To enable smart card logon on Windows 10, you need three things: a smart card reader that Windows recognizes, a smart card with a sign-in (Smart Card Logon) certificate issued by your organization, and a PC that’s joined to a domain that trusts that certificate, usually Active Directory or Microsoft Entra ID. Once those are in place, make sure the Smart Card service is running, insert the card at the sign-in screen, choose Sign-in options > the smart card icon, and enter your PIN.
Smart card logon is mainly a business feature. On a personal PC with a Microsoft account, you can’t sign in to Windows with a smart card. The closest option is a FIDO2 security key or Windows Hello, covered at the end.
What you need
| Requirement | Who provides it |
|---|---|
| Smart card reader (USB or built in) | You or your IT department |
| Smart card or USB token with a sign-in certificate and PIN | Your organization’s certificate authority |
| Windows 10 Pro, Enterprise, or Education joined to a domain | Your IT department |
| Domain controllers set up to accept smart card sign-in | Your IT department |
Step 1: Install the smart card reader
- Plug in the reader. Most readers use the standard CCID driver, and Windows installs it automatically.
- Open Device Manager (right-click Start > Device Manager) and expand Smart card readers. Your reader should be listed without a yellow warning icon.
- If it isn’t recognized, install the driver from the reader maker’s website, then restart.
Some cards, like certain government ID cards, also need middleware from the card issuer before Windows can read them. Your IT department will tell you if you need it.
Step 2: Make sure the Smart Card service is running
- Press Windows key + R, type services.msc, and press Enter.
- Double-click Smart Card.
- Set Startup type to Automatic.
- If Service status says Stopped, click Start, then click OK.
- Also check that Smart Card Device Enumeration Service and Certificate Propagation aren’t disabled.

Step 3: Check that Windows can read your certificate
- Insert the smart card into the reader.
- Press Windows key + R, type certmgr.msc, and press Enter.
- Open Personal > Certificates. With the Certificate Propagation service running, your smart card certificate usually appears here.
- Double-click it and check that it’s valid (not expired) and that Intended Purposes includes Smart Card Logon.
You can also run certutil -scinfo in Command Prompt to see what’s on the card. You’ll be asked for your PIN.
Step 4: Sign in with the smart card
- Lock your PC or sign out.
- Insert the smart card.
- On the sign-in screen, click Sign-in options and choose the smart card icon. If you’re signed in as another user, click Other user first.
- Enter your card’s PIN and press Enter.
For IT admins: Group Policy settings
These policies are under Computer Configuration > Administrative Templates > Windows Components > Smart Card and under Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options:
- Interactive logon: Require Windows Hello for Business or smart card: forces smart card (or Windows Hello for Business) sign-in. Test before turning this on so users aren’t locked out.
- Interactive logon: Smart card removal behavior: lock the workstation or sign the user out when the card is removed. The Smart Card Removal Policy service must be running for this to work.
- Allow certificates with no extended key usage certificate attribute: lets some older cards work.
- Force the reading of all certificates from the smart card: helps when a card has several certificates.
Smart card sign-in also needs your domain controllers to have valid Domain Controller or Kerberos Authentication certificates, and the issuing CA must be trusted in the domain’s NTAuth store. Microsoft’s smart card documentation covers the full setup.
Troubleshooting
- No smart card option at sign-in. The reader isn’t detected or the Smart Card service is off. Recheck Steps 1 and 2.
- “The smart card cannot perform the requested operation” or “No valid certificates were found.” The certificate is missing, expired, or not set up for Smart Card Logon. Contact your IT department for a new certificate.
- “The system could not log you on. The domain controller certificate is not valid.” This is a server-side problem. Your IT team needs to renew the domain controller certificate.
- Card blocked after too many wrong PINs. Only your IT department or card issuer can unblock it.
- Remote Desktop. To use the card through Remote Desktop, make sure Smart cards is checked under Local Resources > More in the Remote Desktop Connection options.
Home PCs: use a security key or Windows Hello instead
If you want hardware-based sign-in on a personal PC, set up Windows Hello (PIN, fingerprint, or face) in Settings > Accounts > Sign-in options. You can also add a FIDO2 security key to your Microsoft account for passwordless sign-in to Microsoft websites. These give many of the same security benefits without a certificate authority.
Frequently asked questions
Can I use a smart card with a local account?
Not without extra third-party software. Windows’ built-in smart card sign-in is designed for domain accounts.
Can I use my government ID card to sign in to Windows?
Usually only on computers managed by that government agency or employer, since they control the certificates and domain.
Does Windows 11 support smart card logon?
Yes. The requirements and steps are the same on Windows 11.

Kermit Matthews is a freelance writer based in Philadelphia, Pennsylvania with more than a decade of experience writing technology guides. He has a Bachelor’s and Master’s degree in Computer Science and has spent much of his professional career in IT management.
He specializes in writing content about iPhones, Android devices, Microsoft Office, and many other popular applications and devices.