| Previous | Next |
| SEC_E_NOTRUSTEEID | SEC_E_INVALIDOBJECT |
SEC_E_NOMEMBERSHIPSUPPORT
Exact value and result class
SEC_E_NOMEMBERSHIPSUPPORT has unsigned value 2147749484 (0x80040E6C) and signed 32-bit value -2147217812. AllStat describes it as “Trustee does not support memberships or collections”. In this result, membership or collection administration is requested for a trustee type that does not support that relationship.
The high bit is set, so this result is a failure HRESULT. Its facility is 4 (FACILITY_ITF) and its low code is 3692 (0x0E6C). These fields identify an interface-defined result family; they do not identify the provider instance, method, object generation or partial effects.
Conditions that specifically lead to the result
- Cause 1 for it: the trustee represents an individual object with no membership model.
- Cause 2 for it: the provider security implementation omits group administration.
- Cause 3 for it: the operation is applied to a special or external identity type.
Contract boundary
OLE DB security administration represents trustees, owners, groups, protected objects and access-entry lists as separate entities. A syntactically valid trustee can still be unknown to a provider, and an allowed permission set depends on the protected object type.
Investigation of this result should start with the provider security interface, effective data-source namespace and exact trustee or access-entry structure supplied. Capture it before ADO, ATL,.NET or a database abstraction layer replaces the native HRESULT with a generic exception.
Diagnostic sequence
- Capture raw
0x80040E6Cand symbolic it at the native call boundary. - Identify the exact failing stage for it: membership or collection administration is requested for a trustee type that does not support that relationship.
- Retrieve all OLE DB error records for it before another COM call replaces thread error information.
- Compare the live object state and provider-granted capabilities with the input that produced it.
- Reduce the operation to the smallest case that preserves the same security contract.
- Apply one evidence-backed correction for it and verify that the result is not merely replaced by a neighboring HRESULT.
Evidence to collect
A useful it event records provider CLSID and version, process architecture, interface IID and method, object correlation ID, transaction state and the immediately preceding HRESULT. When recording it data involving SIDs, account names, groups, ACL contents and protected object identifiers, use types, lengths, hashes or redacted identifiers rather than secrets or complete business data.
- Evidence 1 for it: trustee type and provider capabilities.
- Evidence 2 for it: requested add, remove or enumeration operation.
- Evidence 3 for it: available ITrusteeGroupAdmin or related interfaces.
Corrective actions
- Action 1 for it: feature-detect membership support.
- Action 2 for it: apply direct access entries when appropriate.
- Action 3 for it: manage membership in the authoritative external directory instead.
Practical scenario
A data source accepts external certificate identities for access but cannot place them in provider groups; direct grants replace membership changes. Keeping it with the method and object state makes this scenario diagnosable instead of reducing it to “database error”.
Retry and recovery
Retry rule for it: retry only with a trustee and provider that support memberships or with a different authorization design. A it retry is safe only when the relevant input, object generation, capability or external state has changed. Before replaying a modifying call that returned it, determine whether rows, schema objects or URL resources were partially created or changed.
Do not turn it into an unbounded retry loop. Preserve cancellation for it and use a fresh provider object when the failed call may have left local state ambiguous.
Difference from nearby HRESULT values
SEC_E_NOTRUSTEEID means the trustee is unknown, while it means it is known but has no supported membership contract. Telemetry and remediation for it should keep these outcomes distinct.
Developer and operations guidance
Code handling it should release COM objects in ownership order, retain per-row, per-column or per-property statuses, and log granted capabilities rather than only requested options. While handling it, opaque values such as HACCESSOR, HROW, HCHAPTER, DBID components and provider handles must remain scoped to the object that issued them.
Operational dashboards for it should group by provider version, interface, method and normalized failure stage. A it event must not expose passwords, tokens, full connection strings, unrestricted command text or raw row contents.
Official Microsoft references
Looking for a different code? Search another status or error code.
