| Previous | Next |
| ERROR_DS_WRONG_LINKED_ATT_SYNTAX | ERROR_DS_SAM_NEED_BOOTKEY_FLOPPY |
ERROR_DS_SAM_NEED_BOOTKEY_PASSWORD
Security Account Manager needs to get the boot password.
Windows assigns decimal 8529 and hexadecimal 0x00002151 to ERROR_DS_SAM_NEED_BOOTKEY_PASSWORD. The decisive subject is Security Account Manager startup requiring a boot-key password; the value alone does not reveal which object, server, file, session, or transition failed.
The native Value is 8529 (0x00002151). Preserve this result immediately after the failing Windows call because later logging, cleanup, LDAP, RPC, or file operations can replace the last-error value.
Where the result appears
- processing Security Account Manager startup requiring a boot-key password.
- executing an LDAP, RPC, deployment, replication, or directory-management operation.
- working against a specific domain controller whose replica and schema state affect the result.
- translating extended directory diagnostics into a Win32 error for an application or administration tool.
State boundary to prove
This result applies to Security Account Manager startup requiring a boot-key password and does not by itself prove that the entire server, directory, disk, session, or application is unavailable. The state boundary to prove for it is whether the supported boot-key material can be supplied and validated before SAM exposes account data. Use SAM and System event logs, configured boot-key mode, and startup/recovery environment as independent evidence. When evidence for it disagrees, preserve timestamps and investigate the transition instead of selecting the most convenient value.
Likely causes
- legacy SysKey configuration expects a startup password.
- the stored boot-key mode requires interactive input.
- startup occurs outside the normal protected path.
- boot-key configuration is incomplete or damaged.
Diagnostic sequence
- capture error 8529 immediately at the API boundary and record the operation that was attempted.
- identify the exact owner of Security Account Manager startup requiring a boot-key password, including object generation, server, path, session, replica, or client context.
- collect SAM and System event logs before restarting a service or changing configuration.
- compare configured boot-key mode with the documented or observed precondition.
- correlate startup/recovery environment with the Directory Service event log, LDAP extended diagnostics, replication metadata, dcdiag and repadmin output, and the calling application’s request trace.
- determine whether side effects occurred and verify recovery after changing one responsible condition.
Evidence to collect
- SAM and System event logs.
- configured boot-key mode.
- startup/recovery environment.
- availability and provenance of the authorized password.
Correlate this result with the Directory Service event log, LDAP extended diagnostics, replication metadata, dcdiag and repadmin output, and the calling application’s request trace. Keep the first detailed status even when a later wrapper translates it to error 8529; the first status often distinguishes transport, authorization, storage, schema, state, and application-integrity causes that share the same final Win32 result.
Handling, retry, and recovery
The recovery objective is to use the documented recovery process and authorized boot-key material; do not bypass SAM protection or repeatedly guess credentials.
Retry it only after the recorded condition changes and completion state is known. Idempotent queries may be repeated after recovery, but mutations require a state check first; backoff cannot repair malformed input, corruption, missing structure, or policy rejection.
Telemetry and support fields
- record
ds_sam_need_bootkey_password_apifor the producing function or management operation. - record
ds_sam_need_bootkey_password_targetfor the file, log, session, replica, object, or server identity. - record
ds_sam_need_bootkey_password_state_beforeandds_sam_need_bootkey_password_requested_transition. - record
ds_sam_need_bootkey_password_first_statusfor the earliest lower-level diagnostic.
For support escalation involving it, retain decimal 8529, hexadecimal 0x00002151, the API, UTC time, target identity, and first subsystem-specific status. Include the smallest reproducible request and evidence that distinguishes this condition from nearby codes. In the context of it, many ds codes are internal or management-facing and are not tied to one public function. the producing ldap, rpc, deployment, or management api must therefore be recorded with the code.
Difference from nearby results
ERROR_DS_SAM_NEED_BOOTKEY_FLOPPY expects removable boot-key media rather than a typed password
Practical validation scenario
A restored legacy system uses startup-password SysKey mode. Recovery personnel provide the escrowed password through the supported startup path and then migrate away from the obsolete configuration. The negative test should preserve the responsible condition and reproduce it; the recovery test should change only the identified cause, repeat the same operation, and verify both success and the absence of an unintended partial side effect.
Developer and administrator guidance
Administrators handling it should preserve Directory Service events, replication metadata, and the contacted domain controller before changing objects or forcing role transitions. Developers should retain LDAP extended diagnostics and object identities across wrappers so the Win32 code does not erase the actionable directory result. Code that exposes it through RPC, JSON, REST, PowerShell, or another protocol should preserve the Win32 domain, decimal 8529, hexadecimal 0x00002151, and original component diagnostic.
References
- Microsoft: Win32 system error range containing this code — official context relevant to it.
- Microsoft: AD DS troubleshooting — official context relevant to it.
- Microsoft: repadmin — official context relevant to it.
- Microsoft: dcdiag — official context relevant to it.
- Microsoft: AD and LDS diagnostic event logging — official context relevant to it.
Looking for a different code? Search another status or error code.