What does HRESULT 0x80310086 (FVE_E_POLICY_PROHIBITS_SELFSIGNED) mean?

 
Previous Next
FVE_E_NON_BITLOCKER_OID FVE_E_POLICY_CONFLICT_RO_AND_STARTUP_KEY_REQUIRED

FVE_E_POLICY_PROHIBITS_SELFSIGNED

FVE_E_POLICY_PROHIBITS_SELFSIGNED The selected certificate is self-signed, but the effective BitLocker policy requires a certificate issued by an approved certification authority. The certificate is rejected because of the policy trust requirement.

What to check

  • Confirm whether the certificate is self-signed and whether it is the intended certificate for the protector.
  • Obtain a certificate through the organization’s approved enrollment path if policy requires CA-issued certificates.
  • Do not simply import an unrelated certificate; it must satisfy the BitLocker protector policy and user requirements.
manage-bde -protectors -get <drive>

Microsoft: Configure BitLocker policy settings

Microsoft: manage-bde -protectors

Microsoft: manage-bde


Looking for a different code? Search another status or error code.