hair growth, different glasses frames). In these cases, the PIN fallback handles the recognition failure without requiring a full Windows account password.

Setting up fingerprint recognition

Settings → Accounts → Sign-in options → Fingerprint recognition → Set up → follow prompts to place and lift the finger from the sensor repeatedly. Windows builds a multi-angle model of the fingerprint for reliable recognition. Adding multiple fingers (dominant hand index plus thumb, or main hand plus non-dominant) provides backup options when the preferred finger isn’t available.

Fingerprint recognition works best with a clean, dry sensor and clean fingertips. Wet, dirty, or very dry skin reduces recognition accuracy. If accuracy drops over time: Settings → Accounts → Sign-in options → Fingerprint → Add a finger (re-enrol) or Clean up fingerprints (remove old data and start fresh).

Dynamic lock — automatic locking when you leave

Settings → Accounts → Sign-in options → Dynamic lock → Allow Windows to automatically lock your device when you’re away. Dynamic Lock uses Bluetooth: it detects when your paired phone moves out of range and locks Windows automatically. The lock happens 30-60 seconds after the phone goes out of range — not instant, but reliable for “stepped away from desk” scenarios.

Setup: pair your phone to the PC via Bluetooth first → then enable Dynamic Lock → Windows uses the phone’s Bluetooth signal to detect your presence. If the phone signal weakens or disappears: Windows locks after the timeout. Walking back in: Windows doesn’t unlock automatically (face recognition at login handles that) but the dynamic lock prevents long unattended unlocked machine situations.

Our guide on Windows 11 initial setup covers the sign-in and account configuration during first setup, and our Windows 11 account management covers the full account settings. For enterprise Windows Hello deployment including certificate-based authentication and TPM requirements, Microsoft’s Windows Hello for Business documentation covers the managed deployment scenarios.

Windows Hello in apps and websites

Windows Hello isn’t limited to Windows login. Applications and websites can use Windows Hello for authentication through the WebAuthn/FIDO2 standard and the Windows Biometric Framework. When a site or app supports Windows Hello: you can authenticate with your face or fingerprint instead of a password, using the same biometric already set up for Windows login.

Microsoft’s own applications (Edge, Office, Microsoft 365 web) support this natively. Third-party apps that implement WebAuthn authentication can request Windows Hello through the browser or the app. Banks, password managers, and productivity tools are increasingly adopting this, though adoption varies by provider. This is the direction authentication is heading — Windows Hello is the platform that enables it on Windows devices.

When Windows Hello doesn’t work

Common issues and their fixes:

  • Face recognition not working after updates: Windows Updates occasionally require face recognition to be re-enrolled. Settings → Accounts → Sign-in options → Facial recognition → Improve recognition (re-scan) usually resolves this.
  • Fingerprint not recognised: clean the sensor, dry your finger, and try again. If consistently failing: remove and re-add the fingerprint. Multiple enrolments for the same finger (done at different times) can sometimes conflict — use “Clean up fingerprints” and re-enrol fresh.
  • “Something went wrong” during setup: typically a TPM issue. Check: Win+R → tpm.msc → TPM should be “Ready for use.” If not: a BIOS update or enabling TPM in BIOS may be required.
  • PIN forgotten: Settings → Accounts → Sign-in options → PIN → I forgot my PIN → uses Microsoft account recovery to set a new one. Requires internet access and the Microsoft account credentials.
Windows Hello methodHardware requiredSpeed
Face recognitionIR cameraUnder 1 second
FingerprintFingerprint sensorUnder 1 second (on contact)
PINAny hardware with TPM2-3 seconds (faster than password)
Security keyHardware token (USB)1-2 seconds

Windows Hello is one of the few security improvements that’s also a convenience improvement. A 1-second face recognition unlock is objectively faster and more pleasant than typing a password. The TPM-backed PIN is more secure against remote credential theft than a reusable password. The setup takes 5 minutes; the benefit compounds every time you unlock the machine. For anyone still typing a password to log into Windows 11: setting up Windows Hello is the highest-return 5-minute configuration task available.

Passkeys and Windows Hello

Passkeys are the next evolution of authentication: instead of passwords, passkeys use a public-private key pair where the private key never leaves your device. Windows 11 supports passkeys using Windows Hello as the authentication mechanism — when a website or app asks for passkey verification, Windows prompts for your face, fingerprint, or PIN, and the biometric unlocks the private key that proves your identity.

You’re probably already using this without calling it passkeys: signing into Microsoft accounts, Google accounts, and many major services in Edge or Chrome on Windows 11 can use passkeys with Windows Hello as the authenticator. Sites that have adopted passkeys (an increasing number, particularly after 2024’s broader adoption) show a “Use passkey” option at login — selecting this on Windows 11 triggers Windows Hello authentication rather than a password prompt.

The practical implication: setting up Windows Hello today is also setting up the authentication infrastructure for passkeys. As more sites adopt passkey support, Windows Hello becomes more valuable because it’s the underlying mechanism that makes passkeys work on Windows devices.

Windows Hello and multiple user accounts

Windows Hello is per-user account. Each Windows user account sets up its own PIN, face recognition, or fingerprint independently. The fingerprint sensor on a laptop shared between family members stores each person’s fingerprint under their respective account — touching the sensor when the login screen is for Account A authenticates Account A without seeing or being affected by Account B’s fingerprint data.

Face recognition in shared households: each account sets up face recognition independently. The system doesn’t confuse users — face recognition at the login screen checks which account is currently being logged into and only matches that account’s enrolled face model. Other users’ faces don’t satisfy the recognition even if they stand in front of the camera.

Privacy implications of biometric authentication

Face and fingerprint data in Windows Hello is stored encrypted in the TPM (Trusted Platform Module) chip. The data doesn’t leave the device; Microsoft does not receive or store it. This is a meaningful distinction from some smartphone biometric implementations — Windows Hello was designed with local-only storage from its initial architecture.

The PIN, by contrast, is hashed using the TPM’s hardware capabilities. It’s also local — the PIN hash never leaves the device and can’t be used to authenticate to Microsoft’s services directly. If someone steals your PIN, they still need physical possession of the specific Windows PC to use it. This is fundamentally different from stealing an account password, which can be used from anywhere.

Windows Hello on older hardware

Windows Hello PIN works on any Windows 11 hardware with a TPM 2.0 chip (required for Windows 11). Facial recognition requires an IR camera — standard webcams don’t work for this, only cameras that emit and detect infrared light for accurate 3D face mapping. Fingerprint recognition requires a fingerprint sensor.

For desktop machines without IR cameras or fingerprint sensors: a Windows Hello-compatible accessory adds the capability. Several USB fingerprint readers (Kensington VeriMark, HP USB Fingerprint Reader) and IR webcams (Logitech BRIO, selected Dell and HP models) are Windows Hello certified. Check Microsoft’s list of Windows Hello certified accessories before purchasing to ensure the hardware has the required driver support for Windows Hello integration rather than just a standard camera or reader that won’t trigger the Hello authentication path.

Windows Hello represents Microsoft’s most successful push toward passwordless authentication. The combination of device-bound credentials, hardware-backed security through TPM, and fast biometric authentication addresses both the usability and security problems with traditional passwords simultaneously. Its adoption on Windows has been high precisely because it’s clearly better in both dimensions rather than trading one for the other, which most security improvements fail to achieve.

Disabling Windows Hello

If you want to remove Windows Hello sign-in options: Settings → Accounts → Sign-in options → select the method → Remove. Removing face recognition returns to PIN as the primary sign-in. Removing the PIN returns to password sign-in entirely. On machines joined to a corporate domain: IT may have policies requiring Windows Hello, and local removal may be overridden on next policy sync.

Some users remove Windows Hello to return to password sign-in for specific reasons: shared kiosks where automatic face unlock is undesirable, highly sensitive environments where biometric data creates compliance concerns, or troubleshooting sign-in issues. These are valid specific situations; for the general case, Windows Hello is the superior sign-in method and there’s rarely a compelling reason to revert.

Requiring Windows Hello for privileged operations

Beyond just Windows login: Settings → Accounts → Sign-in options → “Require Windows Hello sign-in for Microsoft accounts” — when enabled, sensitive account operations (password changes, accessing payment information, certain Microsoft Store purchases) require Windows Hello verification rather than just a password confirmation. This adds friction to account changes that an attacker who compromised your account would try to make, providing an additional protection layer for account modification operations. You might also run into Set Up a Printer in Windows 11.

Windows Hello is genuinely more than just a login shortcut. The underlying TPM-backed key infrastructure, the passkey support, the per-device binding of credentials, and the ongoing expansion of Windows Hello-authenticated operations all point toward it being the foundational authentication mechanism for Windows going forward rather than a convenience add-on to the existing password system. Related: How to Set Up a Guest WiFi Network the Smart, Secure Way.

Nikolas Lamprou

Nikolas Lamprou (MSc; GCFR, SC-200, Security+) has been working with computers professionally since 2009 — starting with web development and e-commerce, and moving into cybersecurity over the years. Based in Greece, he brings over 15 years of real-world IT experience to SolveTechToday, where he writes about Windows fixes, software reviews, security tools, and AI applications. His goal is straightforward: cut through the noise and give readers clear, honest guidance on the tech decisions that matter.

Stay Ahead

Fix your next problem before it starts

Get the week's best Windows fixes, software picks, and security guides delivered straight to your inbox. No noise, just solutions.

Press ESC to close · Try "Windows 11" or "Chrome"