| Previous | Next |
| hrFullBackupNotTaken | hrUnknownExpiryTokenFormat |
hrMissingExpiryToken
Where the workflow stopped
hrMissingExpiryToken means the restore request lacks the expiry token created with the backup set.
The stored value is 0xC7FF000F (facility-specific HRESULT). The legacy symbolic name comes from the Windows Directory Service backup/restore message header.
The first useful distinction is that a NULL token can create only a restricted context for querying locations; it cannot authorize the full restore registration path. Start by locating the token captured from DsBackupPrepare, verify its association with this set, and record pointer and size passed to DsRestorePrepare.
Similar-looking outcomes
This result specifically means that a NULL token can create only a restricted context for querying locations; it cannot authorize the full restore registration path. Related values below can appear in the same workflow but require a different response:
hrContentsExpired | the Directory Service judged the backup contents too old under the expiry information associated with the set |
|---|---|
hrUnknownExpiryTokenFormat | bytes were supplied as an expiry token but the Directory Service cannot parse their format |
hrCouldNotConnect | the backup client could not establish the required session with the selected server or running Directory Service |
Objects and state involved
| Diagnostic layer | the opaque expiry token linking a legacy AD backup set to restore authorization and freshness |
|---|---|
| Relevant API surface | DsBackupPrepare token output and DsRestorePrepare token input |
| Code-specific condition | the restore request lacks the expiry token created with the backup set |
| Narrow corrective direction | restore the matching token from protected backup metadata or use the restricted context only for location discovery |
The token must be stored as opaque binary data with the backup set. Without a token, DsRestorePrepare returns a restricted context usable only to query restore locations.
Minimum useful trace
- Code-specific observation: locate the token captured from DsBackupPrepare, verify its association with this set, and record pointer and size passed to DsRestorePrepare.
- Token byte length and hash: capture the value and timestamp from the first occurrence.
- Backup-set identifier: capture the value and timestamp from the first occurrence.
- Storage/copy transformations: capture the value and timestamp from the first occurrence.
- Restore preparation parameters: capture the value and timestamp from the first occurrence.
Steps to resolve it
- Record it,
0xC7FF000F, the API name, the current phase, and all live context or file owners. - Verify the condition by locating the token captured from DsBackupPrepare, verify its association with this set, and record pointer and size passed to DsRestorePrepare.
- Apply only the targeted fix: restore the matching token from protected backup metadata or use the restricted context only for location discovery.
Actions that can make diagnosis worse
- Do not convert the token through text encoding.
- Do not borrow a token from another backup set.
Acceptance criteria for a fix
A useful regression test should force the condition “the restore request lacks the expiry token created with the backup set”, call one documented API transition, and assert the exact HRESULT.
Technical references
- DsRestorePrepare token rules — API ordering, file semantics, warning/error interpretation, or recovery behavior relevant to this HRESULT.
- AD backup walkthrough
- AD restore walkthrough
- Microsoft list of AD DS backup errors
Looking for a different code? Search another status or error code.