| Previous | Next |
| FVE_E_TRANSIENT_STATE | FVE_E_VOLUME_HANDLE_OPEN |
FVE_E_PUBKEY_NOT_ALLOWED
The failed prerequisite
FVE_E_PUBKEY_NOT_ALLOWED / 0x80310058 marks a rejected BitLocker transition: effective policy or volume type disallows a public-key certificate protector for this drive.
Policy troubleshooting must use the effective result, not a screenshot of one editor. Domain GPO, local policy, provisioning packages and MDM can all populate BitLocker settings, and an existing protector can predate the current policy.
Diagnostic map
| Layer | policy and authorization |
|---|---|
| Proof to collect | volume type, effective certificate-protector policy, certificate EKU, provider, private-key availability and requested protector method |
| Different condition | an invalid certificate or missing private key, which are checked only after the protector type is permitted |
| First safe change | use an allowed protector or change the managed policy after confirming recovery and compatibility requirements |
BitLocker evaluates the target volume together with effective Group Policy or MDM policy, Windows edition, caller authorization and the requested protector or management method. A policy HRESULT therefore describes a rejected configuration decision, not evidence that encrypted sectors are damaged.
A focused verification sequence
Recommended operational response
- Use an allowed protector or change the managed policy after confirming recovery and compatibility requirements.
manage-bde -status
gpresult /h bitlocker-policy.html
State checks specific to FVE_E_PUBKEY_NOT_ALLOWED
| Stage | How to interpret it |
|---|---|
| Before the call | Record the target identity and the pre-call policy and authorization state. Effective policy or volume type disallows a public-key certificate protector for this drive. |
| At failure | Preserve volume type, effective certificate-protector policy, certificate EKU, provider, private-key availability and requested protector method. |
Official references
Looking for a different code? Search another status or error code.
