Microsoft’s optional July 28, 2026 preview update KB5101684 unlocks a long-awaited capability: Windows Hello Enhanced Sign-in Security (ESS) now works with external fingerprint sensors. The change, delivered in builds 26100.8973 for Windows 11 24H2 and 26200.8973 for version 25H2, extends the more secure biometric authentication to any desktop or laptop that lacks an integrated fingerprint reader — including Copilot+ PCs. But the rollout comes with a compatibility catch that could trip up eager users.
External fingerprint sensors join the ESS family
Until now, Windows Hello ESS was largely exclusive to devices with a built-in fingerprint module. KB5101684 breaks that mold. After applying the preview update, you can plug in a supported USB fingerprint reader and enroll your fingerprints right from Settings > Accounts > Sign-in options. The setup wizard guides you through scanning your finger, and once enrolled, you can use that external reader to sign in to Windows, authenticate apps, and — critically — use passkeys tied to your Microsoft account or other services.
Microsoft first teased this expansion in the January 2026 KB5074105 update, but only now is the feature arriving on stable builds. The company describes the change succinctly in its support documentation: “Windows Hello Enhanced Sign-in Security (ESS) now supports external fingerprint sensors.” For desktop power users and anyone with a tower PC, that’s a significant quality-of-life boost. No more typing a PIN or password every time you unlock; just a quick tap on a USB stick.
The update itself is not a security patch but rather a cumulative preview, meaning it bundles non-security fixes and features destined for next month’s Patch Tuesday. Installation is voluntary via Windows Update under “Optional updates” or through the Microsoft Update Catalog.
ESS isn’t just any Windows Hello
Windows Hello has been around for a decade, offering camera-based face authentication and fingerprint logins. But the “Enhanced Sign-in Security” flavor is different. ESS bakes in additional hardware-backed protections: biometric data never leaves the device’s secure processing environment, and the authentication pipeline is isolated from the rest of the operating system. This is the same security foundation that Microsoft requires for features like Recall on Copilot+ PCs, which snap constant screenshots and need to ensure only the authenticated user can access them.
In practical terms, ESS makes your fingerprint login much harder to spoof or intercept. However, that elevated security demands compatible hardware. A generic Windows Hello fingerprint reader — even one that works perfectly with the older, non-ESS version — won’t suffice. To retain ESS, your external reader must explicitly support the Enhanced Sign-in Security protocol.
Microsoft states plainly: “If you want to keep Enhanced Sign-in Security turned on, you need a device that supports Enhanced Sign-in Security.” That includes not just the reader itself but also the driver and firmware stack. So far, the list of confirmed ESS-compatible external readers is short, and it will likely grow as hardware makers certify their devices.
The reader you buy matters more than ever
For home users, the takeaway is simple: don’t impulse-buy the cheapest fingerprint USB dongle on Amazon. A conventional reader will plug in and appear to work, but Windows will ask you to disable ESS before you can enroll your prints. And that toggle is destructive. Microsoft warns that turning off ESS removes all existing biometric enrollments and deletes any passkeys associated with the account. You’ll need to set those up again from scratch — including passkeys for websites and Microsoft 365.
If you’re configuring a desktop for a family member or upgrading an older PC, check the manufacturer’s specifications for “Windows Hello Enhanced Sign-in Security” or “ESS” compatibility. Don’t rely on mere “Windows Hello” certification. The difference is not cosmetic; it’s the difference between a hardened credential guard and a regular biometric scan.
How Microsoft got here
The road to external ESS support has been incremental. Windows Hello debuted with Windows 10 in 2015, offering basic biometric authentication. “Enhanced Sign-in Security” arrived later, initially tied to TPM 2.0 and specific fingerprint modules embedded in laptops. Microsoft pushed the feature aggressively in 2024 and 2025 as it prepared Copilot+ PCs, which require ESS to enable Recall — a camera-roll-like feature that stores encrypted snapshots of your activity.
In January 2026, KB5074105 previewed the ESS-for-external-sensors capability, but the code didn’t make it to the monthly mandatory updates. The July 2026 preview is the first time mainstream users on current versions (24H2 and 25H2) get to try it. Notably, Microsoft hasn’t backported this to Windows 10, which exits support in October 2025 and thus won’t receive such feature additions.
For IT administrators, this rollout matters beyond convenience. If your organization enforces ESS through policy, the Settings toggle may not even appear. Group Policy or Intune can lock down Windows Hello to require ESS, effectively blacklisting incompatible readers. Before ordering a fleet of external fingerprint scanners, admins should test a sample unit against a managed PC running the preview update and verify that the sign-in option remains available without any policy complaint.
What to do if you want to use it
First, ensure your PC is running Windows 11 24H2 (build 26100) or 25H2 (build 26200) and that you’ve applied the July preview update. Check Settings > Windows Update > Advanced options for KB5101684. It will be listed as an optional quality update. If you don’t see it, wait — Microsoft is throttling the rollout, and it may take a few days to appear.
Second, locate a fingerprint reader that explicitly states “Enhanced Sign-in Security” compatibility. Check the vendor’s documentation or reach out to their support. When you plug in the device, Windows should automatically recognize it and offer a notification to set up fingerprints. If you instead see a message saying ESS must be off, the reader won’t work with ESS on.
Third, enroll under Accounts > Sign-in options > Fingerprint recognition (Windows Hello). The system will ask you to create a PIN as a backup; this is normal. After enrollment, lock your PC (Windows key + L) and try signing in with a finger tap. You can enroll multiple fingers for redundancy.
If you already use a non-ESS fingerprint reader and want to keep ESS active, you’ll have to replace the reader. Disabling ESS is possible if you don’t rely on passkeys or Recall, but remember that all existing biometric credentials vanish, and you must re-create any passkeys stored on the device.
What’s next for biometrics on Windows
This update signals Microsoft’s ambition to make ESS the default standard for all biometric sign-in — not just on premium laptops but across the Windows ecosystem. Expect a wave of “ESS certified” USB fingerprint readers to hit the market in the coming months, much as we saw a rush of “Windows Hello” cameras after Windows 10 launched. Hardware partners already building TPM-backed sensors will likely have an edge.
For now, the feature remains optional and preview. But once it graduates to a mandatory update (likely in August 2026 Patch Tuesday), the pressure on peripheral makers to certify will ramp up. Desktop users who’ve envied the fingerprint convenience of modern laptops are finally getting a seat at the table — provided they choose their hardware wisely.