| Previous | Next |
| ERROR_ALL_SIDS_FILTERED | NS_E_NOCONNECTION |
ERROR_BIZRULES_NOT_ENABLED
Authorization Manager business-rule scripts disabled identifies a scoped API or runtime boundary rather than a general machine failure. The application attempted to evaluate an AzMan business-rule script while script execution is disabled for that authorization application.
Where the result is produced
This is a policy/capability rejection before script evaluation, not a false result returned by the business rule. Keep ERROR_BIZRULES_NOT_ENABLED, its numeric value, and the first returning operation together.
Evidence to preserve
| Capture | Diagnostic value |
|---|---|
| Authorization store/application, task/operation, business-rule script hash, host process, and script-engine configuration. | Identifies the concrete object and operation associated with Authorization Manager business-rule scripts disabled. |
| Whether the same role decision succeeds when no business rule is attached. | Separates argument or lifecycle state from a lower-layer provider failure. |
| First security/authorization event and the exact API returning the HRESULT. | Creates a stable before-and-after comparison. |
| Effective identity and policy version at the time of the call. | Shows whether this condition is the first result or a translated summary. |
Preserve authorization store/application, task/operation, business-rule script hash, host process, and script-engine configuration before reinstalling, rebooting, clearing state, or substituting another device or provider.
A controlled diagnostic sequence
- Evaluate a static role assignment for the same operation. Keep unrelated inputs fixed so the changed result remains attributable to the tested variable.
- Enable scripts only in an isolated test application and compare the rule result. Record the first returned status and any state transition observed.
- Repeat after one policy refresh without changing the resource ACL or application data. Treat a changed result as a separate failure rather than automatic resolution.
Correction and proof
Targeted correction. Remove the script dependency or explicitly enable and secure business-rule execution in the owning AzMan application.
Acceptance criterion. The authorization decision is reproducible, script failures are logged separately, and disabling scripts again produces the expected controlled rejection.
Technical references
References for ERROR_BIZRULES_NOT_ENABLED on the deployed platform version.
- Microsoft Open Specifications: HRESULT values — defines the status namespace used.
- Microsoft: HRESULT facility extraction — documents the API or lifecycle behind this condition.
- Microsoft: Windows security auditing overview — provides ABI, implementation, or protocol context.
- Microsoft: Authorization Manager — supports the portability and verification limits.
Looking for a different code? Search another status or error code.
