| Previous | Next |
| UTC_E_EXE_TERMINATED | UTC_E_SETUP_NOT_AUTHORIZED |
UTC_E_ESCALATION_NOT_AUTHORIZED
Map the code to the scenario graph: escalation authorization policy
The code UTC_E_ESCALATION_NOT_AUTHORIZED (0x87C5101B) belongs to policy and trust enforcement, inside the Universal Telemetry Client/DiagTrack workflow. A reliable investigation preserves the producing action before any cleanup runs. It identifies escalation authorization policy and reports that the scenario was allowed to load but its escalation phase lacked the required authorization; it does not by itself prove that all Windows diagnostic data collection is unavailable.
DiagTrack applies allowlists, signer checks, path restrictions and destination-specific collection policy. These gates are intended security/privacy boundaries. Diagnosis should identify the exact denied capability rather than recommending broad privilege or policy changes.
Data needed for triage
| UTC diagnostic field | Value |
|---|---|
| Producing layer | policy and trust enforcement |
| Owning state or object | escalation authorization policy |
| Evidence to collect | scenario signer, destination, requested actions, caller token, policy decision and denied capability |
| Narrow comparison | run an otherwise identical approved scenario under the intended service identity |
| Do not confuse with | UTC_E_SETUP_NOT_AUTHORIZED rejects the setup phase before escalation begins |
Reproduce without collateral changes
- Associate this result with one request, one scenario version and one service process ID.
- Save scenario signer, destination, requested actions, caller token, policy decision and denied capability and the first lower-level HRESULT if one exists.
- Change no policy, provider set or destination except for this test: run an otherwise identical approved scenario under the intended service identity.
- Compare the produced artifacts and operational events, not only the top-level return value.
Nearby result: UTC_E_SETUP_NOT_AUTHORIZED — rejects the setup phase before escalation begins.
Policy-preserving test
Build the passing case with an approved path, signer, command or certificate while keeping the enforcement mechanism enabled. This demonstrates compliance with the policy boundary rather than merely removing the boundary.
Fix the contract
Use an authorized signed configuration or remove the forbidden action; do not grant broad interactive admin rights.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for policy and trust enforcement while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis — reference for policy and trust enforcement while interpreting this result.
- Microsoft: CertVerifyCertificateChainPolicy — reference for policy and trust enforcement while interpreting it.
- Microsoft: Windows cryptography functions
Looking for a different code? Search another status or error code.