| Previous | Next |
| hrUnknownExpiryTokenFormat | hrFileClose |
hrContentsExpired
Operational meaning
hrContentsExpired means the Directory Service judged the backup contents too old under the expiry information associated with the set.
The stored value is 0xC7FF0011 (facility-specific HRESULT). The legacy symbolic name comes from the Windows Directory Service backup/restore message header.
The first useful distinction is that the failure is a freshness policy result, not proof that the database or logs are physically corrupt. Start by recording backup creation time, token metadata, current time source, domain-controller role, and available newer system-state backups.
Before altering files or retrying
- Code-specific observation: record backup creation time, token metadata, current time source, domain-controller role, and available newer system-state backups.
Comparison points
It specifically means that the failure is a freshness policy result, not proof that the database or logs are physically corrupt. Related values below can appear in the same workflow but require a different response:
hrMissingExpiryToken | the restore request lacks the expiry token created with the backup set |
|---|---|
hrUnknownExpiryTokenFormat | bytes were supplied as an expiry token but the Directory Service cannot parse their format |
hrDeleteBackupFileFail | backup cleanup could not delete an artifact it was responsible for removing |
Objects and state involved
| Diagnostic layer | the opaque expiry token linking a legacy AD backup set to restore authorization and freshness |
|---|---|
| Relevant API surface | DsBackupPrepare token output and DsRestorePrepare token input |
| Code-specific condition | the Directory Service judged the backup contents too old under the expiry information associated with the set |
| Narrow corrective direction | select a newer valid system-state backup and follow supported AD recovery guidance instead of bypassing expiry checks |
The token must be stored as opaque binary data with the backup set. Without a token, DsRestorePrepare returns a restricted context usable only to query restore locations.
Recommended handling
- Record it,
0xC7FF0011, the API name, the current phase, and all live context or file owners. - Verify the condition by recording backup creation time, token metadata, current time source, domain-controller role, and available newer system-state backups.
- Apply only the targeted fix: select a newer valid system-state backup and follow supported AD recovery guidance instead of bypassing expiry checks.
Acceptance criteria for a fix
A useful regression test should force the condition “the Directory Service judged the backup contents too old under the expiry information associated with the set”, call one documented API transition, and assert the exact HRESULT.
Actions that can make diagnosis worse
- Do not borrow a token from another backup set.
- Do not convert the token through text encoding.
Technical references
- DsRestorePrepare token rules — API ordering, file semantics, warning/error interpretation, or recovery behavior relevant to this HRESULT.
- AD backup walkthrough
- AD restore walkthrough
- Microsoft list of AD DS backup errors
Looking for a different code? Search another status or error code.
