How to fix the TPM has malfunctioned error 80090030
This is a Trusted Platform Module error that blocks signing in to Microsoft 365, Teams or Outlook. It usually points at a device registration or sync problem, or stale cached credentials. Jump to your situation below or work through the methods in order.
By Neeraj Singh ~6 min Updated Jun 2026 89% found this helpful
Error message
80090030. Your computer's Trusted Platform Module has malfunctioned. The device required by this cryptographic provider is not ready for use.
Summary
Error 80090030 is one of the Trusted Platform Module has malfunctioned messages, shown when you try to sign in to Microsoft 365, Teams or Outlook. The text, the device required by this cryptographic provider is not ready, points at a device registration or Entra ID sync problem, or, very commonly, stale cached credentials that no longer match the TPM-backed keys. It is not usually a hardware failure. The fix works through the account and credential layer first: clear the old Office and Windows credentials in Credential Manager, disconnect and reconnect your work or school account to re-register the device, and reset the Microsoft 365 activation. If those do not clear it, clear the TPM and update its firmware. Renaming the NGC folder rebuilds the Windows Hello data when a PIN is involved.
What this error means
Microsoft 365 and Windows store sign-in keys protected by the TPM. The 80090030 wording, the cryptographic device is not ready, means the app asked the TPM for those keys and the request could not be satisfied, usually because the device registration or the cached credentials are out of sync rather than the chip being broken.
That is why the first fixes are about the account and credentials, not the hardware. Clearing the stale credentials and re-registering the device gives the apps fresh, matching keys. Clearing the TPM and updating firmware are the deeper steps for the rarer cases where the chip's state really is the problem.
Common causes
Stale or corrupt cached Office credentials.
A device registration or Entra ID sync failure.
A corrupt NGC folder behind the Windows Hello PIN.
Outdated or mismatched TPM firmware.
Security software blocking the AAD broker plugin.
A wrong system clock breaking token validation.
Expert insight
“80090030 sounds like the chip has died, but it almost never has. The apps asked the TPM for your sign-in keys and the cached credentials no longer line up, usually after a password change or a sync hiccup. So I clear the old Office credentials in Credential Manager, disconnect and reconnect the work account to re-register the device, and reset the Office activation. That fixes the vast majority. Clearing the TPM is the heavy hammer I only reach for if the gentle steps fail.”
2Then set up the PIN again under Settings, Accounts, Sign-in options.
Method 5
Clear the TPM
1Open Settings, Device security, Security processor details, Security processor troubleshooting, and choose Clear TPM (or run tpm.msc, Clear TPM).
2This removes corrupt TPM-stored keys; back up anything protected by the TPM first.
3Restart and sign in again.
Method 6
Update the TPM firmware and BIOS
1Install the latest BIOS or UEFI firmware from your PC or motherboard maker, which includes TPM firmware updates.
2An outdated or mismatched TPM firmware causes these errors.
3Confirm the TPM is ready afterwards in tpm.msc.
80090030 is almost always a credentials or registration problem, not a dead chip, so start by clearing the stale Office credentials and reconnecting your work account, then reset the Office activation. Only clear the TPM and update its firmware if those gentler steps do not resolve it. Renaming the NGC folder fixes a PIN-related variant.
Frequently asked questions
What does TPM error 80090030 mean?
It is a Trusted Platform Module has malfunctioned error meaning the cryptographic device is not ready, usually a device registration or sync problem, or stale cached credentials, during Microsoft 365 or Teams sign-in.
How do I fix 80090030?
Clear the old Office credentials in Credential Manager, disconnect and reconnect your work or school account, and reset the Office activation. Clear the TPM only if those do not work.
Is my TPM chip broken?
Usually not. Despite the wording, 80090030 is nearly always a credentials or registration issue. Clearing stale credentials and re-registering the device fixes most cases without touching the hardware.
Will clearing the TPM lose data?
It can remove keys and anything protected by them, so back up first, and note your BitLocker recovery key. Clearing the TPM is a later step after the credential fixes.
Could antivirus cause it?
Yes. Security software can block the Microsoft AAD broker plugin that handles authentication, producing this error. Add an exception for it or test with the security tool paused.
Why rename the NGC folder?
The NGC folder holds the Windows Hello PIN data. If it is corrupt, signing in fails with TPM errors. Renaming it makes Windows rebuild it, after which you set up the PIN again.
Still not working?
If clearing credentials, re-registering and resetting activation do not help, clear the TPM and update its firmware, then set up Windows Hello again. If it persists across a clean account, the TPM hardware or firmware may genuinely be faulty and worth a vendor check. You can also submit your error to us for a tailored fix.