Likely cause
Error code 2148073494 (0x80090016 "Keyset does not exist") shows up when Windows can no longer use the sign-in key stored in the TPM or in the Web Account Manager (AAD Broker) token cache. This is almost always a device-side problem, not an account problem — it typically follows:
- An Office uninstall that removed everything, including cached credentials
- A third-party cleanup or "remove Office completely" tool that deleted data under AppData/Credential Manager
Step-by-step fix
1. Confirm the account is fine
Have the user sign in at teams.microsoft.com through a browser. If that works, the problem is confirmed to be on the device, not the account.
2. Check the device's join and key status
Open Command Prompt and run:
dsregcmd /status
Check AzureAdJoined, WorkplaceJoined, and KeySignTest. If KeySignTest shows Failed, that confirms the problem is with the device's key or TPM.
Also open tpm.msc — the status should read "The TPM is ready for use."
3. Disconnect the work account
- Go to Settings > Accounts > Access work or school and disconnect the affected work account (if it shows as "Registered").
- Go to Settings > Accounts > Email & accounts and remove the same account there.
- Open Credential Manager > Windows Credentials and delete entries starting with
MicrosoftOffice16…,msteams…, and the OneDrive cached credential.
4. Reset the AAD Broker and Teams cache
Close Teams, Outlook, and all Office apps first. Then rename (don't delete) these folders by appending .old:
%LOCALAPPDATA%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy%LOCALAPPDATA%\Packages\MSTeams_8wekyb3d8bbwe\LocalCache\Microsoft\MSTeams(clears the new Teams client cache)
Restart the device, then sign in to Teams again.
5. If it still fails
- If the device is Entra joined, check the Entra admin center to confirm the device object is still Enabled. If needed, run
dsregcmd /leaveand rejoin — make sure a local admin account is available as a fallback before doing this. - Check the user's sign-in logs in Entra (filter by their UPN and the request's correlation ID) to rule out a Conditional Access or MFA block on the same sign-in attempt.
- Clearing the TPM is a last resort only. Back up the BitLocker recovery key before doing this — clearing the TPM without a backup can lock the device out of its encrypted drive.
When you see this on more than one device
If several devices hit this at once, ask what uninstall method or cleanup tool was used — a shared script or tool that wipes AppData/Credential Manager is the usual root cause, and fixing that prevents the same issue on the next machine.
Need this handled for you?
If you'd rather not walk end users through TPM and credential resets yourself, D SCAPE's Microsoft 365 support team can triage and fix sign-in issues like this remotely as part of ongoing managed support. Talk to the D SCAPE team.