Site icon EfmSoft

What does HRESULT 0x87C51035 (UTC_E_NETWORK_CAPTURE_NOT_ALLOWED) mean?

 
Previous Next
UTC_E_BINARY_MISSING UTC_E_FAILED_TO_RESOLVE_CONTAINER_ID

UTC_E_NETWORK_CAPTURE_NOT_ALLOWED

Read this as a lifecycle result: network-capture policy gate

UTC_E_NETWORK_CAPTURE_NOT_ALLOWED (0x87C51035) is a Universal Telemetry Client result from the network or kernel diagnostic capture layer. Treat this HRESULT as a state-machine report, not as a generic telemetry outage. The relevant state is network-capture policy gate: the scenario requested packet capture where UTC policy, destination or device configuration forbids it. This identifies a specific UTC/DiagTrack condition, not a general service failure.

Condition to preserve: The documented condition is “A network capture trace is not allowed.” A comparison run should change that state, not an unrelated component setting.

Network-capture boundary: the diagnostic scenario is not permitted to collect network traffic under the current policy, capability, or security context. Record the scenario configuration, capture provider, caller elevation, and applicable policy. Deleting prior trace files cannot grant a permission that the capture path does not have.

Network and kernel captures are high-impact diagnostic actions. Policy approval, capture-component startup, ETW/driver resources and rate limits are independent gates and should be verified in that order.

Diagnostic record

UTC diagnostic fieldValue
Producing layernetwork or kernel diagnostic capture
Owning state or objectnetwork-capture policy gate
Evidence to collectscenario signer, capture action, interface scope, destination/ring, privacy policy and authorization decision
Narrow comparisonrun a non-network ETW profile under the same scenario, then compare an approved capture configuration
Do not confuse withUTC_E_FAILED_TO_START_NDISCAP occurs after capture is allowed but the capture component cannot start

Isolate one changing condition

  1. Collect the high-value state: scenario signer, capture action, interface scope, destination/ring, privacy policy and authorization decision.
  2. Use a passing control on the same Windows build, then run a non-network ETW profile under the same scenario, then compare an approved capture configuration.

Nearby result: UTC_E_FAILED_TO_START_NDISCAP — occurs after capture is allowed but the capture component cannot start.

Capture safety

When testing this result, keep scope and duration minimal, document where the capture is stored and verify normal stop/cleanup. Packet and kernel captures can contain sensitive data and consume bounded system resources.

Operational response

Remove the capture action or use an approved diagnostic workflow; do not bypass policy with another sniffer.

Technical references


Looking for a different code? Search another status or error code.

Exit mobile version