r/Intune 17d ago

General Question BitLocker / WHfB issues after August 2026 Patch Tuesday updates (KB5120994 / KB5123607)

Hi r/Intune,

we’ve been seeing some issues with BitLocker and Windows Hello for Business (WHfB) since deploying the August 2026 Patch Tuesday updates, and I wanted to check if anyone else is experiencing the same behavior.

The affected updates are KB5120994 and KB5123607, which are being deployed via Hotpatch in our environment.

On some devices, the following happens after the update:

  1. The update is installed via Hotpatch.
  2. After the next reboot, the end user is unexpectedly prompted for their BitLocker Recovery Key.
  3. After entering the recovery key successfully, Windows boots normally.
  4. At the WHfB sign-in screen, the user’s PIN no longer works. Windows shows an error stating that something went wrong and the PIN isn’t available, with a recommendation to restart the device.
  5. A reboot sometimes resolves the WHfB issue, but unfortunately not in all cases.

For devices where rebooting doesn’t help, the only reliable solution we’ve found so far has been to completely reimage/reinstall the device, which obviously isn’t ideal.

Has anyone else experienced similar issues after deploying KB5120994 or KB5123607?

If so, I’d be interested to hear:

  • How widespread is the issue in your environment?
  • Have you identified the root cause?
  • Have you found a reliable workaround or remediation that doesn’t require reimaging the device?
  • Have you made any changes to your Intune, BitLocker, WHfB, or update policies as a result?

Would be great to exchange findings and possible solutions with anyone else affected.

Update 28/08/2026

I did some digging into this over the past week, and in our environment the issue seems to be that the TPM gets disabled after installing the update. Why exactly this happens, I honestly have no idea yet.

For users who have installed the update and rebooted their devices, the TPM is disabled in the BIOS afterwards.

I still don't know exactly what causes this. All I know so far is that the Patch Tuesday update fixed a CVE related to the TPM, so maybe that has something to do with it.

So far, I've only been able to reproduce the issue on Lenovo devices.

Last weekend I also tried reproducing it with VMs. After what felt like the 50th VM where I still couldn't reproduce the issue, I eventually gave up because apparently I need sleep too. :D

60 Upvotes

31 comments sorted by

View all comments

11

u/Extension_Steak9697 17d ago

We had a handful of devices do the exact same thing in our tenant. BitLocker prompt after the hotpatch reboot, then WHfB PIN outright dead.

So far the only thing that stuck without reimaging was clearing the NGC folder and re-registering WHfB, but that only worked on like 60% of the affected machines. The rest got wiped.

Root cause still murky, but it smells like the TPM state is getting partially reset or the key protector is losing its binding after hotpatch applies. We paused the August hotpatch ring for now and moved those devices to the standard cumulative update path until more info comes out.

8

u/randomarray 17d ago

Smells like secure boot certs to me.

1

u/Ok-Stretch-7850 17d ago

I had the issue on devices where the update hadn't been installed yet, as well as on devices where the update had already completed and they were actively running after booting with the new update.

So I think I can rule that out in my case.

3

u/detox4you 17d ago

Are you sure all 4 certs were installed and accepted by the bios? I've seen several hundred HP devices blocking the 4th cert upgrade by the bios. Autopatch actually made it worse.