What does HRESULT 0xC7FF0010 (hrUnknownExpiryTokenFormat) mean?

 
Previous Next
hrMissingExpiryToken hrContentsExpired

hrUnknownExpiryTokenFormat

Why this result matters

hrUnknownExpiryTokenFormat means bytes were supplied as an expiry token but the Directory Service cannot parse their format.

The stored value is 0xC7FF0010 (facility-specific HRESULT). The legacy symbolic name comes from the Windows Directory Service backup/restore message header.

The first useful distinction is that this is format corruption or mismatch, whereas hrMissingExpiryToken means no token was supplied. Start by recording token length, backup-set identifier, storage encoding, copy path, and whether text conversion or truncation altered the opaque bytes.

Do not confuse it with

This result specifically means that this is format corruption or mismatch, whereas hrMissingExpiryToken means no token was supplied. Related values below can appear in the same workflow but require a different response:

hrMissingExpiryTokenthe restore request lacks the expiry token created with the backup set
hrContentsExpiredthe Directory Service judged the backup contents too old under the expiry information associated with the set
hrInvalidBackupSequencebackup APIs were called in an order that violates the ESE external-backup state machine

Keep the original constant and hexadecimal value in telemetry. Replacing this result with “backup failed” or “database warning” removes the state information needed to select the next legal API call.

Forensic checklist

  • Code-specific observation: record token length, backup-set identifier, storage encoding, copy path, and whether text conversion or truncation altered the opaque bytes.

Objects and state involved

Diagnostic layerthe opaque expiry token linking a legacy AD backup set to restore authorization and freshness
Relevant API surfaceDsBackupPrepare token output and DsRestorePrepare token input
Code-specific conditionbytes were supplied as an expiry token but the Directory Service cannot parse their format
Narrow corrective directionretrieve the unmodified binary token from the same backup set and pass its exact byte count

The token must be stored as opaque binary data with the backup set. Without a token, DsRestorePrepare returns a restricted context usable only to query restore locations.

Actions that can make diagnosis worse

  • Do not convert the token through text encoding.
  • Do not borrow a token from another backup set.

Validation after correction

  1. Record it, 0xC7FF0010, the API name, the current phase, and all live context or file owners.
  2. Verify the condition by recording token length, backup-set identifier, storage encoding, copy path, and whether text conversion or truncation altered the opaque bytes.
  3. Apply only the targeted fix: retrieve the unmodified binary token from the same backup set and pass its exact byte count.

Acceptance criteria for a fix

A useful regression test should force the condition “bytes were supplied as an expiry token but the Directory Service cannot parse their format”, call one documented API transition, and assert the exact HRESULT.

Technical references


Looking for a different code? Search another status or error code.