What does NTSTATUS 0xC000049D (STATUS_CHILD_PROCESS_BLOCKED) mean?

 
Previous Next
STATUS_DAX_MAPPING_EXISTS STATUS_STORAGE_LOST_DATA_PERSISTENCE

STATUS_CHILD_PROCESS_BLOCKED

Child-process creation was denied by policy

Windows returns STATUS_CHILD_PROCESS_BLOCKED when process security or execution policy rejects the requested state or operation. The parent process is running under a mitigation or application-control rule that prohibits creating child processes. The executable path of the child may be valid yet still be blocked by the parent policy.

Capture parent and child command lines, creation flags, mitigation attributes and policy events. Move the operation to an approved broker or redesign the workflow.

Check whether the parent intentionally opted into a child-process restriction or inherited it from application control. The first denied creation event should identify the policy source more reliably than retries with altered command lines.

References


Looking for a different code? Search another status or error code.