TPM For Windows Hello After Restart

Options
2»

Comments

  • gussic
    gussic
    Community Member
    Options

    Upgrading to the newest nightly did not fix the TPM issue for my intel based machines.

  • MikeT
    Options

    Hi @gussic,

    Can you do the following for me, it'll let us know if your Windows Hello key are in the software provider or the TPM provider:

    1. Click start and search for Powershell, open it
    2. Enter the following command: certutil -csp "Microsoft Passport Key Storage Provider" -key -v | Select-String -Pattern "NgcKeyImplType"
    3. Does it output 1 (0x1) or 2 (ox2)?

    It should show something like NgcKeyImplType: 1 (0x1) if it is in hardware TPM provider.

  • gussic
    gussic
    Community Member
    Options

    Hey @MikeT

    This is the output I got:

    PS C:\Users\user> certutil -csp "Microsoft Passport Key Storage Provider" -key -v | Select-String -Pattern "NgcKeyImplType"
    
      NgcKeyImplType: 1 (0x1)
      NgcKeyImplType: 1 (0x1)
      NgcKeyImplType: 1 (0x1)
    

    Cheers

  • MikeT
    Options

    Hi @gussic,

    Interesting. Could you send us your 1Password diagnostics report, it might explain what's going on.

    Here's how to generate the report on Windows

    Please email the report to support+forum@1password.com and in your email, also include:

    Let us know here when you sent it, so we can look for it.

  • gussic
    gussic
    Community Member
    Options

    Hi @MikeT

    I have an existing ticket open #ALL-72966-442 - I have sent through another batch of diagnostics now but I have sent them previously as well - hopefully it helps you work out what is happening!

  • MikeT
    Options

    Thank you, I'll reply there.

  • jpalo
    jpalo
    Community Member
    Options

    FYI: This has worked well in the last 1-2 months, so thank you for the fix. Something I've noticed, though, is that whenever Windows 11 build is updated (Windows Insiders build), 1Password forgets the Hello configuration, and you need to type in your password to unlock one time, followed by the Hello authentication. After that it works correctly until a new Windows build is installed. Not sure if this is something that could even be handled by 1Password - in any case it may not be a high prio issue, however, it might also affect users installing larger Windows updates that occur 1-2 times per year.

  • Tertius3
    Tertius3
    Community Member
    Options

    From what I observed in the last months, the TPM saved password was always forgotten after a system reboot that was required by Windows Update. It was not (as far as I remember never) forgotten after manual shutdown/reboot/restart initiated by myself.

  • AliH1P
    Options

    Hey @jpalo and @Tertius3, thanks for sharing your observations. At the moment, this is the expected behavior as the TPM state becomes invalidated as an extra security measure after a Windows and/or driver update.

    I'm glad to hear it's otherwise working well for you!

    Ali

This discussion has been closed.