| Previous | Next |
| WEP_E_HARDWARE_NOT_COMPLIANT | WEP_E_PROTECTION_SUSPENDED |
WEP_E_LOCK_NOT_CONFIGURED
WEP_E_LOCK_NOT_CONFIGURED — 0x88010004
WEP_E_LOCK_NOT_CONFIGURED means that device encryption cannot satisfy EAS lockout behavior because the required device-lock/recovery configuration is absent.
Start with the failing layer
Windows Encryption Provider integration has separate gates for provider licensing, hardware readiness, volume support, provisioning, active protection, device-lock configuration, and EAS compliance. WEPHOSTSVC events should therefore be read alongside the third-party provider’s own inventory and logs, not as a replacement for them.
Volume encryption being active does not by itself prove that policy-driven device lock and recovery are configured.
Preserve before retrying
- Provider lock capability, recovery material escrow, and device-lock configuration
- EAS failed-attempt and RequireEncryption policies
- Boot/recovery environment state and provider management policy
- WEPHOSTSVC/provider events identifying the missing prerequisite
Three useful comparisons
- Configure lock/recovery on a disposable encrypted device.
- Exercise a safe simulated lockout using vendor guidance.
- Verify recovery-key access before enabling enforcement.
Decision points
Use the outcomes to narrow the layer rather than to accumulate unrelated fixes for device-lock prerequisites for encryption policy:
A defensible fix
Repair the failed contract rather than the surrounding system: Configure the provider’s lockout and recovery prerequisites through an approved management workflow before applying the EAS policy.
Close the incident only when a controlled lock test enters the expected protected state and authorized recovery restores access without data loss.
Technical references
The details above are grounded in the following Microsoft specifications and API documentation:
Looking for a different code? Search another status or error code.
