If you are trying to install or use Microsoft Office 365 on Windows 11 but keep getting the error “Device TPM problem,” “Trusted Platform Module malfunctioned,” “Error code 80090016,” or “Keyset does not exist.” This article will guide you through several different steps you can take to solve the problem. If you're in a rush and don't have time to allocate to fixing this issue right now, you can still generally use the browser version of Office 365.
Takeaways:
- Learn how to fix “Device TPM problem" in Office 365.
- Learn how to fix “Trusted Platform Module malfunctioned" error in Office 365.
- Learn how to fix "Error code 80090016" in Office 365.
- Learn how to fix “Keyset does not exist.” in Office 365.
Table of Contents
How to Fix Device TPM Problem in Office 365
First, you'll need to check if this problem affects Office everywhere or just the installed apps/software. If the affected Microsoft 365 account works at Office.com but fails in Word, Outlook, Excel, or another desktop app, you'll need to work your way through the steps below.
On the other hand, if the account also fails in a browser, you'll need to check the account password, MFA, license, administrator restrictions, or Microsoft 365 service status first. Clearing the TPM will not fix an account that is disabled, blocked, or no longer licensed, so you clearly have a different issue to fix.
Rebuild the Office and Windows Sign-In Cache
Before deleting token data, make sure you know the affected account password and have access to its MFA method. This process signs Office and related Windows account components out locally. So you will need to sign back into a lot of things once this is done.
- Close Word, Excel, Outlook, Teams, OneDrive, and other Microsoft 365 apps.
- Open Credential Manager.
- Select Windows Credentials.
- Remove entries that start with or refer to MicrosoftOffice16. Do not remove unrelated saved credentials.
- Press Windows + R, enter %LOCALAPPDATA%\Packages, and press Enter.

- Open the folder beginning with Microsoft.AAD.BrokerPlugin.
- Open AC > TokenBroker > Accounts. If the Accounts folder is unavailable, open the TokenBroker folder instead.
- Delete the files inside the relevant TokenBroker location.
- If present, also open the Microsoft.Windows.CloudExperienceHost folder and clear the files in its corresponding AC > TokenBroker > Accounts location.

- Restart Windows and sign in to the Microsoft 365 app again.
If this fixes the problem, it was simply old/corrupted local authentication data. If the TPM or keyset error still happens, you'll have to try another solution below.
Clear the TPM After Saving Your BitLocker Recovery Key
The TPM stores hardware-backed security keys used by Windows and services such as Windows Hello and device authentication. If there is any sort of problem with this data, things are going to start behaving badly. So clearing the TPM can fix TPM-related errors. This is a delicate problem, so don't just jump into it without any prep.
Save your recovery key first
If BitLocker or Device Encryption is enabled, make sure you have your recovery key before clearing the TPM. You can follow Microsoft's BitLocker recovery guide here.
On a work or school computer, check with your administrator before clearing the TPM because organisational policies may control the device, and without them you won't be able to get things back to normal as you are hoping.
- Press Windows + R, type tpm.msc, and press Enter.
- In TPM Management, select Clear TPM.

- Confirm the action and restart Windows.
- If the firmware asks you to approve clearing the TPM during startup, confirm it.
- Sign in to Windows and allow the TPM to initialise.
- Open the Microsoft 365 app and try signing in again.
Enable Memory Integrity if Required by Your Organisation
Some managed Microsoft 365 devices have security and compliance requirements beyond a valid username and password. Memory integrity is part of Windows Core isolation and may be relevant when the device is expected to meet organisational security requirements. It's not common on home PC and gaming systems since it is rather resource-heavy, so don't enable it if it isn't 100% required.
If Memory integrity is already enabled, there is no need to change it. If your organisation requires it and it is disabled, enabling it will probably cause more problems than it solves.
- Open Windows Security.
- Select Device security.
- Open Core isolation details.
- Turn Memory integrity on.
- Restart Windows.
- Open the Microsoft 365 app and try signing in again.
If you have issues doing this, make sure all your BIOS is fully up to date and check all your drivers for new versions as well.