| Previous | Next |
| UTC_E_BINARY_MISSING | UTC_E_FAILED_TO_RESOLVE_CONTAINER_ID |
UTC_E_NETWORK_CAPTURE_NOT_ALLOWED
Read this as a lifecycle result: network-capture policy gate
UTC_E_NETWORK_CAPTURE_NOT_ALLOWED (0x87C51035) is a Universal Telemetry Client result from the network or kernel diagnostic capture layer. Treat this HRESULT as a state-machine report, not as a generic telemetry outage. The relevant state is network-capture policy gate: the scenario requested packet capture where UTC policy, destination or device configuration forbids it. This identifies a specific UTC/DiagTrack condition, not a general service failure.
Condition to preserve: The documented condition is “A network capture trace is not allowed.” A comparison run should change that state, not an unrelated component setting.
Network-capture boundary: the diagnostic scenario is not permitted to collect network traffic under the current policy, capability, or security context. Record the scenario configuration, capture provider, caller elevation, and applicable policy. Deleting prior trace files cannot grant a permission that the capture path does not have.
Network and kernel captures are high-impact diagnostic actions. Policy approval, capture-component startup, ETW/driver resources and rate limits are independent gates and should be verified in that order.
Diagnostic record
| UTC diagnostic field | Value |
|---|---|
| Producing layer | network or kernel diagnostic capture |
| Owning state or object | network-capture policy gate |
| Evidence to collect | scenario signer, capture action, interface scope, destination/ring, privacy policy and authorization decision |
| Narrow comparison | run a non-network ETW profile under the same scenario, then compare an approved capture configuration |
| Do not confuse with | UTC_E_FAILED_TO_START_NDISCAP occurs after capture is allowed but the capture component cannot start |
Isolate one changing condition
- Collect the high-value state: scenario signer, capture action, interface scope, destination/ring, privacy policy and authorization decision.
- Use a passing control on the same Windows build, then run a non-network ETW profile under the same scenario, then compare an approved capture configuration.
Nearby result: UTC_E_FAILED_TO_START_NDISCAP — occurs after capture is allowed but the capture component cannot start.
Capture safety
When testing this result, keep scope and duration minimal, document where the capture is stored and verify normal stop/cleanup. Packet and kernel captures can contain sensitive data and consume bounded system resources.
Operational response
Remove the capture action or use an approved diagnostic workflow; do not bypass policy with another sniffer.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for network or kernel diagnostic capture while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis — reference for network or kernel diagnostic capture while interpreting it.
- Microsoft: NDIS filter-driver installation and binding
- Microsoft: Packet Monitor overview
Looking for a different code? Search another status or error code.