What does HRESULT 0x87C51039 (UTC_E_UNAPPROVED_SCRIPT) mean?

 
Previous Next
UTC_E_THROTTLED UTC_E_SCRIPT_MISSING

UTC_E_UNAPPROVED_SCRIPT

Where the UTC workflow stopped: DiagTrack script approval policy

UTC_E_UNAPPROVED_SCRIPT (0x87C51039) is a Universal Telemetry Client result from the policy and trust enforcement layer. The key question is which UTC object rejected the request. The relevant state is DiagTrack script approval policy: the referenced script exists and has a recognized type but is not approved for scenario execution. This identifies a specific UTC/DiagTrack condition, not a general service failure.

DiagTrack applies allowlists, signer checks, path restrictions and destination-specific collection policy. These gates are intended security/privacy boundaries. Diagnosis should identify the exact denied capability rather than recommending broad privilege or policy changes.

Evidence to preserve

UTC diagnostic fieldValue
Producing layerpolicy and trust enforcement
Owning state or objectDiagTrack script approval policy
Evidence to collectscript path, hash, signer, catalog/package, scenario signature, approval rule and target build
Narrow comparisonrun a known approved script through the same RunScriptAction and compare policy events
Do not confuse withUTC_E_SCRIPT_MISSING means no file is present at the approved reference

Controlled reproduction

  1. Associate this result with one request, one scenario version and one service process ID.
  2. Save script path, hash, signer, catalog/package, scenario signature, approval rule and target build and the first lower-level HRESULT if one exists.
  3. Change no policy, provider set or destination except for this test: run a known approved script through the same RunScriptAction and compare policy events.
  4. Compare the produced artifacts and operational events, not only the top-level return value.

Nearby result: UTC_E_SCRIPT_MISSING — means no file is present at the approved reference.

Policy-preserving test

Build the passing case with an approved path, signer, command or certificate while keeping the enforcement mechanism enabled. This demonstrates compliance with the policy boundary rather than merely removing the boundary.

Correction and verification

Deploy the approved signed artifact or replace the action; do not weaken script policy globally.

Technical references


Looking for a different code? Search another status or error code.