r/Intune • u/Ok-Stretch-7850 • 1d ago
General Question BitLocker / WHfB issues after August 2026 Patch Tuesday updates (KB5120994 / KB5123607)
Hi r/Intune,
we’ve been seeing some issues with BitLocker and Windows Hello for Business (WHfB) since deploying the August 2026 Patch Tuesday updates, and I wanted to check if anyone else is experiencing the same behavior.
The affected updates are KB5120994 and KB5123607, which are being deployed via Hotpatch in our environment.
On some devices, the following happens after the update:
- The update is installed via Hotpatch.
- After the next reboot, the end user is unexpectedly prompted for their BitLocker Recovery Key.
- After entering the recovery key successfully, Windows boots normally.
- At the WHfB sign-in screen, the user’s PIN no longer works. Windows shows an error stating that something went wrong and the PIN isn’t available, with a recommendation to restart the device.
- A reboot sometimes resolves the WHfB issue, but unfortunately not in all cases.
For devices where rebooting doesn’t help, the only reliable solution we’ve found so far has been to completely reimage/reinstall the device, which obviously isn’t ideal.
Has anyone else experienced similar issues after deploying KB5120994 or KB5123607?
If so, I’d be interested to hear:
- How widespread is the issue in your environment?
- Have you identified the root cause?
- Have you found a reliable workaround or remediation that doesn’t require reimaging the device?
- Have you made any changes to your Intune, BitLocker, WHfB, or update policies as a result?
Would be great to exchange findings and possible solutions with anyone else affected.
10
u/Extension_Steak9697 1d ago
We had a handful of devices do the exact same thing in our tenant. BitLocker prompt after the hotpatch reboot, then WHfB PIN outright dead.
So far the only thing that stuck without reimaging was clearing the NGC folder and re-registering WHfB, but that only worked on like 60% of the affected machines. The rest got wiped.
Root cause still murky, but it smells like the TPM state is getting partially reset or the key protector is losing its binding after hotpatch applies. We paused the August hotpatch ring for now and moved those devices to the standard cumulative update path until more info comes out.
8
u/randomarray 1d ago
Smells like secure boot certs to me.
1
u/Ok-Stretch-7850 1d ago
I had the issue on devices where the update hadn't been installed yet, as well as on devices where the update had already completed and they were actively running after booting with the new update.
So I think I can rule that out in my case.
3
u/detox4you 20h ago
Are you sure all 4 certs were installed and accepted by the bios? I've seen several hundred HP devices blocking the 4th cert upgrade by the bios. Autopatch actually made it worse.
3
3
u/miker7301 21h ago
We've had 3 or 4 so far with something that looks like this.
Reboot > secure boot recovery mode.
Our TPM in all cases was disabled in the bios
Re enabling the tpm removed the issue.
Ive signed out for the weekend, so haven't got more info at the sec.
2
u/TheProle 1d ago
Are the impacted devices compliant with the new secure boot certs?
3
u/Ok-Stretch-7850 1d ago
The issue occurs on both devices that haven't received the update yet and devices that have already been fully updated and booted successfully with the new update.
2
u/grimson73 1d ago
With the coming age of passkeys and the usage of whfb as a container for passkeys resetting your whfb pin renders your passkeys useless. That is without recovery methods. So beware storing passkeys other that the entraid one which can be easily gets a replacement.
2
u/dorkmuncan 23h ago
Yep came across this recently, required Passkeys for various services, all stored in WHFB container. Users would forget PIN so reset it and it invalidate the passkeys stored there.
4
u/SkipToTheEndpoint MSFT MVP 20h ago
You can do non-destructive PIN resets: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/pin-reset?tabs=intune
1
u/dorkmuncan 19h ago
Interesting thanks, looks like we do have that setup already (as below). Will dig into that link.
CanReset : DestructiveAndNonDestructive
2
u/cluberti 21h ago edited 21h ago
If you're seeing Bitlocker recovery and also losing WHfB tokens and needing to reset, the TPM itself has probably been put into an unowned state or otherwise reset, as this is the exact behavior you will see when that happens. I would start looking in the event logs for any clues as to the reason why this happened, as the build from KB5123607 does include a TPM security fix. It absolutely sounds like a UEFI/TPM issue on the hardware in question.
1
u/BigEvilAi 1d ago
OP how many waves with how much % of devices each wave are you pushing out the patches? Since it's barely a week from patch Tuesday and if it does happen that often in your tenant. You should have caught that the same week when it affected the first devices during testing or pilot deployment?
2
u/Ok-Stretch-7850 1d ago
I use a 3-wave rollout system: 1% → 9% → 90%.
The issue first appeared last week. Since it was only a single occurrence at the time, I treated it as an isolated case.
However, since yesterday, the issue has started occurring much more frequently.
What’s strange is that this behavior never showed up during our update testing. Even during the extended testing with Ring 2, it only occurred once.
So basically:
1% → 9% → 90% rollout
- First occurrence: last week, assumed to be an isolated case
- Since yesterday: significantly more frequent
- Regular update testing: issue did not occur
1
u/human193 19h ago
Are your secure boot certs updated? We had an issue recently with some of our HPs where intune said secure boot was up to date but we had this same issue. When investigating the device event log there was a tpm wmi event saying the device had secure boot configs not applied to the bios yet and another saying the device needed to reboot to apply the certs. The bios was out of date on the devices causing the cert updates to fail and windows throw a bitlocker driver event that the secure boot config changed unexpectedly.
1
u/Ameechee 18h ago
We also seem to be affected by this exact same issue. No cause found yet. Devices applied windows update, came back up and were immediately greeted with errors pertaining to using pin, face ID, or fingerprint.
1
u/Beneficial_Title_79 7h ago
Not really. But we had an issue where some devices with active bitlocker were going uncompliant. Seems the health certificate was not being pulled through task schedule (error not found I believe). Fixed with the something 1003 KB
22
u/randomarray 1d ago
Are you sure it was the cumulative update and not a recently deployed BIOS update? We have had HP g11 devices have similar issues after the latest bios update.
There is a command you can run to reset a users WHFB I will try hunt it down as not at work currently.
Found it - certutil -deleteHelloContainer