| Previous | Next |
| CO_E_FAILEDTOQUERYCLIENTBLANKET | CO_E_ACCESSCHECKFAILED |
CO_E_FAILEDTOSETDACL
COM could not place a DACL in the security descriptor
CO_E_FAILEDTOSETDACL is HRESULT 2147549481 (0x80010129) from winerror.h. The documented description is “Unable to set a discretionary ACL into a security descriptor.” The relevant context is the COM IAccessControl, DCOM client identity, trustee translation, token inspection, security descriptor, ACL, or serialization workflow.
What to verify
Verify that the ACL is structurally valid, self-relative versus absolute form is correct, and owner/group fields satisfy the consuming API. That boundary prevents this result from being misclassified as corruption, network failure, or a reason for an unsafe automatic retry.
Where it is encountered
- This result can be returned during IAccessControl initialization, access checks, owner/trustee processing, and serialized ACL persistence.
- This result can be returned during server-side DCOM impersonation, client blanket inspection, token and SID lookup.
- It can be returned during security descriptor construction, DACL canonicalization, file-backed policy storage, or legacy NetAccess migration.
The immediate focus is construction or update of a COM access-control security descriptor where the discretionary ACL cannot be attached or validated.
Correct handling and recovery
Rebuild the descriptor with documented security APIs, validate every ACE and SID, and apply the DACL only after canonical ordering.
Reconcile partial output and server-side effects before attempting the operation again.
Difference from nearby HRESULTs
It is descriptor assembly failure; CO_E_ACCESSCHECKFAILED occurs when evaluating an assembled descriptor.
Developer and administrator guidance
Change the smallest component, identity, ACL, package, or threading boundary that the evidence identifies, then reproduce the same operation.
Practical scenario
A configuration tool builds a self-relative descriptor but calls a setter that expects absolute pointers. It converts format explicitly and verifies the resulting DACL.
References
Looking for a different code? Search another status or error code.