What does HRESULT 0xC00E0011 (MQ_ERROR_ILLEGAL_USER) mean?

 
Previous Next
MQ_ERROR_ILLEGAL_SORT MQ_ERROR_NO_DS

MQ_ERROR_ILLEGAL_USER

What this result actually narrows down

Applications should keep MQ_ERROR_ILLEGAL_USER attached to the exact MSMQ call that produced it. The result marks principal cannot be resolved or represented. Capture the exact account syntax and domain context used by the security or directory operation.

The property namespace is split among message, queue, computer, private-computer, and management properties. When diagnosing this result, A numeric identifier meaningful in one structure is not automatically legal in another API.

Validation occurs in layers: identifier recognition, variant type, buffer shape, value range, required companions, and operation eligibility. These layers correspond to different MSMQ HRESULTs and different fixes.

MSMQ objects involved

SubsystemMSMQ property arrays and their parallel identifier, value, and status elements
Relevant conditionthe property identifier, VARTYPE, value, operation, and buffer ownership are validated separately
Code-specific focusprincipal cannot be resolved or represented

Do not merge it with other property failures: identifier, VARTYPE, value, size, required companions, and operation eligibility are diagnosed by different codes. The code-specific boundary is principal cannot be resolved or represented.

Triage data

  • The api name and whether the structure was input, output, or both.
  • The first failing property rather than only the aggregate hresult.
  • The complete apropid/apropvar/astatus triples in original order.

Correct response

Resolve the account to a SID under the same identity before repeating the MSMQ call.

What this code is not

Changing a queue ACL or restarting the service does not correct an invalid identifier, VARTYPE, value, structure, or property combination. Code-specific condition: principal cannot be resolved or represented.

Example failure path

Principal-resolution checks

Preserve the account string exactly as supplied, including domain qualification and any local-computer prefix. Resolve it to a SID under the same security context used by the MSMQ call, then compare that SID with the intended queue owner, trustee, or certificate registrant. A valid-looking display name can identify a different principal after domain migration or account recreation.

  • Test local and domain account namespaces explicitly instead of relying on the caller's default domain.
  • Record lookup failures from the operating system and AD DS separately from the MSMQ HRESULT.
  • Avoid replacing the user with an administrator account as a permanent fix; correct the principal mapping required by the operation.

Technical references


Looking for a different code? Search another status or error code.