What does HRESULT 0x87C5101B (UTC_E_ESCALATION_NOT_AUTHORIZED) mean?

 
Previous Next
UTC_E_EXE_TERMINATED UTC_E_SETUP_NOT_AUTHORIZED

UTC_E_ESCALATION_NOT_AUTHORIZED

Map the code to the scenario graph: escalation authorization policy

The code UTC_E_ESCALATION_NOT_AUTHORIZED (0x87C5101B) belongs to policy and trust enforcement, inside the Universal Telemetry Client/DiagTrack workflow. A reliable investigation preserves the producing action before any cleanup runs. It identifies escalation authorization policy and reports that the scenario was allowed to load but its escalation phase lacked the required authorization; it does not by itself prove that all Windows diagnostic data collection is unavailable.

DiagTrack applies allowlists, signer checks, path restrictions and destination-specific collection policy. These gates are intended security/privacy boundaries. Diagnosis should identify the exact denied capability rather than recommending broad privilege or policy changes.

Data needed for triage

UTC diagnostic fieldValue
Producing layerpolicy and trust enforcement
Owning state or objectescalation authorization policy
Evidence to collectscenario signer, destination, requested actions, caller token, policy decision and denied capability
Narrow comparisonrun an otherwise identical approved scenario under the intended service identity
Do not confuse withUTC_E_SETUP_NOT_AUTHORIZED rejects the setup phase before escalation begins

Reproduce without collateral changes

  1. Associate this result with one request, one scenario version and one service process ID.
  2. Save scenario signer, destination, requested actions, caller token, policy decision and denied capability and the first lower-level HRESULT if one exists.
  3. Change no policy, provider set or destination except for this test: run an otherwise identical approved scenario under the intended service identity.
  4. Compare the produced artifacts and operational events, not only the top-level return value.

Nearby result: UTC_E_SETUP_NOT_AUTHORIZED — rejects the setup phase before escalation begins.

Policy-preserving test

Build the passing case with an approved path, signer, command or certificate while keeping the enforcement mechanism enabled. This demonstrates compliance with the policy boundary rather than merely removing the boundary.

Fix the contract

Use an authorized signed configuration or remove the forbidden action; do not grant broad interactive admin rights.

Technical references


Looking for a different code? Search another status or error code.