| Previous | Next |
| NS_E_DRM_OPERATION_CANCELED | NS_E_DRM_UNABLE_TO_CREATE_PLAYLIST_OBJECT |
NS_E_DRM_RESTRICTIONS_NOT_RETRIEVED
What failed in WMDRM
0xC00D2769 maps to NS_E_DRM_RESTRICTIONS_NOT_RETRIEVED. Read it as a result from trusted playback path and output restrictions: the license you are using has associated output restrictions. This license is unusable until these restrictions are queried. Keeping the “restrictions not retrieved” boundary intact prevents a later playback message from hiding the original DRM failure.
Record the exact API, object state, input identity and first lower-level result associated with this failure.
Place in the DRM workflow
The workflow around this result matters: output restrictions must be queried and enforced before the operation; a driver can render ordinary media yet fail the protected path. In addition, legacy Secure Audio Path and newer protected-media mechanisms use trusted components, so an unvalidated or revoked component is not repaired by changing the content file.
State to capture before retry
- Protected identity: application certificate and revocation state.
- Operation state: restriction-query result before playback or burn begins.
- Persistence or transport: protected-path renewal or component-validation event.
- Security context: requested output and protection level.
- Correlation point: audio/video driver identity, signature and version.
For the “restrictions not retrieved” investigation, use KIDs, license IDs, hashes, certificate thumbprints, sizes and timestamps where possible. Do not place content keys, complete license blobs, passwords, cookies or decrypted media in ordinary logs.
A useful investigation order
- Locate the earliest API return, callback or event containing this result and
0xC00D2769. - Identify the exact content, license, store, device or migration object instance involved in “restrictions not retrieved”.
- Determine whether “restrictions not retrieved” occurred before network exchange, during response validation, while enforcing policy, or while committing protected state.
- Perform the code-specific check: record the exact API, object state, input identity and first lower-level result associated with this failure.
- Make one targeted change — correct the producing DRM state or input and retry with a fresh operation object — and repeat the same producing operation.
Targeted fix
Representative case: The application reaches the restrictions not retrieved path and receives this exact HRESULT before the higher-level media action can complete.
What not to do first
- Avoid interpreting an output-policy failure as proof that the license itself is corrupt.
Nearby results with different meanings
| Result | Different condition |
|---|---|
NS_E_DRM_DEBUGGING_NOT_ALLOWED | The protected operation detects that its process is running under a debugger. |
NS_E_DRM_INVALID_APPCERT | The DRM application certificate is malformed, mismatched or cannot be validated. |
NS_E_DRM_APPCERT_REVOKED | The application certificate is rejected by WMDRM revocation policy. |
Verification after correction
After the repair, recreate the WMDRM object and run the smallest reproducer. Confirm that 0xC00D2769 no longer occurs, that the intended license action completes, and that no store, certificate, clock or migration warning replaces it.
Technical references
- Output protection levels — API and state rules for the DRM operation described here.
- Secure Audio Path model.
- Protected Media Path.
- DRM export and output protection — API and state rules for the DRM operation described here.
Looking for a different code? Search another status or error code.