| Previous | Next |
| UTC_E_CHILD_PROCESS_FAILED | UTC_E_CANNOT_LOAD_SCENARIO_EDITOR_XML |
UTC_E_COMMAND_LINE_NOT_AUTHORIZED
Interpret the result in context: RunExeWithArgs command-line allowlist
When UTC_E_COMMAND_LINE_NOT_AUTHORIZED (0x87C5101E) is returned, the producing layer is policy and trust enforcement. Start by locating the exact scenario-engine boundary that emitted this value. The rejected object or state is RunExeWithArgs command-line allowlist, and the specific condition is that the executable/argument combination did not pass UTC command-line authorization. Keep this first HRESULT even if a later service call reports another error.
DiagTrack applies allowlists, signer checks, path restrictions and destination-specific collection policy. These gates are intended security/privacy boundaries. Diagnosis should identify the exact denied capability rather than recommending broad privilege or policy changes.
Build a minimal evidence set
| UTC diagnostic field | Value |
|---|---|
| Owning state or object | RunExeWithArgs command-line allowlist |
| Producing layer | policy and trust enforcement |
| Do not confuse with | UTC_E_BINARY_MISSING means the authorized reference points to no binary on the device |
| Evidence to collect | normalized executable path, full argument vector, quoting, signer/hash, scenario signature and policy rule |
| Narrow comparison | invoke the same approved binary with the minimal documented arguments and add switches individually |
Run an A/B check
- Associate this result with one request, one scenario version and one service process ID.
- Save normalized executable path, full argument vector, quoting, signer/hash, scenario signature and policy rule and the first lower-level HRESULT if one exists.
- Change no policy, provider set or destination except for this test: invoke the same approved binary with the minimal documented arguments and add switches individually.
- Compare the produced artifacts and operational events, not only the top-level return value.
Nearby result: UTC_E_BINARY_MISSING — means the authorized reference points to no binary on the device.
Policy-preserving test
Build the passing case with an approved path, signer, command or certificate while keeping the enforcement mechanism enabled. This demonstrates compliance with the policy boundary rather than merely removing the boundary.
Safe remediation
Use the approved command shape or redesign the scenario; escaping changes must not be used to bypass policy.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for policy and trust enforcement while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis
- Microsoft: CertVerifyCertificateChainPolicy
- Microsoft: Windows cryptography functions
Looking for a different code? Search another status or error code.