| Previous | Next |
| hrRestoreMapExists | hrLogFileNotFound |
hrIncrementalBackupDisabled
Why this result matters
For hrIncrementalBackupDisabled, treat the value as part of a state machine: it says what remained valid and what did not. The decisive boundary is the database lineage no longer permits the requested incremental backup and requires a new full baseline.
The stored Value is 0xC7FF0009 (facility-specific HRESULT). The HRESULT carries failure severity, so output state must be treated according to the individual API contract. The legacy this result name comes from the Windows Directory Service backup/restore message header.
The first useful distinction is that missing one log file is hrLogFileNotFound; this result says the incremental chain itself has been invalidated. Start by record the last successful full backup identity, intervening maintenance or modification, current database signature, and backup history. That separates a reproducible incident from a later generic cleanup or service error.
Do not confuse it with
This result specifically means that missing one log file is hrLogFileNotFound; it says the incremental chain itself has been invalidated. Related values below can appear in the same workflow but require a different response:
hrLogFileNotFound | an incremental Directory Service backup cannot assemble the required transaction-log set |
|---|---|
hrFullBackupNotTaken | the caller requested an incremental backup without a completed full backup recorded as its baseline |
hrCircularLogging | the Directory Service component is using circular logs, so the historical range needed for an incremental backup is not guaranteed to remain |
Keep the original constant and hexadecimal value in telemetry. Replacing it with “backup failed” or “database warning” removes the state information needed to select the next legal API call.
Forensic checklist
Preserve the first result before retries, cleanup, service restart, or file replacement changes the evidence. The diagnostic record should identify the exact API phase and the owner of every handle or artifact involved.
- Code-specific observation: record the last successful full backup identity, intervening maintenance or modification, current database signature, and backup history.
- Generation range and checkpoint: record it together with it and the timestamp of the first occurrence.
- Catalog and truncation history: record it together with it and the timestamp of the first occurrence.
- Full and incremental backup IDs: record it together with it and the timestamp of the first occurrence.
- Database and log signatures: record it together with it and the timestamp of the first occurrence.
Use hashes, lengths, IDs, generation numbers, and redacted samples instead of copying directory contents or sensitive database values into routine logs. For this it investigation, a complete provenance chain is often more useful than a second automatic retry.
Objects and state involved
| Diagnostic layer | full-backup baseline, incremental descendants, retained log generations, and catalog lineage |
|---|---|
| Relevant API surface | DsBackupPrepare backup type, log enumeration/truncation, and ESE external backup |
| Code-specific boundary | the database lineage no longer permits the requested incremental backup and requires a new full baseline |
| Narrow corrective direction | take and verify a new full backup, then start a new incremental chain from that baseline |
An incremental backup depends on a previous full database image and a continuous required log history., circular logging retires old generations based on checkpoint state rather than backup-chain retention needs.
Actions that can make diagnosis worse
- do not combine an incremental set with an unrelated full backup.
- do not delete logs manually to make a directory look clean.
- do not discard the first lower-level Win32, RPC, or JET result merely because a later cleanup call returned a more familiar error.
Validation after correction
- Record it,
0xC7FF0009, the API name, the current phase, and all live context or file owners. - Verify the decisive condition by record the last successful full backup identity, intervening maintenance or modification, current database signature, and backup history.
- Apply only the narrow correction: take and verify a new full backup, then start a new incremental chain from that baseline.
- After it, recreate any context invalidated by the failure; do not carry stale HBC, cursor, file, or restore-map state into the retry.
- repeat the smallest non-destructive test that reaches the same boundary, then verify both the return value and the resulting file, cursor, backup, or database state.
Acceptance criteria for a fix
A useful regression test for this HRESULT should force the condition “the database lineage no longer permits the requested incremental backup and requires a new full baseline”, call one documented API transition, and assert the exact HRESULT. The corrected the case should change only the decisive precondition and should verify cleanup as well as the primary output. For the result backup or restore path, also prove that the resulting set can be enumerated and that no file handle or context remains active after finalization.
Technical references
- AD backup walkthrough — API ordering, file semantics, warning/error interpretation, or recovery behavior relevant to it.
- ESE files and circular logging
- External backup sequence
- Microsoft JET_ERR enumeration
- Microsoft list of AD DS backup errors
Looking for a different code? Search another status or error code.