Your fingerprint is not a password, because you cannot change it after it leaks. That single fact is the argument for Aadhaar biometric lock, a free UIDAI feature that takes about a minute to enable and that most people have never touched.
It is also widely misunderstood — including by articles that tell you it does things it does not do. Here is what it actually blocks.
What Locking Does
When your biometrics are locked, UIDAI will not allow fingerprint, iris or face authentication against your Aadhaar. A requesting agency that tries gets rejected with error code 330.
All three biometric modes are covered, not just fingerprints.
What Locking Does Not Do — Read This Part
Three claims circulate widely and all three are wrong.
It does not block OTP-based authentication. Aadhaar e-KYC using an OTP to your registered mobile keeps working exactly as before. So does demographic verification. This is deliberate: locking biometrics should not lock you out of your own online services.
It does not freeze your bank account or stop DBT subsidies. Direct benefit transfers are credited against your Aadhaar-seeded account number; they do not require a fingerprint. Only transactions that need biometric authentication will fail.
It does not stop all Aadhaar misuse. Someone holding a photocopy of your Aadhaar can still attempt document-based fraud. Locking closes the biometric door, not every door.
The Threat It Actually Addresses: AePS
This is the reason the feature exists in practice.
The Aadhaar-enabled Payment System lets someone withdraw cash from a bank account using an Aadhaar number and a fingerprint, through a business correspondent with a handheld device. It is a genuinely valuable service for rural banking, and it is also the mechanism behind a long-running category of fraud in which cloned fingerprints — lifted from documents, property registration records, or silicone copies — are used to drain accounts.
Because AePS runs on Aadhaar number plus fingerprint, a biometric lock defeats it. If you never use AePS, there is very little reason to leave biometric authentication enabled.
How to Lock It
You need a working mobile number in your Aadhaar record — the whole thing runs on an OTP.
- Go to myaadhaar.uidai.gov.in.
- Log in with your Aadhaar number and the OTP.
- Open Lock/Unlock Biometrics.
- Read the confirmation, accept, and enable the lock.
You can also do it from UIDAI’s Aadhaar app, which has biometric locking built in, or at an Aadhaar Seva Kendra. If your registered number is dead, none of these will work — that has to be fixed first, and our guide to linking a mobile number with Aadhaar covers it.
Unlocking When You Need To
Some things genuinely require biometrics: opening certain bank accounts, some pension verification, property registration, certain government office procedures.
Log back into myAadhaar and unlock the same way. Complete whatever you needed to do, then lock it again immediately. Treating the unlocked state as temporary by habit is the whole discipline.
A note on something you will read elsewhere: many Indian articles state that a temporary unlock automatically re-locks after ten minutes. We could not find that duration stated in UIDAI’s own documentation, so do not rely on it. Assume it stays unlocked until you re-lock it, and check the status yourself afterwards.
Virtual ID, the Companion Habit
Locking biometrics protects one channel. The other exposure is your Aadhaar number itself, which you hand over constantly — hotels, offices, gas connections, courier verification.
UIDAI’s Virtual ID is a revocable 16-digit number you can generate and use in place of your Aadhaar number for authentication and e-KYC. The receiving party gets what it needs; it does not get your actual Aadhaar number. Generate one from myAadhaar and use it wherever a number is demanded by someone who has no business retaining it.
Who Should Definitely Do This
Anyone who does not use AePS, which is most urban account holders. Anyone whose Aadhaar photocopies are in circulation — which, after a few rental agreements and job applications, is everyone. And especially elderly relatives, who are targeted disproportionately and are least likely to notice an unexplained withdrawal quickly.
Do it for your parents while you are at it. It takes a minute per person and closes the single most damaging Aadhaar attack.
Pair it with the other checks worth doing once a year: the SIM connections registered on your name, and knowing how the digital arrest scam works before someone calls. We keep these India-specific security walkthroughs current at Techleez.
If You Think AePS Fraud Has Already Happened
An unexplained cash withdrawal from a rural or semi-urban location you have never visited is the classic signature, and it often appears on accounts belonging to people who do not check statements frequently.
Move quickly, because the reporting window shapes what can be recovered:
- Lock your biometrics immediately to stop any further withdrawals while you deal with the ones that already happened.
- Call 1930, the national cyber financial fraud helpline, and report the unauthorised transaction. Speed matters more than completeness here.
- File on cybercrime.gov.in and keep the acknowledgement number.
- Notify your bank in writing and ask them to raise a dispute. Insist on a written acknowledgement with a reference number rather than a verbal assurance at the counter.
- Ask the bank for the transaction trail — the business correspondent ID and terminal location. That detail is what an investigation runs on.
The reporting sequence and escalation ladder are the same ones set out in our guide to UPI fraud and recovery, and the same principle applies: the first hour is worth more than the next week.
Check the Rest of the Surface
Biometric lock closes one specific attack. A few adjacent habits close most of the rest, and none takes long.
Use a masked Aadhaar download whenever you must hand over a copy — it hides the first eight digits while remaining valid as identification. Write the purpose and date across any photocopy you give out, so it cannot be quietly reused for something else. Avoid handing your Aadhaar to hotels, gyms and delivery agents who ask out of habit rather than requirement, and use a Virtual ID where a number is genuinely needed.
Finally, check your Aadhaar authentication history from the myAadhaar portal every few months. It lists where your Aadhaar has been used to authenticate and when. An entry from an agency you have never dealt with is the earliest warning you will get, and it costs nothing to look.
Frequently Asked Questions
Is Aadhaar biometric lock free?
Yes, on the myAadhaar portal and in UIDAI’s Aadhaar app.
Will locking biometrics stop my DBT subsidy or pension credit?
No. Those are credited to your Aadhaar-seeded bank account and do not require a fingerprint.
Does biometric lock stop Aadhaar OTP e-KYC?
No. OTP-based and demographic authentication continue to work normally. Only fingerprint, iris and face authentication are blocked.
Does it protect against AePS fraud?
Yes. AePS withdrawals require a fingerprint against your Aadhaar, so a biometric lock prevents them.
How long does a temporary unlock last?
UIDAI does not state a duration in its published FAQs, despite the ten-minute figure repeated on many sites. Re-lock it yourself once you are done and verify the status.
Can I lock biometrics without a registered mobile number?
No. The service is verified by OTP, so you must add a working number to your Aadhaar first.
