Fix it now
80090016 is NTE_BAD_KEYSET, “Keyset does not exist”. Windows keeps the key that proves your identity to Entra ID in a protected container, normally sealed by the TPM, and the component that needed it could not open it. Microsoft attributes it to the device TPM, and every Microsoft 365 app on the machine fails the same way.
Get-Tpm
dsregcmd /status
certutil -DeleteHelloContainer
- Read
Get-Tpm. TpmPresent and TpmReady both True means the hardware is fine and the fault is in the container above it. - Run Microsoft’s Sign-in troubleshooter for Microsoft 365 before anything manual. It is the documented automatic fix for this family.
- If one user fails on a device where others are fine, run
certutil -DeleteHelloContaineras that user, sign out and back in, and set the PIN up again. - If every user on the device fails, run
dsregcmd /leaveon an Entra joined or hybrid joined device, restart, and let it re-register. - Check that your antivirus or firewall is not blocking
Microsoft.AAD.BrokerPlugin.exeorbackgroundTaskHost.exe, which Microsoft names as required.
certutil -DeleteHelloContainer removes that user’s PIN and biometric sign-in on that device. Make sure they know their password first.
If sign-in completes you can stop here. If not, the next section explains what the container is and why each step is more destructive than the last.
Why it happens
When a device registers with Entra ID it generates a key pair. The private half is written into a protected container, ideally sealed by the TPM so it cannot be copied off the machine, and the public half is recorded against the device object in the directory. Every silent token the Web Account Manager issues afterwards is proved with that private key. If the container cannot be opened, nothing can be proved, and every application that depends on it stops signing in.
The five codes in this article are all cryptography errors from the same header file, and they describe different failures of that machinery rather than five versions of one failure. 80090016 is NTE_BAD_KEYSET, “Keyset does not exist”: the container the caller asked for is not there. 80090011 is NTE_NOT_FOUND, “Object was not found”. 80090030 is NTE_DEVICE_NOT_READY, “The device that is required by this cryptographic provider is not ready for use”. 80090034 is NTE_ENCRYPTION_FAILURE, “Encryption failed”. 80090023 is NTE_TOKEN_KEYSET_STORAGE_FULL: “The security token does not have storage space available for an additional container”.
That last one is worth reading twice, because it points somewhere none of the others do. A TPM has finite storage for key containers, and a device that has accumulated containers – many user profiles, repeated re-registrations, or an application creating containers it never releases – can simply run out of room. The fix for a full token is not the same as the fix for a missing keyset.
Containers become unopenable for mundane reasons: a profile that roams badly, a firmware update that changes the TPM’s storage hierarchy, a TPM in lockout after repeated failures, or a device restored from an image captured after registration so the directory holds a public key whose private half no longer exists. The order you work through this in matters, because each step costs more than the one before.
The user’s Windows Hello container is damaged
You have this one if One user fails on a device where other accounts sign in normally, and the PIN either fails or cannot be changed.
- Sign in as that user and run
certutil -DeleteHelloContainerfrom an elevated prompt. - Sign out of Windows and back in.
- Set the PIN up again when prompted, which rebuilds the container.
- Start Teams or Outlook and confirm sign-in completes.
This removes the PIN and any biometric sign-in for that user on that device. On a laptop away from the office, confirm they know their password before you do it.
Security software is blocking the broker
You have this one if The TPM is healthy, the container rebuild works, and the failure returns – often across a group of machines running the same endpoint agent.
- Allow
Microsoft.AAD.BrokerPlugin.exeandbackgroundTaskHost.exein the antivirus and firewall product – Microsoft names both. - Confirm HTTPS traffic to
https://login.microsoftonline.comis permitted; the broker does not fall back to plain HTTP. - Retest, then raise a permanent exclusion with the vendor rather than leaving protection disabled.
The device registration no longer matches the directory
You have this one if dsregcmd /status shows the device joined but with no primary refresh token, or in a state inconsistent with the directory object.
- Read the full
dsregcmd /statusoutput and note the join type before changing anything. - On an Entra joined or hybrid joined device, run
dsregcmd /leaveand restart, then let the device register again. - For a work account added to a personal device, remove it under Settings, Accounts, Access work or school and add it back.
- Remove the stale device object from the directory only after the device has re-registered successfully.
Leaving and rejoining signs users out and needs administrative access. Exhaust the container and broker fixes first.
The TPM has no room for another container
You have this one if 80090023 specifically, on a device that has hosted many profiles or been re-registered repeatedly.
- Remove Windows Hello containers for profiles that no longer use the device, with
certutil -DeleteHelloContainersigned in as each. - Delete unused local user profiles from System, Advanced system settings, User Profiles.
- If the device is genuinely shared by a large number of users, plan for that rather than treating each failure as a separate incident.
The TPM is in lockout or its firmware is faulty
You have this one if Get-Tpm reports the device as not ready or locked out, and the fault appeared across several machines of the same model after an update.
- Run
Get-Tpmand record the reported state before changing anything. - Check the manufacturer’s site for a TPM firmware update for that model, and read their notes on whether applying it clears keys.
- Suspend BitLocker and confirm you hold the recovery keys, then clear the TPM from
tpm.mscor withClear-Tpm. - Restart, let the device re-register with Entra ID, and have users set their PIN up again.
Clearing a TPM destroys every key it holds. BitLocker will demand the recovery key, Windows Hello enrolments are lost for every user on the device, and anything else sealed to that TPM stops working. Suspend BitLocker and confirm you hold the recovery keys before you go near this.
Full reference
What each code actually says
| Code | Symbolic name | Published text |
|---|---|---|
80090016 |
NTE_BAD_KEYSET | Keyset does not exist |
80090011 |
NTE_NOT_FOUND | Object was not found |
80090023 |
NTE_TOKEN_KEYSET_STORAGE_FULL | The security token does not have storage space available for an additional container |
80090030 |
NTE_DEVICE_NOT_READY | The device that is required by this cryptographic provider is not ready for use |
80090034 |
NTE_ENCRYPTION_FAILURE | Encryption failed |
Microsoft’s Web Account Manager error list shows the same values in decimal, which is how they often appear in application logs: 2148073494 is 0x80090016 and 2148073520 is 0x80090030. If you are reading a log that gives you a ten-digit number rather than a hex code, convert before you search.
Work through the layers in order
| Scope of the failure | Start here |
|---|---|
| One user on one device | That user’s Windows Hello container |
| Every user on one device | The device’s registration, then the TPM |
| Many devices at once, same model | A TPM firmware or driver update pushed to that model |
| Devices restored from an image | Registration state captured in the image; re-register the device |
Get-Tpm reports not ready or locked out |
The TPM, before anything in Windows |
| 80090023 on a heavily shared device | Container storage on the TPM, not the container itself |
A warning about registry workarounds
There is a registry value circulating for this error that moves the account broker’s key protection out of the TPM and into software. It is not documented by Microsoft, and what it does is real: it takes keys that were sealed to hardware and makes them software-protected, on every account on that machine, permanently until someone remembers to reverse it. That is a deliberate reduction in the protection those keys receive, applied to fix a sign-in prompt. Do not do it. If the TPM genuinely cannot hold the key, fix or replace the TPM.
Where to look when the obvious steps fail
- Microsoft’s Sign-in troubleshooter for Microsoft 365 is the documented automatic fix and should be your first move, not your last.
- The Microsoft Entra ID operational log on the device carries the AADSTS detail behind the failure. AADSTS70002 with AADSTS135011 means the device is disabled in the directory; with AADSTS50155 it means the device is not authenticated.
- Non-persistent VDI with single sign-on through a federated identity provider has its own documented failure, 0xc0f10005, which is not a TPM problem at all.
- A device whose object was deleted from Entra ID needs re-registration, not a container rebuild; the container is fine, the directory no longer has the matching public key.
- Check the Windows build. This family has been the subject of several fixes, and a device months behind on updates is worth patching before it is worth rebuilding.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
80090016 |
NTE_BAD_KEYSET, “Keyset does not exist” – the protected key container the caller asked for could not be opened; Microsoft attributes it to the device TPM | Microsoft Learn |
80090030 |
NTE_DEVICE_NOT_READY, “The device that is required by this cryptographic provider is not ready for use” | Microsoft Learn |
80090034 |
NTE_ENCRYPTION_FAILURE, “Encryption failed” | Microsoft Learn |
80090011 |
NTE_NOT_FOUND, “Object was not found” | Microsoft Learn |
80090023 |
NTE_TOKEN_KEYSET_STORAGE_FULL, “The security token does not have storage space available for an additional container” | Microsoft Learn |
Confirm the fix worked
Get-Tpmreports the TPM present, ready and not locked out.dsregcmd /statusshows the device state and token section as expected for your join type.- Teams and Outlook both sign in on the device without a prompt loop.
- The user can set and use a PIN again, which proves the container rebuilt.
- Restart and confirm sign-in still succeeds with no manual intervention.
Questions people ask about this
Is this a licensing problem?
No, and it costs nothing to fix. The device cannot prove its identity cryptographically, which is unrelated to what you have bought. An account without a licence produces a separate and much clearer message about the service.
Will I lose data by clearing the Hello container?
No data is lost, but the user loses their PIN and any fingerprint or face sign-in on that device and must set them up again. Confirm they know their password first, particularly on a laptop away from the office.
Do we have to clear the TPM?
Rarely, and it belongs last. Most cases resolve with a container rebuild, an antivirus exclusion, or re-registering the device. Clearing the TPM invalidates BitLocker protectors and every enrolled credential on the machine, so it needs preparation rather than improvisation.
Why did this appear across a whole batch of laptops?
Almost always a firmware or driver update rolled out to one hardware model, or an image captured after the devices were registered. Find out what changed on that model before treating it as a hundred separate incidents.
What is different about 80090023?
It is the only one of the five that means the TPM has no room, rather than that a key is missing or unusable. On a device shared by many profiles, removing Hello containers and stale user profiles is the fix; rebuilding one container will not help.
