What does HRESULT 0x87C5101C (UTC_E_SETUP_NOT_AUTHORIZED) mean?

 
Previous Next
UTC_E_ESCALATION_NOT_AUTHORIZED UTC_E_CHILD_PROCESS_FAILED

UTC_E_SETUP_NOT_AUTHORIZED

Locate the rejected contract: scenario setup authorization

UTC_E_SETUP_NOT_AUTHORIZED has the unsigned value 0x87C5101C. In UTC it comes from policy and trust enforcement, where scenario setup authorization owns the decision. The symbolic name points to a narrow UTC contract that can be tested directly. The immediate contract failed because the preparatory setup actions were rejected by UTC policy or caller permissions, so diagnosis should remain at that boundary until a controlled comparison crosses it.

DiagTrack applies allowlists, signer checks, path restrictions and destination-specific collection policy. These gates are intended security/privacy boundaries. Diagnosis should identify the exact denied capability rather than recommending broad privilege or policy changes.

Capture checklist

UTC diagnostic fieldValue
Owning state or objectscenario setup authorization
Producing layerpolicy and trust enforcement
Do not confuse withUTC_E_ESCALATION_NOT_AUTHORIZED occurs later, when the escalation itself is denied
Evidence to collectsetup action list, caller token, scenario signature, target paths/services and policy decision
Narrow comparisonremove one setup action at a time in a signed test scenario to identify the denied capability

Comparison with a passing case

  1. Export the relevant Microsoft-Windows-UniversalTelemetryClient/Operational events and preserve their ActivityId or request correlation alongside this result.
  2. Capture setup action list, caller token, scenario signature, target paths/services and policy decision. Do this before restarting the service or deleting any working directory.
  3. Perform this one-variable comparison: remove one setup action at a time in a signed test scenario to identify the denied capability.
  4. After the comparison, record the next HRESULT and whether the requested session, action, trigger or output object was actually created.

Nearby result: UTC_E_ESCALATION_NOT_AUTHORIZED — occurs later, when the escalation itself is denied.

Policy-preserving test

Build the passing case with an approved path, signer, command or certificate while keeping the enforcement mechanism enabled. This demonstrates compliance with the policy boundary rather than merely removing the boundary.

Resolution and regression test

Correct the setup contract or execution identity before evaluating any escalation result.

Technical references


Looking for a different code? Search another status or error code.