What does Windows error code 8220 (ERROR_POLICY_ONLY_IN_DS) mean?

 
Previous Next
ERROR_POLICY_OBJECT_NOT_FOUND ERROR_PROMOTION_ACTIVE

ERROR_POLICY_ONLY_IN_DS

The requested policy information is only in the directory service.

ERROR_POLICY_ONLY_IN_DS is Win32 error 8220 (0x0000201C) in Active Directory Domain Services (AD DS). Interpret this result at the call that produced it and use the system message above as the immediate condition rather than as a complete root cause.

Windows assigns decimal 8220 and hexadecimal 0x0000201C to this result. The decisive subject is policy information that exists only in Active Directory; the value alone does not reveal which object, server, file, session, or transition failed.

Where the result appears

  • processing policy information that exists only in Active Directory.
  • executing an LDAP, RPC, deployment, replication, or directory-management operation.
  • working against a specific domain controller whose replica and schema state affect the result.
  • translating extended directory diagnostics into a Win32 error for an application or administration tool.

State boundary to prove

This result applies to policy information that exists only in Active Directory and does not by itself prove that the entire server, directory, disk, session, or application is unavailable. The state boundary to prove for it is whether the caller queries a directory service capable of returning the requested policy data. Use requested policy field, local versus domain policy source, and domain and DC discovery result as independent evidence. When evidence for it disagrees, preserve timestamps and investigate the transition instead of selecting the most convenient value.

Likely causes

  • the caller uses a local policy source for domain-only information.
  • no directory service is reachable.
  • the machine is not in the expected domain context.
  • the API was asked to satisfy a domain policy request offline.

Diagnostic sequence

  1. capture error 8220 immediately at the API boundary and record the operation that was attempted.
  2. identify the exact owner of policy information that exists only in Active Directory, including object generation, server, path, session, replica, or client context.
  3. collect requested policy field before restarting a service or changing configuration.
  4. compare local versus domain policy source with the documented or observed precondition.
  5. correlate domain and DC discovery result with the Directory Service event log, LDAP extended diagnostics, replication metadata, dcdiag and repadmin output, and the calling application’s request trace.
  6. determine whether side effects occurred and verify recovery after changing one responsible condition.

Evidence to collect

  • requested policy field.
  • local versus domain policy source.
  • domain and DC discovery result.
  • contacted directory partition.

Correlate it with the Directory Service event log, LDAP extended diagnostics, replication metadata, dcdiag and repadmin output, and the calling application’s request trace. Keep the first detailed status even when a later wrapper translates it to error 8220; the first status often distinguishes transport, authorization, storage, schema, state, and application-integrity causes that share the same final Win32 result.

Handling, retry, and recovery

The recovery objective is to query the directory-backed policy source using current domain context and handle offline operation explicitly.

Retry it only after the recorded condition changes and completion state is known. Idempotent queries may be repeated after recovery, but mutations require a state check first; backoff cannot repair malformed input, corruption, missing structure, or policy rejection.

Telemetry and support fields

  • record policy_only_in_ds_api for the producing function or management operation.
  • record policy_only_in_ds_target for the file, log, session, replica, object, or server identity.
  • record policy_only_in_ds_state_before and policy_only_in_ds_requested_transition.
  • record policy_only_in_ds_first_status for the earliest lower-level diagnostic.

For support escalation involving it, retain decimal 8220, hexadecimal 0x0000201C, the API, UTC time, target identity, and first subsystem-specific status. Include the smallest reproducible request and evidence that distinguishes this condition from nearby codes. In the context of it, many ds codes are internal or management-facing and are not tied to one public function. the producing ldap, rpc, deployment, or management api must therefore be recorded with the code.

Difference from nearby results

ERROR_POLICY_OBJECT_NOT_FOUND reaches the directory but cannot find the object; this code says the selected non-directory source cannot provide the information

Practical validation scenario

A laptop tool requests a domain-only policy while offline and queries only local policy. It defers the result until a DC is available instead of treating the field as absent. The negative test should preserve the responsible condition and reproduce it; the recovery test should change only the identified cause, repeat the same operation, and verify both success and the absence of an unintended partial side effect.

Developer and administrator guidance

Administrators handling it should preserve Directory Service events, replication metadata, and the contacted domain controller before changing objects or forcing role transitions. Developers should retain LDAP extended diagnostics and object identities across wrappers so the Win32 code does not erase the actionable directory result. Code that exposes it through RPC, JSON, REST, PowerShell, or another protocol should preserve the Win32 domain, decimal 8220, hexadecimal 0x0000201C, and original component diagnostic.

References


Looking for a different code? Search another status or error code.