| Previous | Next |
| NS_E_DRM_LICENSE_NOTENABLED | NS_E_DRM_STORE_NEEDINDI |
NS_E_DRM_LICENSE_APPSECLOW
Where the operation stopped
0xC00D27DA maps to NS_E_DRM_LICENSE_APPSECLOW. Read it as a result from license validity, rights and policy enforcement: the player application security level is below the license requirement. Keeping the “license appseclow” boundary intact prevents a later playback message from hiding the original DRM failure.
State to capture before retry
- Protected identity: application security level and required output protection.
- Operation state: remaining counts, device registration and revocation state.
- Persistence or transport: requested action such as play, copy, burn or transfer.
- Security context: license ID, KID and content-header identity.
- Correlation point: valid-from, expiration and secure-clock values.
For the “license appseclow” investigation, use KIDs, license IDs, hashes, certificate thumbprints, sizes and timestamps where possible. Do not place content keys, complete license blobs, passwords, cookies or decrypted media in ordinary logs.
A useful investigation order
- Start from
0xC00D27DAand map it to the first WMDRM object that returned it. - Separate content/header evidence, license evidence, machine/device evidence and service/network evidence around “license appseclow”.
- Before retrying this result, check whether another “license appseclow” operation was active or whether the previous result may have committed partially.
- Record required and actual application security levels and certificate identity.
- Apply the smallest supported fix: use an updated trusted player satisfying the license policy; avoid resetting unrelated protected state.
Targeted fix
The supported response to this result is narrow: use an updated trusted player satisfying the license policy. After correcting it, reopen or recreate the object that owned “license appseclow” so the verification does not reuse state from the failed operation.
Representative case: A license is valid but refuses playback in an older application build.
What not to do first
- Avoid changing the system clock or bypassing output protection to make a time- or security-bound license appear valid.
Nearby results with different meanings
| Result | Different condition |
|---|---|
NS_E_DRM_LICENSE_NOTENABLED | The selected license has a future valid-from time and is not active yet. |
NS_E_DRM_STORE_NEEDINDI | The license cannot be stored until the DRM client is individualized to the required level. |
NS_E_DRM_LICENSE_EXPIRED | The selected license is past its permitted validity period. |
Verification after correction
A valid regression has two fixtures: one that deliberately produces “the player application security level is below the license requirement” and one that applies the targeted correction. Compare callback order, selected license/KID, final rights decision and persistence state; disappearance of the “license appseclow” dialog alone is not proof.
Technical references
- DRM basics and rights enforcement.
- Licenses and the local license store — API and state rules for the DRM operation described here.
- Output protection levels.
- DRM protection and license distribution.
Looking for a different code? Search another status or error code.