| Previous | Next |
| UTC_E_CERT_REV_FAILED | UTC_E_KERNELDUMP_LIMIT_REACHED |
UTC_E_FAILED_TO_START_NDISCAP
Where the UTC workflow stopped: NDIS capture component startup
UTC_E_FAILED_TO_START_NDISCAP has the unsigned value 0x87C51040. In UTC it comes from network or kernel diagnostic capture, where NDIS capture component startup owns the decision. The key question is which UTC object rejected the request. The immediate contract failed because network capture passed policy but the NDISCAP service/driver path did not become operational, so diagnosis should remain at that boundary until a controlled comparison crosses it.
Network and kernel captures are high-impact diagnostic actions. Policy approval, capture-component startup, ETW/driver resources and rate limits are independent gates and should be verified in that order.
Evidence to preserve
| UTC diagnostic field | Value |
|---|---|
| Owning state or object | NDIS capture component startup |
| Producing layer | network or kernel diagnostic capture |
| Do not confuse with | UTC_E_NETWORK_CAPTURE_NOT_ALLOWED is a policy denial before component startup |
| Evidence to collect | service/driver state, filter bindings, target adapters, start HRESULT, privileges and operational logs |
| Narrow comparison | start a capture on one known physical adapter and compare with the failing adapter/topology |
Controlled reproduction
- Export the relevant
Microsoft-Windows-UniversalTelemetryClient/Operationalevents and preserve their ActivityId or request correlation alongside this result. - Capture service/driver state, filter bindings, target adapters, start HRESULT, privileges and operational logs. Do this before restarting the service or deleting any working directory.
- Perform this one-variable comparison: start a capture on one known physical adapter and compare with the failing adapter/topology.
- After the comparison, record the next HRESULT and whether the requested session, action, trigger or output object was actually created.
Nearby result: UTC_E_NETWORK_CAPTURE_NOT_ALLOWED — is a policy denial before component startup.
Capture safety
When testing this result, keep scope and duration minimal, document where the capture is stored and verify normal stop/cleanup. Packet and kernel captures can contain sensitive data and consume bounded system resources.
Correction and verification
Repair the capture component or binding and verify clean start/stop; avoid reinstalling unrelated network protocols.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for network or kernel diagnostic capture while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis — reference for network or kernel diagnostic capture while interpreting it.
- Microsoft: NDIS filter-driver installation and binding
- Microsoft: Packet Monitor overview
Looking for a different code? Search another status or error code.
