Microsoft is expanding Windows Hello Enhanced Sign-in Security to compatible external fingerprint readers, starting with the August 2026 servicing update for Windows 11 version 24H2. The change means you can now add the highest tier of biometric protection to a desktop PC or a laptop without a built-in ESS‑capable sensor—all through a certified USB peripheral.

The Concrete Change in August 2026

Until now, Enhanced Sign-in Security (ESS) was largely confined to Secured-core PCs, premium business laptops, and devices with tightly integrated biometric hardware. The August update lifts that lid: compatible third-party fingerprint readers that carry a Microsoft-issued manufacturing certificate and support the Secure Device Connection Protocol can establish an isolated, encrypted authentication channel to Windows. When you enroll a fingerprint through one of these readers with ESS active, the matching happens inside the reader’s own secure processor instead of passing raw biometric data to Windows for comparison. The operating system only receives a cryptographically verified “match” or “no-match” result.

Microsoft’s support documentation makes it clear that while fingerprint peripherals are now in scope, external camera modules still are not. If you have an external Windows Hello IR camera, it will continue to work for standard Windows Hello sign-in, but it cannot provide the ESS-enhanced face-authentication path. The company hasn’t publicly detailed why cameras remain excluded, though its technical requirements hint at the complexity: ESS face recognition relies on a chain of certified camera modules, firmware, and protected memory regions that are harder to assure across generic USB webcams.

What Enhanced Sign-in Security Actually Protects

Standard Windows Hello already replaces reusable passwords with device-bound cryptographic keys protected by the TPM. Your fingerprint or face is only used locally to unlock that key, and the biometric template never leaves your PC. For most home users, this is already a substantial step up from a password.

ESS adds an extra armor layer to the authentication pipeline. It places sensitive biometric operations inside Virtualization-Based Security (VBS) enclaves and requires match-on-chip behavior from fingerprint sensors. The goal is to block attacks where malware with deep system access tries to inject a fake fingerprint sample, replay a captured authentication sequence, or tamper with the communication between sensor and OS. The sign-in screen looks identical—you still touch a reader or enter a PIN—but the back end is hardened against sophisticated local compromise.

If your PC already has an ESS-capable internal fingerprint reader or IR camera, the toggle may have appeared in Settings months ago. The August update simply extends that same architecture to external USB peripherals that meet the new hardware requirements.

Who Gains the Most from This Update

Desktop users finally get a straightforward path to ESS. Many desktops don’t ship with built-in biometric hardware, and add-on USB readers were often stuck at standard Windows Hello security. Now, if you buy a reader that explicitly advertises ESS compatibility, you can bring your desktop into the same security tier as a modern business laptop.

Home users with a compatible reader can flip the switch and forget about it. There’s no noticeable change in routine. If you frequently handle sensitive files or simply want the strongest available consumer-grade biometric lock, ESS is a sensible default when your hardware supports it.

IT administrators should note two system-wide effects. First, ESS is a machine-wide setting, not a per-user preference. Once enabled, all users must re-enroll their biometrics the next time they sign in. Second, the transition deletes existing non‑ESS biometric enrollments and any associated passkeys—an intentional cleanup to ensure a secure baseline. That means every user will need to create a new PIN, re-register fingerprints, and re‑provision affected passkeys. For shared devices, plan a brief interruption.

How We Got Here

Microsoft introduced Enhanced Sign-in Security during the Windows 11 era, initially as a feature gated behind Secured-core PC requirements. It gradually expanded to more hardware, but external fingerprint readers remained a gap. Windows Central’s August 2026 report confirmed that certified USB readers were joining the supported list, and subsequent Release Preview builds showed the feature in testing. The phased rollout Microsoft mentions means the option may not appear instantly on every compatible machine; it will become available through Windows Update in waves.

What to Do Now

  1. Check your Windows version. You need Windows 11 24H2 or later and the August 2026 cumulative update installed.
  2. Connect the external reader. Make sure Windows recognizes it. If the device came with a driver, install it.
  3. Open Settings > Accounts > Sign-in options. Scroll to “Additional settings” and look for “Enhanced sign-in security.”
  4. Interpret what you see.
    - “Pending set up” – Windows sees the reader but needs you to enroll a fingerprint first.
    - “Update PIN” – Your current sign-in setup requires a refresh before ESS can be enabled. Follow the prompt.
    - Toggle is on/off – If the toggle already works, you’re set.
  5. Enroll your fingerprint. Go to “Fingerprint recognition (Windows Hello)” under “Ways to sign in” and follow the on-screen instructions.
  6. Re‑provision passkeys. If you relied on Windows Hello‑bound passkeys, they will have been removed during the transition. Re‑create them in the affected apps or websites.

Important caveat: While ESS is enabled, Windows will ignore any non‑ESS biometric sensors. If you have an older “Windows Hello compatible” USB reader, it will stop working for sign-in. You can turn ESS off to restore standard Hello support, but that also removes the hardware‑isolated protection.

What Comes Next

The expansion to external fingerprint readers opens a door, but it also sharpens the question about external cameras. Microsoft has not signaled any timeline for bringing ESS to USB‑based Windows Hello cameras. Until it does, desktop users who prefer face authentication will need to choose between the convenience of an external IR camera and the higher assurance of an ESS‑certified fingerprint reader.

For now, if you’re buying a biometric peripheral for a Windows 11 machine, look for one that explicitly lists Enhanced Sign-in Security compatibility. It’s the clearest way to future‑proof your setup as Microsoft continues to harden the authentication backbone of its flagship OS.