Microsoft is expanding one of the least understood security features in Windows 11. Beginning with the August 2026 update, Enhanced Sign-in Security (ESS) now supports compatible external fingerprint readers, extending the company’s most secure Windows Hello experience to devices without built-in biometric hardware.
The timing couldn’t be better because Enhanced Sign-in Security has confused users ever since Microsoft introduced it. Some users assume it’s simply a newer version of Windows Hello, while others think it’s reserved for businesses or Copilot+ PCs.
The reality is that Windows Hello and Windows Hello Enhanced Sign-in Security use the same sign-in experience, but they protect your biometric data in different ways.
After spending time digging through Microsoft’s support page, I think that’s the distinction most explanations miss. Enhanced Sign-in Security isn’t about making facial recognition more accurate or fingerprint sign-in faster. It’s about making the entire authentication process harder to attack.
Standard Windows Hello is already one of the best security features
Before the Enhanced Sign-in Security feature was introduced, Windows Hello had already replaced passwords with a much stronger authentication model.
Instead of storing passwords that can be stolen or reused, Windows Hello creates cryptographic credentials that are attached to the Trusted Platform Module (TPM) available on your computer. Facial recognition and fingerprints are used only to unlock those credentials, and your biometric templates remain on the device rather than being uploaded to Microsoft’s servers.
For the average home user, that already provides excellent protection against phishing, password reuse, and stolen credentials.
The Enhanced Sign-in Security feature doesn’t replace the architecture already in place. Instead, it builds another layer on top of it.
The real difference is where the trust is placed
This is where the comparison becomes interesting. Using the standard Windows Hello, the operating system relies on the system to process biometric authentication after receiving data from the trusted sensor. Enhanced Sign-in Security moves much of that work into isolated, hardware-protected environments.
When using the Enhanced Sign-in Security feature, Microsoft improves that trust. Instead of allowing sensitive biometric operations to occur in the normal Windows environment, the feature isolates them using Virtualization-Based Security (VBS) and Trusted Platform Module (TPM) 2.0 technology.
The algorithms for facial recognition run in a protected memory region, secure fingerprint readers perform matching within the hardware itself, and communication between the biometric sensor and the operating system is encrypted and isolated.
In other words, Windows Hello protects your credentials, and Windows Hello Enhanced Sign-in Security protects both your credentials and the path your biometric data takes before Windows 11 authenticates you.
Fingerprints show the biggest difference
Using a standard Windows Hello fingerprint reader, the sensor captures your fingerprint, and Windows 11 verifies it securely using the operating system and TPM-backed credentials.
An ESS-compatible fingerprint reader moves more of that process into the hardware itself. These readers include a dedicated secure processor, store fingerprint templates inside the device, contain a Microsoft-issued certificate that proves they’re trusted hardware, and establish an encrypted communication channel with the operating system. Instead of receiving raw biometric data, Windows 11 receives only the authentication result.
Microsoft hasn’t explained why ESS still doesn’t support external Windows Hello cameras (likely because USB can be a vector for attack). However, its support page shows that enhanced security for facial recognition relies on specific camera hardware, firmware, and protected memory through Virtualization-Based Security (VBS), whereas ESS fingerprint readers can perform biometric matching inside certified hardware. That architectural difference may explain why Microsoft expanded support for external fingerprint readers first.
The practical benefit is a smaller attack surface. In simple terms, even if malware gains elevated privileges, it has fewer ways to interfere with the biometric authentication process.
Should you enable Enhanced Sign-in Security?
If your computer doesn’t support Enhanced Sign-in Security, there’s no reason to worry. The standard security of Windows Hello remains one of the strongest consumer authentication systems available, and it’s already a significant upgrade over passwords.
However, if your device includes Enhanced Sign-in Security-compatible hardware, or you’re planning to buy a new external fingerprint reader that supports the feature, I’d recommend enabling it and leaving it on.
Not because Windows Hello suddenly became insecure, but because the enhanced option can add an extra layer of security. If your hardware supports it, there’s little downside to leaving it enabled.
How to enable the enhanced security feature
If the feature is available for your Windows Hello-compatible authentication device, you can enable it by going to Settings > Accounts > Sign-in options.
Once the USB fingerprint reader is connected and recognized by the operating system, on this page, under the “Additional settings” section, check the state of the “Enhanced sign-in security” setting.
If your system wasn’t previously running ESS, you may see a prompt showing “Pending set up” or “Update PIN.”
If the “Update PIN” option shows up, use it to complete the setup. On the other hand, if you see the “Pending set up” option, then configure the “Fingerprint recognition” feature under the “Ways to sign in” section.
One important note. When upgrading your system to Enhanced Sign-in Security, Windows 11 will remove any existing non-ESS biometric enrollments and associated credentials to ensure a clean, secure environment. You will need to refresh your PIN and register your fingerprints again using the new sensor. Once complete, the ESS toggle will show as enabled.
Also, while the feature is turned on, you won’t be able to use peripherals that do not support the security feature.
Windows Central’s Take
Microsoft hasn’t done itself any favors with the name “Enhanced Sign-in Security.” It sounds like an entirely new authentication system, when in reality it’s an evolution of Windows Hello that strengthens how biometric authentication is processed behind the scenes. A lot of users will never notice the difference because the sign-in experience is exactly the same.
What makes the August 2026 Security Update important isn’t that Windows Hello suddenly became more secure, as the standard Windows Hello has long been one of the strongest authentication systems available on consumer devices. The real significance is that the company is lifting the limitations by adding support for compatible external fingerprint readers.
If your computer already supports Enhanced Sign-in Security, I’d leave it enabled. If it doesn’t, I wouldn’t replace perfectly good hardware to get the feature because standard Windows Hello is already an excellent authentication system. However, if you’re buying a new fingerprint reader for your computer, choosing an Enhanced Sign-in Security-compatible model is the better long-term investment since Microsoft is clearly expanding support for that ecosystem.
Do you think Enhanced Sign-in Security is worth using, or is standard Windows Hello already enough for your needs? Let me know in the comments.
More resources
Explore more in-depth how-to guides, troubleshooting advice, and essential tips to get the most out of Windows 11 and 10. Start browsing here:
Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.