A glance at the laptop, a finger on the sensor—and Windows is unlocked. For many users, Windows Hello has long been part of everyday life. Passwords seem almost a thing of the past. But a study by the Federal Office for Information Security (BSI) shows that how well Windows Hello protects you doesn’t depend solely on Microsoft’s software. The hardware used, the settings, and—above all—the question of who already has access to the computer are also crucial factors.
As part of its “Windows Dissected” project, the BSI focused in particular on Windows Hello for Business. The findings are especially relevant for businesses. While biometric login is convenient, convenience does not automatically mean it is impervious to attack.
Windows Hello makes passwords obsolete—or so it seems
Windows Hello works on a simple principle: Instead of entering a traditional password every time, the user verifies their identity using, for example, a PIN, a fingerprint, or their face.
Technically, however, there is much more to it than that. During setup, special cryptographic keys are generated on the device. The critical private key is not supposed to leave the device. Access to it is granted only after the user has successfully verified their identity.
A so-called TPM can provide additional protection. It is a security module that manages certain information in a protected area of the computer. This is intended to make it more difficult for attackers to gain access to important keys or other security-related data.
At first glance, that sounds like a pretty robust concept. But this is precisely where the BSI's investigation comes in.
If the attacker is already inside the computer
The most important takeaway is relatively easy to explain: Windows Hello is not a magic shield against someone who already has extensive control over a computer.
Of particular interest here is the biometric information that Windows requires for facial recognition or fingerprint recognition. This data is not simply stored unprotected on the hard drive; it is stored in encrypted form in a database.
The situation becomes particularly critical when an attacker already has extensive access to the device. Under certain conditions, security mechanisms can then be bypassed, allowing the attacker to obtain information related to the biometric templates.
According to the BSI's findings, under such conditions it may even be possible to alter the stored information. An attacker could thereby associate their own biometric characteristics with another user's account.
This means that, under certain conditions, the attacker's face, for example, could subsequently be used to impersonate someone else when interacting with Windows.
However, there is one crucial caveat: This is not an attack in which someone simply scans a stranger's face from a distance and then takes control of any computer. The attacker must already have significant access to the device in question.
This is particularly interesting for businesses
That is exactly why the study should not be interpreted as a “Windows Hello is insecure” headline. The reality is more complicated.
An attacker who already has extensive control over a computer has a significant security advantage to begin with. The real question is: To what extent can an attacker exploit this control, and what additional opportunities does it create?
This becomes particularly relevant for computers used by multiple people. For example, if several employees register their biometric data on the same device, the system becomes more complex.
The BSI therefore recommends registering only one person for Windows Hello on a device, whenever possible. This may sound trivial, but it can be an important security measure in companies with shared computers.
After all, the fewer identities and pieces of biometric information stored on a single device, the smaller the attack surface.
ESS is intended to provide better protection for biometric logins
Another recommendation concerns what is known as “Enhanced Sign-in Security,” or ESS for short.
The feature is designed to ensure that the processing of biometric information relies more heavily on specially protected hardware components. However, this requires the system to have suitable cameras or fingerprint sensors and the appropriate drivers.
This is precisely a point that is often overlooked in everyday use: Security features are not automatically available on every Windows computer.
A modern Windows system alone does not guarantee maximum security. What matters is the interaction between the operating system, hardware, drivers, and the security features that are actually enabled.
For businesses, this means that if you want to use Windows Hello in a professional setting, you shouldn't just ask whether the feature is available. It's much more important to ask which security features the specific hardware actually supports.
Sometimes the good old PIN is the better choice
Also of interest is the BSI's recommendation for situations in which ESS is not available. In such cases, logging in using only a PIN may be more practical than using biometric methods.
At first glance, this seems almost contradictory. After all, biometric login is considered particularly modern and convenient.
A modern and futuristic system is not automatically secure. What matters is how well it can be protected against attacks under realistic conditions.
Companies should therefore also take additional protective measures. These include, in particular, an appropriate TPM and an encrypted hard drive. Together, these measures can help ensure that an attacker cannot easily access sensitive information even if they gain access to the device.
Home users can also take a look at their computer's security settings. Anyone who uses Windows Hello with facial recognition or a fingerprint should check what hardware is installed and whether additional security features, such as ESS, are supported.
The BSI gives us no reason to panic—but it does give us a good reason to take a closer look
The study shows one thing above all: IT security is rarely a matter of “secure” or “insecure.”
Windows Hello can be a strong and convenient alternative to traditional passwords. At the same time, there are scenarios in which its effectiveness depends on how the device is equipped and configured, as well as what privileges an attacker has already gained.
This isn't unique to Windows Hello. It's a fundamental reality of modern IT security: A system can be exceptionally well-protected at the front door—but if someone already has a key to the building, the situation is entirely different.
For this reason, companies in particular should not make the mistake of viewing biometric authentication as their sole security strategy. The overall security strategy is what matters most.
What legaldata thinks about it
The BSI's study is particularly interesting because it corrects a common misconception: New technology is not automatically secure technology.
Facial recognition and fingerprint scanning feel more secure than a password because they seem personal and modern. However, the actual level of security doesn't come from the sense of security you feel when looking into the camera. It comes from the technology behind it—and from configuring it correctly.
For companies, therefore, the question shouldn't be, "Do we have Windows Hello?" The better question is, "How secure is Windows Hello actually on our devices?"
Anyone who can't answer this question is ultimately relying on the factory settings and trusting that everything will work out. With a personal laptop, this might be considered carelessness. But in a company that handles sensitive customer data, trade secrets, or personal information, it can quickly become a real security problem.
Perhaps the most important point from the BSI study is therefore this: Security is not a single product, and certainly not just a checkbox in the Windows settings. It is an integrated system. And it is precisely this integrated system that should be reviewed regularly.




