| Previous | Next |
| UTC_E_THROTTLED | UTC_E_SCRIPT_MISSING |
UTC_E_UNAPPROVED_SCRIPT
Where the UTC workflow stopped: DiagTrack script approval policy
UTC_E_UNAPPROVED_SCRIPT (0x87C51039) is a Universal Telemetry Client result from the policy and trust enforcement layer. The key question is which UTC object rejected the request. The relevant state is DiagTrack script approval policy: the referenced script exists and has a recognized type but is not approved for scenario execution. This identifies a specific UTC/DiagTrack condition, not a general service failure.
DiagTrack applies allowlists, signer checks, path restrictions and destination-specific collection policy. These gates are intended security/privacy boundaries. Diagnosis should identify the exact denied capability rather than recommending broad privilege or policy changes.
Evidence to preserve
| UTC diagnostic field | Value |
|---|---|
| Producing layer | policy and trust enforcement |
| Owning state or object | DiagTrack script approval policy |
| Evidence to collect | script path, hash, signer, catalog/package, scenario signature, approval rule and target build |
| Narrow comparison | run a known approved script through the same RunScriptAction and compare policy events |
| Do not confuse with | UTC_E_SCRIPT_MISSING means no file is present at the approved reference |
Controlled reproduction
- Associate this result with one request, one scenario version and one service process ID.
- Save script path, hash, signer, catalog/package, scenario signature, approval rule and target build and the first lower-level HRESULT if one exists.
- Change no policy, provider set or destination except for this test: run a known approved script through the same RunScriptAction and compare policy events.
- Compare the produced artifacts and operational events, not only the top-level return value.
Nearby result: UTC_E_SCRIPT_MISSING — means no file is present at the approved reference.
Policy-preserving test
Build the passing case with an approved path, signer, command or certificate while keeping the enforcement mechanism enabled. This demonstrates compliance with the policy boundary rather than merely removing the boundary.
Correction and verification
Deploy the approved signed artifact or replace the action; do not weaken script policy globally.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for policy and trust enforcement while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis — reference for policy and trust enforcement while interpreting this result.
- Microsoft: CertVerifyCertificateChainPolicy — reference for policy and trust enforcement while interpreting it.
- Microsoft: Windows cryptography functions
Looking for a different code? Search another status or error code.