Recent Windows 11 updates have introduced several authentication-related issues and changes affecting user sign-in experiences. Microsoft has acknowledged that updates released since August may cause the password sign-in icon to disappear from the lock screen, although the password field remains accessible by interacting with the invisible button. Additionally, users employing FIDO2 security keys may now be prompted to set up or enter a PIN during authentication, a change implemented to comply with WebAuthn specifications and ensure consistent user verification across registration and sign-in flows.
Microsoft has not yet provided a permanent fix for the missing password icon but is working on a resolution. For the FIDO2 PIN prompt, organizations can adjust their WebAuthn configuration to discourage PIN entry if desired. These issues highlight the impact of recent Windows 11 updates on authentication workflows, requiring both end users and administrators to adapt to new behaviors and potential workarounds while Microsoft addresses the underlying problems.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft updated its support guidance to warn that Windows 11 updates released since August may make the password login icon invisible on the lock screen for affected users. The company said it is working on a fix but has not provided a timeline, and advised that the hidden option can still be selected by hovering over the blank space.
Microsoft published a support document on Tuesday warning that recent Windows 11 updates may prompt users to set up or enter a PIN when authenticating with FIDO2 security keys. The company also noted that organizations can avoid the prompt by setting WebAuthn user verification to discouraged.
Microsoft completed the rollout of the FIDO2 security key PIN prompt change with the November KB5068861 security update for Windows 11. The update can require users to set a PIN even if one was not configured during initial registration.
In September, Microsoft resolved additional problems linked to the same August Windows updates, including DRM-protected video playback interruptions, app installation failures for non-admin users, severe lag in NDI streaming software, and failed WSUS security updates. Some of these fixes were delivered through emergency updates.
After the August 2025 KB5064081 non-security preview update and later updates, some Windows 11 24H2 and 25H2 systems with multiple sign-in methods enabled began showing a blank area instead of the password sign-in icon on the lock screen. The password option still works if users hover over the invisible button.
Microsoft began rolling out a change in Windows 11 24H2 and 25H2 with the KB5065789 preview update that can prompt users to create or enter a PIN when using FIDO2 security keys. The change aligns Windows behavior with WebAuthn user-verification requirements, especially when identity providers request verification as preferred.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.