FIX: Your Computer’s Trusted Platform Module Has Malfunctioned 80090016

If you’re an IT professional and managing Office 365 for your clients, this article may help you to resolve a Trusted Platform Module (TPM) error which your clients may see. Some of the clients while sychronization of email or contacts, will be asked for credentials. After the credentials are entered, they’re asked for same again. And following error happens then:

Something went wrong. Your computer’s Trusted Platform Module has malfunctioned. If this error persists, contact your system administrator with the error code 80090016.

Device Manager Windows 10

In this case, the server message is ‘Keyset does not exist Keyset does not exist‘. The common cause for this issue may be that TPM chip or firmware is not up-to-date. You should upgrade TPM firmware and this should help. Else, you can below mentioned fixes.

FIX 1 – Uninstall TPM And Check

1. Press W8K+ R and type devmgmt. msc in the Run, hit Enter key to open Device Manager snap-in.

Device Manager Windows 10

2. In the Device Manager window, under Security devices, right click on Trusted Platform Module [X.0], where X.0 is the version number and select Uninstall device. Confirm the uninstall operation on confirmation prompt.

Device Manager Windows 10

3. Close Device Manager, reboot and check the status of problem.

If after rebooting the machine, the issue is resolved, it means the TPM chip is really corrupted and you need to seek for its hardware replacement.

If issue still persists, try FIX 2 mentioned next.

FIX 2 – Rename Azure Active Directory Authentication Plugin

By default, Outlook or rather should I say Office 365 on Windows 10 V1703 or later uses Azure Active Directory Authentication Library (ADAL) framework-based authentication. Microsoft says, Office build 16.0.7967 or later, uses Web Account Manager (WAM) for sign-in workflows. This issue can be fixed by renaming the plugin used for the authentication purpose. You need to sign in with different account or perform this workaround from a network share and make sure the client facing this account is signed off. Then try these steps:

1. Press W8K+ R and type %appdata%\Local\Packages and press Enter key or click OK.

2. Under Packages folder, rename the Microsoft. AAD. BrokerPlugin_cw5n1h2txyewy to Microsoft. AAD. BrokerPlugin_cw5n1h2txyewy.old .

3. Note that Microsoft. AAD. BrokerPlugin_cw5n1h2txyewy folder will be automatically recreated as soon as the affected client log in. Start Outlook and allow organization to manage the device. If you get any TPM error, ignore it and continue using Outlook. The error may no longer appearing then.

Kapil Arya

About Kapil Arya

Kapil is presently a Microsoft MVP in Windows IT Pro expertise. He is Windows Insider MVP as well, and author of ‘Windows Group Policy Troubleshooting’ book. In 2015, Microsoft India accomplished him as ‘Windows 10 Champion’. Being passionate Windows blogger, he loves to help others on fixing their system issues. You can follow him for news/updates and fixes for Windows.

Hi Kapil, thanks for this. I followed your steps – but I’m facing the same issues all over again. I’ve been recommended to create a new profile, failing which, I should reformat windows. I’ve read multiple articles here a new profile has not solved the problem.

I started facing this issue of credentials after the latest windows 10 feature update 2 weeks back.

What do you recommend?

we had to replace a motherboard in a staff members laptop and started to receive this error after the new one was installed. Basically just had to rename a AAD Broker folder.

Outlook: Something Went Wrong Error 80090016

Outlook Error 80090016

Note: The this won’t affect users who are subject to MFA (Multi Factor Authentication,) so this can be enabled to solve this problem.

Solution One Code 80090016

On the affected machine navigate to;

Outlook Error something went wrong

Rename that folder to Microsoft. AAD. BrokerPlugin_cw5n1h2txyewy. old

The log out and back in again.

Solution Two Code 80090016

WARNING : This involves disabling modern authentication, do not consider this a fix, it’s more of a work around, that will stop working in or around November 2019, when modern authentication is manditory.

On the affected machine, run regedit and navigate to;

Create a new DWORD (32 Bit) Entry

  • Name: EnableADAL
  • Value: 0 (that’s a Zero)

Outlook EnableADAL

What does this do?: It disables ‘Modern Authentication’.

Then restart Outlook. (Note: It may re-prompt for a password).

Author: PeteLong

40 Comments

“What does this do?: It enables ‘Modern Authentication’.”

Hi Bruce (correct! – need more coffee)
– And don’t call me Shirley! ?

Worked a treat with a client battling this issue. Thanks!

Working perfectly.
Thank you so much ?

You made my day. It solved this 3 days pending issue in 10 seconds. That’s great.

You saved my life ! Works like a charm !!
Thank you !

I followed the steps, restarted outlook, and am still having the same issue. I wonder what else could be causing the problem.

me too, same error remains (after rebooting too)

Reg entry worked for me. THANKS.

oh man worked like charm thanks

This may resolve the issue, but I feel like jumping straight into disabling modern auth is not the best resolution.

Firstly Thanks for the feedback, If you feel there’s a better solution, please post it here for the benefit of others.

Thanks PeteLong for your hints. Nevertheless I agree with Heywood, it is not a good idea to disable Modern Authentication. And I am affraid it is the one who propose a solution who should estimate the impact and offer other options when it has undesired consequences.

Guys, Do some research! if a tenant requires MFA/ADAL or OAuth they will have it enabled at an ORG level, so disabling it on a client machine will make no difference whatsoever. If you disable it on a client and it can still connect it was not being used anyway.

While I appreciate all feedback, think like technicians, if you don’t like a solution, then either find a better one, and communicate it to your peers, or don’t implement the solution that I propose. Remember I’m providing this information for free, for the benefit of the technical community.

If modern auth is not working for a single client then disabling it is a workaround. While this may get someone out of a tough spot, calling it a solution is misleading. Nothing wrong with a workaround, but it is best to at least highlight the risks of disabling the more secure authentication method if that is what you are recommending.

You saved my day and swett
Thank you so much

You saved my working hours, Thank you very much….

Great, working perfectly. Thank you so much.

This is actually a poor solution if you are in an enterprise environment as it disables modern authentications and defaults to legacy.

A better option is to rename the folder C:\users\$dir\AppData\Local\Packages\Microsoft. AAD. BrokerPlugin_cw5n1h2txyewy to. old and log the user in again.

If that’s the better solution, it’s the first one that’s been offered, can anyone confirm that this resolves the issue? If so I’ll update ether article accordingly?

Pete I tried the tip from BraveSpear and it worked for me

Thank you Andrew article updated accordingly. Kudos to BraveSpear.

BraveSpear’s solution worked for me as well.

#1 Worked for me. Thanks

worked for me, Thanks for the tips

Solution 1 worked perfectly…

I had similar issue that was resolved by uninstalled the “Trusted Platform Module” in Device Manager and restart the computer.

Wouldn’t let me change the name of the file like in solution 1 because it said that the file was in use. Uninstalling from device manager worked for me as well, so thank you!

dude you saved my day. thanks for this pinpoint solution.

trying method one but file is locked and cannot be renamed. Used by another app. But I do not know which one…

Make sure Outlook is closed, and it’s not running in the task tray, and no other users are logged in.

The registry change worked fine, thanks, until we can apply a better correction.

Renaming the folder doesn’t work in all situations. I’ve now encountered this specific issue on 5+ machines. For several of them, renaming the folder did the trick. For the rest, I’ve ended up recreating the user profile, after trying everything else. The question is, why is this becoming a regular thing?

Thanks, this information is very usefull

Muchas gracias por compartir esta información, para mi la solucion #1 no funcionó, la opcion de Regedit SI.

Tal como alguien pregunta más arriba, sería interesante saber porque se está produciendo esta situación.

Solution 2 its working for me thank you man

Hi.
This worked on a computer that has issues whith all kinds of authentication. Outlook, OneDrive, Chrome sync account, Adobe Cloud account and so on.
Well, it worked for a while that is. After three or four re-boots and about the same ammount of shut-downs the issues are back.
Thanks anyway…

Hi, thank you so much, Solution N1 work for me! Like Joakim said, I don’t know if the fix will work for longer than 3-4 reboots. I will let you know. Thank you.

Thanks for this – Solution 1 was part of the solution for me.

This user seems to have a damaged TPM – and if I enforce MFA in the Admin console for that user, it generates an error on the endpoint, saying malfunction in TPM.

If I disable MFA for that user, he still has to accept a login prompt in the Authenticator, and all his apps seem stable and fine with the saved login.

Turn on MFA again – problem returns.

Disabling MFA for that user (perhaps as long as the user had previously enrolled his device to authenticate logins) seems to retain the MFA security, but not contact the TPM for whatever generates the problem.

So, there could be 3 things going on simultaneously:
1. Cooked TPM
2. Enabling enforcement of MFA generates the TPM error
3. bad data of something in the path specified in Solution 1 above.

Maybe this helps someone!
Live long and prosper

tried solution 1 but windows says the file to rename is being used by another program. what program uses this so I can close it?

How to Fix Error Code 0x80090016 for PIN and Microsoft Store in Windows 10

How to Fix Error Code 0x80090016 for PIN and Microsoft Store in Windows 10

If you encounter Error Code 0x80090016 while trying to create a PIN or when you are using Microsoft Store, then you’ve come to the right place as this post will guide you in how you can fix this problem.

Recently some users reported that they were unable to sign in or set up the Windows 10 Login PIN. Note that the potential fixes for this issue are totally different in both scenarios.

Here’s the error message you get when you encounter the PIN related error:

“Something went wrong, We weren’t able to set up your PIN. Sometimes it helps to try again or you can skip for now and do this later.”

On the other hand, here’s the error message you get for the Microsoft Store-related error:

“Try that again, Something happened on our end and we couldn’t sign you in.”

Here are some potential fixes you can try to fix the Error Code 0x80090016 in the Microsoft Store:

Option 1 – Try to sync the Date and Time

The first thing you can try is to sync the Date and Time of your computer as wrong Date and Time settings is one of the most common causes of connection problems like the Error Code 0x80090016. This is because of the incompatibility between the SSL Certificate validation date and the System Clock. Thus, you have to sync your System Clock. Refer to the steps below to do so.

  • Start by tapping the Win + I keys to open the Windows Settings.
  • Next, go to Time & Language > Date & time.
  • From there, turn the toggle on for the “Set time automatically and Set time zone automatically” option on the right side panel.
  • After that, click on Region & language located on the left side panel and make sure that the Country or region on the right side panel is set to the country you live in.
  • Now close the Settings app and restart your computer and see if it fixes the problem or not.

Option 2 – Try to re-register the Microsoft Store app via PowerShell

  • Tap the Win + X key combination or right click on the Start button and click on the Windows PowerShell (Admin) option.
  • If a User Account Control or UAC prompt appears, just click on Yes to proceed and open the Windows PowerShell window.
  • Next, type in or copy-paste the following command to re-register the Microsoft Store app and tap Enter:

powershell — ExecutionPolicy Unrestricted Add-AppxPackage — DisableDevelopmentMode — Register $Env:SystemRootWinStoreAppxManifest. xml

  • Wait for the process to be completed and then restart your computer.

Option 3 – Try to reset the Microsoft Store cache

Just like browsers, Microsoft Store also caches as you view apps and games so it is most likely that the cache is no longer valid and must be removed. To do so, follow the steps below.

  • Right click on the start button and click on Command Prompt (administrator).
  • Next, type in the command, “exe” and tap Enter. Once you do, the command will clear the cache for the Windows Store app.
  • Now restart your PC and afterwards, try opening Microsoft Store again and then see if Error Code 0x80090016 is resolved or not.

Option 4 – Try to run the Windows Store Troubleshooter

The Windows 10 Store Apps Troubleshooter will help you in fixing the Error Code 0x80090016. This is a great built-in tool from Microsoft that helps users fix any app installation issues. So this is worth a try to solve the problem. This built-in tool also helps you fix the Windows 10 Store if it isn’t working.

To use the Windows Store Troubleshooter, follow the steps below.

  • Tap Win + I keys again to open the Windows Settings panel.
  • Go to Update & Security and then go to Troubleshoot.
  • On your right hand side, scroll down to find the Windows Store Apps and then click on Run the troubleshooter option and see if it fixes the problem.

On the other hand, you can use the options below if you encounter Error Code 0x80090016 while setting up your PIN.

Option 5 – Try to manage the NGC Folder

  • You need to boot your computer into Safe Mode first.
  • Next, delete all the contents of the NGC folder and you can do that by taking ownership of the folder first. To do so, refer to these sub-steps:
    • First, locate the concerned folder and right click on it then select Properties.
    • Next, click on the Edit button in the Properties window and click OK to confirm if you got a User Account Control elevation request.
    • After that, select user/group from the permission windows or click on the Add button to add other user or group. It would be best if you add “Everyone” to give permission.
    • Then check “Full Control” under the “Allow” column to assign full access rights control permissions.
    • Now edit the permission to Full Control for “Everyone”.
    • Click OK to save the changes made and then exit.

    Option 6 – Try to use the Group Policy Editor

    • Tap the Win + R keys to open the Run dialog box
    • Then type “gpedit. msc” in the field and hit Enter or click OK to open the Group Policy Editor.
    • Next, navigate to this setting: Computer Configuration > Administrative Templates > System > Logon

    • After that, double click on “Turn on convenience PIN Sign-in” and set its radio button to Enable. This policy setting has the following description:

    “This policy setting allows you to control whether a domain user can sign in using a convenience PIN. If you enable this policy setting, a domain user can set up and sign in with a convenience PIN. If you disable or don’t configure this policy setting, a domain user can’t set up and use a convenience PIN. Note: The user’s domain password will be cached in the system vault when using this feature. To configure Windows Hello for Business, use the Administrative Template policies under Windows Hello for Business.”

    • After you set the radio button to Enable, it will turn on the Logins using PIN. Note that setting the radio button to Disabled or Not Configured will turn off the Logins using PIN.
    • Now exit the Group Policy Editor and restart your PC so that the changes can take effect.

    If the fixes given above didn’t help you in fixing the Error Code 0x80090016 in Windows 10, worry not, as there is still another option that could help you. This option is Restoro, also known as a “one-click” solution. What makes Restoro better than other system utility tools or antivirus programs is that aside from helping you free up disk usage and memory in your computer, it helps you in fixing whatever issue your system is facing. Aside from that, it also cleans out your computer for any junk or corrupted files that help you eliminate any unwanted files from your system. This is basically a solution that’s within your grasp with just a click. It’s easy to use as it is user-friendly. For complete set of instructions in downloading and using it, follow the steps below.

    Perform a full system scan using Restoro. To do so, follow the instructions below.

    Источники:

    https://www. kapilarya. com/fix-your-computers-trusted-platform-module-has-malfunctioned-80090016

    https://www. petenetlive. com/KB/Article/0001549

    https://errortools. com/ru/windows/how-to-fix-error-code-0x80090016-for-pin-and-microsoft-store-in-windows-10/

Понравилась статья? Поделиться с друзьями:
Добавить комментарий

;-) :| :x :twisted: :smile: :shock: :sad: :roll: :razz: :oops: :o :mrgreen: :lol: :idea: :grin: :evil: :cry: :cool: :arrow: :???: :?: :!: