| Previous | Next |
| UTC_E_EXCLUSIVITY_NOT_AVAILABLE | UTC_E_ESCALATION_DIRECTORY_ALREADY_EXISTS |
UTC_E_GETFILE_FILE_PATH_NOT_APPROVED
Read this as a lifecycle result: GetFile collection path policy
When UTC_E_GETFILE_FILE_PATH_NOT_APPROVED (0x87C5102E) is returned, the producing layer is policy and trust enforcement. Treat this HRESULT as a state-machine report, not as a generic telemetry outage. The rejected object or state is GetFile collection path policy, and the specific condition is that a local path requested by GetFile is outside the approved collection roots or fails canonical path checks. Keep this first HRESULT even if a later service call reports another error.
DiagTrack applies allowlists, signer checks, path restrictions and destination-specific collection policy. These gates are intended security/privacy boundaries. Diagnosis should identify the exact denied capability rather than recommending broad privilege or policy changes.
Diagnostic record
| UTC diagnostic field | Value |
|---|---|
| Owning state or object | GetFile collection path policy |
| Producing layer | policy and trust enforcement |
| Do not confuse with | UTC_E_GETFILE_EXTERNAL_PATH_NOT_APPROVED adds stricter rules for external-ring collection |
| Evidence to collect | original and canonical path, environment expansion, reparse points, file owner, scenario signer and policy rule |
| Narrow comparison | collect a small test file from an approved root using the same action |
Isolate one changing condition
- Export the relevant
Microsoft-Windows-UniversalTelemetryClient/Operationalevents and preserve their ActivityId or request correlation alongside this result. - Capture original and canonical path, environment expansion, reparse points, file owner, scenario signer and policy rule. Do this before restarting the service or deleting any working directory.
- Perform this one-variable comparison: collect a small test file from an approved root using the same action.
- After the comparison, record the next HRESULT and whether the requested session, action, trigger or output object was actually created.
Nearby result: UTC_E_GETFILE_EXTERNAL_PATH_NOT_APPROVED — adds stricter rules for external-ring collection.
Policy-preserving test
Build the passing case with an approved path, signer, command or certificate while keeping the enforcement mechanism enabled. This demonstrates compliance with the policy boundary rather than merely removing the boundary.
Operational response
Move diagnostic output to an approved location or change the signed scenario policy; avoid traversal or symlink tricks.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for policy and trust enforcement while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis
- Microsoft: CertVerifyCertificateChainPolicy
- Microsoft: Windows cryptography functions
Looking for a different code? Search another status or error code.