What does HRESULT 0xC0090002 (ERROR_ALL_SIDS_FILTERED) mean?

 
Previous Next
ERROR_AUDITING_DISABLED ERROR_BIZRULES_NOT_ENABLED

ERROR_ALL_SIDS_FILTERED

The numeric result becomes useful only when tied to the exact operation and object state. A SID-filtering operation removed every candidate SID, leaving no security identity to build the intended authorization context.

Operational meaning

This is not access denied after an ordinary ACL check; the authorization context was emptied before a meaningful access check could be performed. Keep ERROR_ALL_SIDS_FILTERED, its numeric value, and the first returning operation together.

Build a reproducible record

CaptureDiagnostic value
Input token/SID list, filtering rules, trust boundary, deny-only attributes, and resulting group set.Identifies the concrete object and operation associated with authorization context left with no usable SIDs.
Which rule removed each SID and whether user, primary group, logon, or service SID was expected to remain.Separates argument or lifecycle state from the provider beneath authorization context left with no usable SIDs.
First security/authorization event and the exact API returning the HRESULT.Creates a stable before-and-after comparison.
Effective identity and policy version at the time of the call.Shows whether this condition is the first result or a translated summary.

Preserve input token/SID list, filtering rules, trust boundary, deny-only attributes, and resulting group set before reinstalling, rebooting, clearing state, or substituting another device or provider.

Checks that separate the causes

  1. Run the filter against a synthetic token containing one explicitly allowed SID. Keep unrelated inputs fixed so the changed result remains attributable to the tested variable.
  2. Compare local and cross-trust contexts while preserving the same resource ACL. Record the first returned status and any state transition observed.
  3. Repeat after one policy refresh without changing the resource ACL or application data. Treat a changed result as a separate failure rather than automatic resolution.

Resolution criteria

Targeted correction. Correct the trust or filtering policy so the minimum intended identity survives, without broadly disabling SID filtering.

Acceptance criterion. The resulting context contains the expected bounded SID set and access decisions match a documented positive and negative test.

Technical references

References for ERROR_ALL_SIDS_FILTERED on the deployed platform version.


Looking for a different code? Search another status or error code.