How to Fix “Device TPM Problem” in Office 365
The sign-in prompt in Office 365 or Microsoft 365 desktop apps may say device TPM problem, Trusted Platform Module malfunctioned, Error code 80090016, or Keyset does not exist.

This message can appear even when your password still works in a browser at office.com. That makes the desktop error look like a bad password, but it is not always reaching that stage.
Windows is also trying to prove that this user profile and this device still match the Microsoft 365 sign-in keys stored locally.
That local trust record can fall out of sync after a Windows profile migration, motherboard or TPM change, work/school account change, device rejoin, or broken Web Account Manager token.
Clearing the right local sign-in record is usually enough. Clearing the TPM itself needs more care because it can affect BitLocker and Windows Hello.
| What you see | Start with |
|---|---|
| Word, Excel, Outlook, OneDrive, or Teams fails, but the account works in the browser. | Rebuild the Office and AAD Broker sign-in cache. |
| The message includes 80090016, Keyset does not exist, or appeared after motherboard/TPM work. | Save the BitLocker recovery key, then clear TPM only if the safer cache reset did not work. |
| Windows also says the device has a problem with a work or school account. | Reconnect the account under Access work or school. |
| The PC is managed by work or school and fails device-compliance checks. | Check Memory integrity and device registration with IT if needed. |
| Only one Windows profile gets the TPM sign-in error. | Test the same Microsoft 365 account from a fresh Windows profile. |
If the same account also fails in a browser, fix the account password, MFA, license, or administrator block first. A TPM reset will not repair a Microsoft 365 account that is disabled or no longer licensed.
1. Rebuild the Office and AAD Broker Sign-In Cache
When Microsoft 365 apps fail on the desktop but the same account works online, the safest first cleanup is the local Office and Windows sign-in cache.
Microsoft’s TPM malfunctioned troubleshooting removes MicrosoftOffice16 credentials and clears TokenBroker data for Microsoft.AAD.BrokerPlugin and Microsoft.Windows.CloudExperienceHost.
This helps because those folders can keep old account tokens that Office reuses even after the account itself is fine.
This signs Office and Windows account components out locally. Make sure you know the affected account password and MFA method before deleting token data.
This is not needed when the same account fails in a browser too. Fix the Microsoft 365 account, password, MFA, or license state first.
- Close all Office, Microsoft 365, Teams, OneDrive, and Outlook windows.
- Open Credential Manager, select Windows Credentials, and remove entries that start with or refer to MicrosoftOffice16. Leave unrelated saved passwords alone.
- Press Windows + R, type %LOCALAPPDATA%\Packages, and press Enter.

- Open the folder that starts with Microsoft.AAD.BrokerPlugin, then open AC\TokenBroker\Accounts. If the Accounts folder is missing, open AC\TokenBroker.
- Delete the files inside that TokenBroker location.

- If this PC also has a Microsoft.Windows.CloudExperienceHost folder with AC\TokenBroker\Accounts, clear the files in that account-token folder as well.
- Restart the PC and sign in to the Microsoft 365 app again.
If the app signs in now, the desktop token cache was stale. If the same TPM or keyset message returns, continue to the next method below before touching work/school account registration.
If the message is mainly Another account from your organization is already signed in, the Appuals Microsoft 365 account conflict guide covers that more specific Office identity problem.
2. Clear the TPM Only After Saving the BitLocker Recovery Key
The Trusted Platform Module stores hardware-backed keys for Windows Hello, device trust, and some Microsoft 365 sign-in requests.
If Office asks for a key that no longer matches the TPM-backed record on this PC, the app can fail before the normal password prompt finishes.
Microsoft includes Clear TPM in its TPM-malfunction repair list, but this is not the same as clearing an app cache. It resets security keys Windows uses locally.
On work or school PCs, confirm the device policy first. Microsoft notes that some TPM repair steps require a Microsoft 365 admin.
This is not needed when the message disappeared after Method 1 or when the account only fails in a browser.
- Press Windows + R, type tpm.msc, and press Enter.

- In TPM Management, select Clear TPM.

- Confirm the action and restart when Windows asks.
- If the firmware screen asks you to approve the TPM clear during restart, approve it.
- Sign in to Windows, let Windows reinitialize the TPM, and then open the Microsoft 365 app again.
3. Reset the Work or School Account Connection
Microsoft 365 desktop apps do not rely only on the sign-in window inside Word or Outlook. Windows also keeps a separate Access work or school connection that tells Office whether this device is registered with the organization.
If that Windows account record is stale, Office can keep presenting old device tokens even after you type the correct password. Reconnecting the account forces Windows to request a fresh device relationship.
This is not needed when the PC is domain joined, Entra joined, or managed by work/school policy and you are not allowed to remove the connection yourself. In that case, ask the Microsoft 365 admin or help desk to check the device record first.
- Open Windows Settings.
- Go to Accounts > Access work or school.

- Select the affected Office 365, Microsoft 365, or work/school account.
- Select Disconnect.

- Restart the PC.
- Return to Access work or school.
- Select Connect and sign in again.

- Restart once more if Windows asks to complete the work/school account setup.
4. Enable Memory Integrity When the Device Is Expected to Be Compliant
On managed Microsoft 365 devices, sign-in can depend on more than a valid password. The organization may expect the PC to meet security requirements before Office accepts the device as trusted.
Microsoft’s TPM-malfunction article includes Memory integrity because it is part of Windows Core isolation. Turning it on can help when the Microsoft 365 sign-in problem is tied to local device security or compliance state.
This is not needed when your organization does not require device compliance and Memory integrity is already on.
If Windows refuses to enable Memory integrity, fix the driver warning first instead of forcing the switch through registry edits.
Appuals has a separate Core isolation and Memory integrity guide if you need a deeper walkthrough for that setting.
- Open Windows Security.
- Go to Device security.
- Select Core isolation details.

- Turn Memory integrity on.

- Restart the PC.
- Open the Microsoft 365 app and sign in again.
5. Test the Same Microsoft 365 Account in a New Windows Profile
A damaged Windows profile can keep a broken Web Account Manager store, Office identity cache, or TPM-linked user key even after the device itself is healthy.
A new Windows profile helps because it gives Microsoft 365 a clean local identity store without reinstalling Windows.
Use this after the cache, TPM, work/school account, and security-setting checks. The result is most useful when you sign in with the same Microsoft 365 account that failed in the old profile.
This is not needed when the same Microsoft 365 account already fails on several Windows profiles or several PCs. That points to an account, license, Entra ID, Intune, or tenant-side issue.
- Open Windows Settings.
- Go to Accounts > Other users. Microsoft also documents this under its Windows user-account guidance.

- Select Add account.
- Create a new local or Microsoft account.

- Change the account type to Administrator.

- Sign out of the old Windows profile and log in to the new one.
- Open Word, Excel, Outlook, or another Microsoft 365 app and sign in with the affected Microsoft 365 account.
When the new profile works, move your files carefully and rebuild Office in the new profile instead of clearing TPM again.
If the same TPM message appears in the new profile too, the problem is no longer isolated to the old Windows profile. Collect the exact error code, Correlation ID, timestamp, Windows version, device name, and whether the PC is Entra joined or managed by Intune.
A Microsoft 365 admin can then check Entra device status, Intune compliance, and sign-in logs. If you do not know who that is, Microsoft explains how to find your Microsoft 365 admin.





