| Previous | Next |
| STATUS_FVE_PROTECTION_CANNOT_BE_DISABLED | STATUS_FWP_CALLOUT_NOT_FOUND |
STATUS_FVE_OSV_KSR_NOT_ALLOWED
KSR is not allowed for the OS volume
STATUS_FVE_OSV_KSR_NOT_ALLOWED is a policy result for a protected operating-system volume. KSR-related work is being requested, but BitLocker policy does not permit that operation for the OS volume in its current protected state.
Diagnostics should start with policy and volume role. A data volume, removable volume, and operating-system volume can have different BitLocker policy constraints; using the same management flow for all of them can surface this status.
Diagnostic focus
- Confirm the target is the operating-system volume, not a data volume.
- Check applicable BitLocker GPO/CSP settings before changing protectors.
- Log whether the request came from management tooling, servicing, or a user-initiated protection refresh.
References
- Microsoft: BitLocker FAQ
- Microsoft: BitLocker preboot recovery screen
- Microsoft: Configure BitLocker
- Microsoft: BitLocker recovery overview
- Microsoft: BitLocker drive encryption for OEMs
- Microsoft: COM error codes for TPM, PLA and FVE
Looking for a different code? Search another status or error code.