| Previous | Next |
| FRS_ERR_INVALID_API_SEQUENCE | FRS_ERR_STOPPING_SERVICE |
FRS_ERR_STARTING_SERVICE
The file replication service cannot be started.
The native value for FRS_ERR_STARTING_SERVICE is 8002 (0x00001F42). Preserve this result immediately after the failing Windows call because later logging, cleanup, LDAP, RPC, or file operations can replace the last-error value.
This result belongs to legacy File Replication Service (FRS). A diagnosis of it must connect the condition to the producing API, current state, object identity, and first lower-level diagnostic.
Where the result appears
- processing starting the legacy File Replication Service.
- managing a legacy FRS replica set or SYSVOL member.
- handling a service, RPC, directory, staging, or database transition owned by NtFrs.
- running an administrative tool against an environment whose FRS/DFSR migration state must be known.
State boundary to prove
This result applies to starting the legacy File Replication Service and does not by itself prove that the entire server, directory, disk, session, or application is unavailable. The state boundary to prove for it is whether NtFrs can initialize its database, RPC endpoints, replica-set state, and required directories. Use File Replication Service event log, Service Control Manager status and exit code, and NtFrs database and staging paths as independent evidence. When evidence for it disagrees, preserve timestamps and investigate the transition instead of selecting the most convenient value.
Likely causes
- the service database is damaged or locked.
- dependencies or RPC are unavailable.
- the service identity lacks access.
- SYSVOL or replica paths are missing.
- startup is blocked by pending recovery.
Diagnostic sequence
- capture error 8002 immediately at the API boundary and record the operation that was attempted.
- identify the exact owner of starting the legacy File Replication Service, including object generation, server, path, session, replica, or client context.
- collect File Replication Service event log before restarting a service or changing configuration.
- compare Service Control Manager status and exit code with the documented or observed precondition.
- correlate NtFrs database and staging paths with the File Replication Service event log, Service Control Manager, Directory Service and Netlogon events, RPC diagnostics, and replica-set state.
- determine whether side effects occurred and verify recovery after changing one responsible condition.
Evidence to collect
- File Replication Service event log.
- Service Control Manager status and exit code.
- NtFrs database and staging paths.
- RPC and dependency state.
- domain controller role and SYSVOL migration state.
Correlate it with the File Replication Service event log, Service Control Manager, Directory Service and Netlogon events, RPC diagnostics, and replica-set state. Keep the first detailed status even when a later wrapper translates it to error 8002; the first status often distinguishes transport, authorization, storage, schema, state, and application-integrity causes that share the same final Win32 result.
Handling, retry, and recovery
The recovery objective is to fix the first startup event, preserve the FRS database until recovery choice is known, and migrate SYSVOL to DFS Replication when the domain still relies on legacy FRS.
Retry it only after the recorded condition changes and completion state is known. Idempotent queries may be repeated after recovery, but mutations require a state check first; backoff cannot repair malformed input, corruption, missing structure, or policy rejection.
Telemetry and support fields
- record
starting_service_apifor the producing function or management operation. - record
starting_service_targetfor the file, log, session, replica, object, or server identity. - record
starting_service_state_beforeandstarting_service_requested_transition. - record
starting_service_first_statusfor the earliest lower-level diagnostic.
For support escalation involving it, retain decimal 8002, hexadecimal 0x00001F42, the API, UTC time, target identity, and first subsystem-specific status. Include the smallest reproducible request and evidence that distinguishes this condition from nearby codes. In the context of it, frs is legacy technology. for sysvol, determine the domain’s actual migration state before applying an frs recovery procedure, because a domain already migrated to dfs replication has a different owner and recovery model.
Difference from nearby results
FRS_ERR_SERVICE_COMM means the service is running but cannot be contacted; this code means startup itself failed
Practical validation scenario
NtFrs stops after database recovery events following a disk incident. The administrator captures the event sequence and performs the supported nonauthoritative recovery instead of repeatedly starting the service. The negative test should preserve the responsible condition and reproduce it; the recovery test should change only the identified cause, repeat the same operation, and verify both success and the absence of an unintended partial side effect.
Developer and administrator guidance
Administrators handling it must identify whether SYSVOL is actually owned by FRS or by DFS Replication before recovery. Developers and scripts should record directional partners, replica-set identity, and the first FRS event rather than treating a successful HTTP, RPC, or service-control call as proof that replication completed. Code that exposes it through RPC, JSON, REST, PowerShell, or another protocol should preserve the Win32 domain, decimal 8002, hexadecimal 0x00001F42, and original component diagnostic.
References
- Microsoft: Win32 system error range containing this code — official context relevant to it.
- Microsoft: Migrate SYSVOL from FRS to DFS Replication — official context relevant to it.
- Microsoft: Use BurFlags to reinitialize FRS — official context relevant to it.
- Microsoft: AD DS troubleshooting — official context relevant to it.
Looking for a different code? Search another status or error code.