Question
After changing the login password on a Windows PC, the following error started appearing: "403 Login denied according to access policy. No certificate has been selected."
The password change did not involve entering the old password (such as a password reset by an administrator). Please explain the cause and how to resolve this issue.
Answer
On Windows devices, the private key linked to the certificate is encrypted with the Windows account password and stored in the key container. When a password change is made without entering the old password, such as by an administrator, due to Windows OS specifications, access to the key container file where the private key linked to the certificate is stored becomes restricted, making it impossible to use the certificate.
How to resolve
Please check if the certificate can be used again by applying one of the following solutions.
Solution 1: Revert the password to the previous value
By reverting the password to its previous value, access to the key container will be restored and the certificate will become usable again.
Solution 2: Delete and reinstall the device certificate
Please delete and reinstall the certificate using the following steps.
- Delete the installed device certificate from the device.
Reference article: [Device Certificate] How to delete an installed device certificate (Windows) - From the Access Control management screen, resend the installation instruction email for the relevant device certificate.
Reference article: [Device Certificate] Resending the device certificate installation instruction email - Follow the steps in the resent installation instruction email to reinstall the device certificate.