Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix 80090016

Error 80090016 in Teams and Outlook: the TPM keyset does not exist

11 min read Updated October 5, 2026 Microsoft 365 & Entra ID

Fix it now

80090016 is NTE_BAD_KEYSET, “Keyset does not exist”. Windows keeps the key that proves your identity to Entra ID in a protected container, normally sealed by the TPM, and the component that needed it could not open it. Microsoft attributes it to the device TPM, and every Microsoft 365 app on the machine fails the same way.

Elevated PowerShell. Run the first two and read them before running the third

Get-Tpm
dsregcmd /status
certutil -DeleteHelloContainer
  1. Read Get-Tpm. TpmPresent and TpmReady both True means the hardware is fine and the fault is in the container above it.
  2. Run Microsoft’s Sign-in troubleshooter for Microsoft 365 before anything manual. It is the documented automatic fix for this family.
  3. If one user fails on a device where others are fine, run certutil -DeleteHelloContainer as that user, sign out and back in, and set the PIN up again.
  4. If every user on the device fails, run dsregcmd /leave on an Entra joined or hybrid joined device, restart, and let it re-register.
  5. Check that your antivirus or firewall is not blocking Microsoft.AAD.BrokerPlugin.exe or backgroundTaskHost.exe, which Microsoft names as required.

certutil -DeleteHelloContainer removes that user’s PIN and biometric sign-in on that device. Make sure they know their password first.

If sign-in completes you can stop here. If not, the next section explains what the container is and why each step is more destructive than the last.

Why it happens

When a device registers with Entra ID it generates a key pair. The private half is written into a protected container, ideally sealed by the TPM so it cannot be copied off the machine, and the public half is recorded against the device object in the directory. Every silent token the Web Account Manager issues afterwards is proved with that private key. If the container cannot be opened, nothing can be proved, and every application that depends on it stops signing in.

The five codes in this article are all cryptography errors from the same header file, and they describe different failures of that machinery rather than five versions of one failure. 80090016 is NTE_BAD_KEYSET, “Keyset does not exist”: the container the caller asked for is not there. 80090011 is NTE_NOT_FOUND, “Object was not found”. 80090030 is NTE_DEVICE_NOT_READY, “The device that is required by this cryptographic provider is not ready for use”. 80090034 is NTE_ENCRYPTION_FAILURE, “Encryption failed”. 80090023 is NTE_TOKEN_KEYSET_STORAGE_FULL: “The security token does not have storage space available for an additional container”.

That last one is worth reading twice, because it points somewhere none of the others do. A TPM has finite storage for key containers, and a device that has accumulated containers – many user profiles, repeated re-registrations, or an application creating containers it never releases – can simply run out of room. The fix for a full token is not the same as the fix for a missing keyset.

Containers become unopenable for mundane reasons: a profile that roams badly, a firmware update that changes the TPM’s storage hierarchy, a TPM in lockout after repeated failures, or a device restored from an image captured after registration so the directory holds a public key whose private half no longer exists. The order you work through this in matters, because each step costs more than the one before.

The user’s Windows Hello container is damaged

You have this one if One user fails on a device where other accounts sign in normally, and the PIN either fails or cannot be changed.

  1. Sign in as that user and run certutil -DeleteHelloContainer from an elevated prompt.
  2. Sign out of Windows and back in.
  3. Set the PIN up again when prompted, which rebuilds the container.
  4. Start Teams or Outlook and confirm sign-in completes.

This removes the PIN and any biometric sign-in for that user on that device. On a laptop away from the office, confirm they know their password before you do it.

Security software is blocking the broker

You have this one if The TPM is healthy, the container rebuild works, and the failure returns – often across a group of machines running the same endpoint agent.

  1. Allow Microsoft.AAD.BrokerPlugin.exe and backgroundTaskHost.exe in the antivirus and firewall product – Microsoft names both.
  2. Confirm HTTPS traffic to https://login.microsoftonline.com is permitted; the broker does not fall back to plain HTTP.
  3. Retest, then raise a permanent exclusion with the vendor rather than leaving protection disabled.

The device registration no longer matches the directory

You have this one if dsregcmd /status shows the device joined but with no primary refresh token, or in a state inconsistent with the directory object.

  1. Read the full dsregcmd /status output and note the join type before changing anything.
  2. On an Entra joined or hybrid joined device, run dsregcmd /leave and restart, then let the device register again.
  3. For a work account added to a personal device, remove it under Settings, Accounts, Access work or school and add it back.
  4. Remove the stale device object from the directory only after the device has re-registered successfully.

Leaving and rejoining signs users out and needs administrative access. Exhaust the container and broker fixes first.

The TPM has no room for another container

You have this one if 80090023 specifically, on a device that has hosted many profiles or been re-registered repeatedly.

  1. Remove Windows Hello containers for profiles that no longer use the device, with certutil -DeleteHelloContainer signed in as each.
  2. Delete unused local user profiles from System, Advanced system settings, User Profiles.
  3. If the device is genuinely shared by a large number of users, plan for that rather than treating each failure as a separate incident.

The TPM is in lockout or its firmware is faulty

You have this one if Get-Tpm reports the device as not ready or locked out, and the fault appeared across several machines of the same model after an update.

  1. Run Get-Tpm and record the reported state before changing anything.
  2. Check the manufacturer’s site for a TPM firmware update for that model, and read their notes on whether applying it clears keys.
  3. Suspend BitLocker and confirm you hold the recovery keys, then clear the TPM from tpm.msc or with Clear-Tpm.
  4. Restart, let the device re-register with Entra ID, and have users set their PIN up again.

Clearing a TPM destroys every key it holds. BitLocker will demand the recovery key, Windows Hello enrolments are lost for every user on the device, and anything else sealed to that TPM stops working. Suspend BitLocker and confirm you hold the recovery keys before you go near this.

Full reference

What each code actually says

Code Symbolic name Published text
80090016 NTE_BAD_KEYSET Keyset does not exist
80090011 NTE_NOT_FOUND Object was not found
80090023 NTE_TOKEN_KEYSET_STORAGE_FULL The security token does not have storage space available for an additional container
80090030 NTE_DEVICE_NOT_READY The device that is required by this cryptographic provider is not ready for use
80090034 NTE_ENCRYPTION_FAILURE Encryption failed

Microsoft’s Web Account Manager error list shows the same values in decimal, which is how they often appear in application logs: 2148073494 is 0x80090016 and 2148073520 is 0x80090030. If you are reading a log that gives you a ten-digit number rather than a hex code, convert before you search.

Work through the layers in order

Scope of the failure Start here
One user on one device That user’s Windows Hello container
Every user on one device The device’s registration, then the TPM
Many devices at once, same model A TPM firmware or driver update pushed to that model
Devices restored from an image Registration state captured in the image; re-register the device
Get-Tpm reports not ready or locked out The TPM, before anything in Windows
80090023 on a heavily shared device Container storage on the TPM, not the container itself

A warning about registry workarounds

There is a registry value circulating for this error that moves the account broker’s key protection out of the TPM and into software. It is not documented by Microsoft, and what it does is real: it takes keys that were sealed to hardware and makes them software-protected, on every account on that machine, permanently until someone remembers to reverse it. That is a deliberate reduction in the protection those keys receive, applied to fix a sign-in prompt. Do not do it. If the TPM genuinely cannot hold the key, fix or replace the TPM.

Where to look when the obvious steps fail

  • Microsoft’s Sign-in troubleshooter for Microsoft 365 is the documented automatic fix and should be your first move, not your last.
  • The Microsoft Entra ID operational log on the device carries the AADSTS detail behind the failure. AADSTS70002 with AADSTS135011 means the device is disabled in the directory; with AADSTS50155 it means the device is not authenticated.
  • Non-persistent VDI with single sign-on through a federated identity provider has its own documented failure, 0xc0f10005, which is not a TPM problem at all.
  • A device whose object was deleted from Entra ID needs re-registration, not a container rebuild; the container is fine, the directory no longer has the matching public key.
  • Check the Windows build. This family has been the subject of several fixes, and a device months behind on updates is worth patching before it is worth rebuilding.

Every code this article covers

Code What it points at Source
80090016 NTE_BAD_KEYSET, “Keyset does not exist” – the protected key container the caller asked for could not be opened; Microsoft attributes it to the device TPM Microsoft Learn
80090030 NTE_DEVICE_NOT_READY, “The device that is required by this cryptographic provider is not ready for use” Microsoft Learn
80090034 NTE_ENCRYPTION_FAILURE, “Encryption failed” Microsoft Learn
80090011 NTE_NOT_FOUND, “Object was not found” Microsoft Learn
80090023 NTE_TOKEN_KEYSET_STORAGE_FULL, “The security token does not have storage space available for an additional container” Microsoft Learn

Confirm the fix worked

  1. Get-Tpm reports the TPM present, ready and not locked out.
  2. dsregcmd /status shows the device state and token section as expected for your join type.
  3. Teams and Outlook both sign in on the device without a prompt loop.
  4. The user can set and use a PIN again, which proves the container rebuilt.
  5. Restart and confirm sign-in still succeeds with no manual intervention.

Questions people ask about this

Is this a licensing problem?

No, and it costs nothing to fix. The device cannot prove its identity cryptographically, which is unrelated to what you have bought. An account without a licence produces a separate and much clearer message about the service.

Will I lose data by clearing the Hello container?

No data is lost, but the user loses their PIN and any fingerprint or face sign-in on that device and must set them up again. Confirm they know their password first, particularly on a laptop away from the office.

Do we have to clear the TPM?

Rarely, and it belongs last. Most cases resolve with a container rebuild, an antivirus exclusion, or re-registering the device. Clearing the TPM invalidates BitLocker protectors and every enrolled credential on the machine, so it needs preparation rather than improvisation.

Why did this appear across a whole batch of laptops?

Almost always a firmware or driver update rolled out to one hardware model, or an image captured after the devices were registered. Find out what changed on that model before treating it as a hundred separate incidents.

What is different about 80090023?

It is the only one of the five that means the TPM has no room, rather than that a key is missing or unusable. On a device shared by many profiles, removing Hello containers and stale user profiles is the fix; rebuilding one container will not help.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix 403 FORBIDDEN and Access Denied in SharePoint Online and OneDrive Free Fix Teams CAA20003 and CAA2000C: clock skew, Conditional Access and forced prompts License Error AADSTS70008 and AADSTS700082: the refresh token expired or was revoked Free Fix AADSTS7000215 and AADSTS700016: bad client secret or missing app registration
โ† Back to Knowledge Base