| Previous | Next |
| NS_E_DRM_INVALID_LICENSEBLOB | NS_E_DRM_DRMV2CLT_REVOKED |
NS_E_DRM_INCLUSION_LIST_REQUIRED
The state behind the HRESULT
NS_E_DRM_INCLUSION_LIST_REQUIRED belongs to the point where the requested operation requires an inclusion list that the license does not contain. This result comes from WMDRM for Network Devices, whose state machine implements the transmitter/receiver protocol that registers a network playback device, approves it, validates proximity, opens a protected session and transcrypts licensed content for that receiver.
The investigation becomes concrete when you query the license policy for the required inclusion-list object.
Build a useful incident record
This result is meaningful only while the following state remains associated with one operation: device certificate and serial number, registration-database entry, approval flag, validation timestamp, network session, protocol message and transcrypt policy. Preserve the exact WMDRM-ND message type, device identifier, certificate chain, registration state, round-trip timing and the first protocol HRESULT for it.
This evidence matters because the rejected condition is specifically that the requested operation requires an inclusion list that the license does not contain.
Focused verification
- Preserve this result and
0xC00D28B5before cleanup, fallback or another media item changes the context. - Apply the narrow correction for it: issue/use a license containing the required approved-device list.
- Associate it with its current WMDRM for Network Devices object and the requested action.
- Run the direct check for it: query the license policy for the required inclusion-list object.
- Compare the failure with a known-good case that changes only the property named by this condition: the requested operation requires an inclusion list that the license does not contain.
- Repeat the same action with the same content/device identity and verify that it is not replaced by another policy or trust failure.
Reconstruct the decision
A useful failure model for it links cause and recovery: the requested operation requires an inclusion list that the license does not contain. Verify that model when you query the license policy for the required inclusion-list object, then make the smallest change needed to issue/use a license containing the required approved-device list. The result model is suitable for a regression fixture because its expected state change is observable without weakening the DRM policy.
Interpretation limits
The established fact is that the requested operation requires an inclusion list that the license does not contain. That fact does not independently establish damaged media bytes, a missing decoder, a generally broken network, or invalid rights for every other action.
If the Player, encoder, setup program or device layer later emits a broader error, retain it as the first specific result. The object and operation attached to it are usually more diagnostic than a later cleanup or user-interface summary.
State table
| Field | Value |
|---|---|
| Lower result | the earliest store, network, cryptographic, driver or provider status preceding the final it wrapper |
| Owner | operation, API/callback, object or session identifier, and component/device version associated with it |
| Direct check | query the license policy for the required inclusion-list object |
| Policy input | requested action plus the exact license, certificate, profile, output or registration property evaluated by it |
| Temporal state | trusted/system time, validity interval, request sequence and retry number when they influence it |
Neighboring security decisions
| Result | Why it points elsewhere |
|---|---|
NS_E_DRM_EXPIRED_LICENSEBLOB | the license blob carried in the Cardea request has passed its validity interval |
NS_E_DRM_INVALID_LICENSEBLOB | the Cardea request contains a license blob that fails format, integrity or binding checks |
NS_E_DRM_DRMV2CLT_REVOKED | a legacy DRM v2 client component required by the operation is revoked |
Repair criterion
The next attempt becomes meaningful only after you issue/use a license containing the required approved-device list. Success means that the same requested action is accepted after that precise state change, not merely that another file or device happens to work.
- A broad reset is not the first step for it; Do not delete the complete device-registration database before preserving the failing device record and certificate chain; that removes the distinction between registration, approval, validation and session failures.
- Do not alter trusted time, revocation enforcement, certificate validation or output policy merely to suppress it; that bypasses the decision instead of correcting its input.
- Retain one failing artifact and one corrected artifact so the resolution of it can be regression-tested.
Acceptance condition
For the final it test, keep the content KID or file hash, requested action, user/account, device identity and output route unchanged wherever they apply.
Technical references
- Windows Media DRM 10 for Network Devices — defines the platform objects used when diagnosing it.
- Device registration — documents the protocol or API boundary behind it.
- Using the WMDRM-ND protocol — provides the normative workflow relevant to it.
- MS-DRMND protocol specification — lists the security and state transitions used to interpret it.
Looking for a different code? Search another status or error code.
