July 26, 2026, 12:49 pm | Read time: 3 minutes
The Federal Office for Information Security has taken a closer look at Windows Hello for Business. The agency published the first technical report from the “Windows Dissected” project. The focus is on the login procedure developed by Microsoft, which is used on many private and business Windows computers. Instead of a traditional password, login is done via PIN, fingerprint, or facial recognition. The report describes both the technical foundations and potential vulnerabilities that can be exploited under certain conditions.
How Windows Hello Works in the Background
According to the BSI, Windows creates cryptographic keys during setup. These bind the login to the respective device. The private key remains on the computer and is only released after a person authenticates via PIN, fingerprint, or facial recognition. Additional protection can be provided by a Trusted Platform Module, or TPM. The module stores important key information in a secure hardware environment, making it more difficult to access.
The report (PDF document) also describes situations where these protective measures can lose their effectiveness. This particularly affects systems where attackers already have local administrator rights and can access certain stored data.
Biometric Data Can Become a Risk
For facial and fingerprint recognition, Windows stores encrypted templates in a database on the device. According to BSI, attackers can, under certain conditions, access information that serves to protect this data. This could allow them to decrypt the stored templates, alter the database, and assign their own biometric data to another user’s account.
In such a case, it would be possible to log in with one’s own face under the identity of another person. However, the report states that the attack does not work remotely. Instead, the system must already be largely under the control of the attackers, with the necessary rights in place.
1.3 Billion Passwords Leaked–Here’s What You Should Do Now
Data Breach with 16 Billion Passwords? What’s Really Behind the Reports
ESS Aims to Enhance Security
According to BSI, the described vulnerability is particularly relevant on shared computers. This is especially true when multiple people have stored their biometric features on the same device.
As a protective measure, the agency recommends using “Enhanced Sign-in Security” (ESS) if possible. This feature shifts parts of the biometric processing to a specially protected area. Additionally, compatible cameras and fingerprint sensors are more closely integrated into the security functions. This is intended to better protect both the stored biometric data and their comparison. However, ESS is only available on devices whose hardware and drivers support the feature.
Also of interest: Due to AI, Microsoft urges updates within three days
Recommendations for Businesses and Private Users
The BSI derives several recommendations from the investigation. Companies should, if possible, register only one person per device for Windows Hello. This reduces the risk of biometric data being incorrectly assigned to different accounts.
If ESS is not available, logging in exclusively via PIN may be the safer alternative. Furthermore, the agency recommends using a suitable TPM and an encrypted hard drive. Private users should also check whether their system supports ESS and whether biometric login can be additionally secured.