What does HRESULT 0x80310072 (FVE_E_POLICY_USER_CERTIFICATE_NOT_ALLOWED) mean?

 
Previous Next
FVE_E_DV_NOT_ALLOWED_BY_GP FVE_E_POLICY_USER_CERTIFICATE_REQUIRED

FVE_E_POLICY_USER_CERTIFICATE_NOT_ALLOWED

FVE_E_POLICY_USER_CERTIFICATE_NOT_ALLOWED The operation attempted to use a user-certificate or smart-card protector, but the effective BitLocker policy forbids that protector type. The problem is policy selection, not necessarily an invalid certificate.

What to check

  • Confirm whether the target drive is allowed to use certificate-based protectors.
  • Use a permitted protector type or have the managed policy changed through the proper approval path.
  • Do not remove the existing recovery material before the replacement protector has been tested.
manage-bde -protectors -get <drive>

Microsoft: Configure BitLocker policy settings

Microsoft: manage-bde -protectors

Microsoft: manage-bde


Looking for a different code? Search another status or error code.