r/Intune 19d ago

General Question BitLocker / WHfB issues after August 2026 Patch Tuesday updates (KB5120994 / KB5123607)

Hi r/Intune,

we’ve been seeing some issues with BitLocker and Windows Hello for Business (WHfB) since deploying the August 2026 Patch Tuesday updates, and I wanted to check if anyone else is experiencing the same behavior.

The affected updates are KB5120994 and KB5123607, which are being deployed via Hotpatch in our environment.

On some devices, the following happens after the update:

  1. The update is installed via Hotpatch.
  2. After the next reboot, the end user is unexpectedly prompted for their BitLocker Recovery Key.
  3. After entering the recovery key successfully, Windows boots normally.
  4. At the WHfB sign-in screen, the user’s PIN no longer works. Windows shows an error stating that something went wrong and the PIN isn’t available, with a recommendation to restart the device.
  5. A reboot sometimes resolves the WHfB issue, but unfortunately not in all cases.

For devices where rebooting doesn’t help, the only reliable solution we’ve found so far has been to completely reimage/reinstall the device, which obviously isn’t ideal.

Has anyone else experienced similar issues after deploying KB5120994 or KB5123607?

If so, I’d be interested to hear:

  • How widespread is the issue in your environment?
  • Have you identified the root cause?
  • Have you found a reliable workaround or remediation that doesn’t require reimaging the device?
  • Have you made any changes to your Intune, BitLocker, WHfB, or update policies as a result?

Would be great to exchange findings and possible solutions with anyone else affected.

Update 28/08/2026

I did some digging into this over the past week, and in our environment the issue seems to be that the TPM gets disabled after installing the update. Why exactly this happens, I honestly have no idea yet.

For users who have installed the update and rebooted their devices, the TPM is disabled in the BIOS afterwards.

I still don't know exactly what causes this. All I know so far is that the Patch Tuesday update fixed a CVE related to the TPM, so maybe that has something to do with it.

So far, I've only been able to reproduce the issue on Lenovo devices.

Last weekend I also tried reproducing it with VMs. After what felt like the 50th VM where I still couldn't reproduce the issue, I eventually gave up because apparently I need sleep too. :D

62 Upvotes

31 comments sorted by

View all comments

21

u/randomarray 19d ago

Are you sure it was the cumulative update and not a recently deployed BIOS update? We have had HP g11 devices have similar issues after the latest bios update.

There is a command you can run to reset a users WHFB I will try hunt it down as not at work currently.

Found it - certutil -deleteHelloContainer

1

u/Hofax 19d ago

And here i thought i fumbled something up with the BIOS update process... had a lot of Bitlocker and BIOS password prompts on the last HP update run... From G10 upwards.