| Previous | Next |
| ERROR_IPSEC_QM_POLICY_PENDING_DELETION | WARNING_IPSEC_QM_POLICY_PRUNED |
WARNING_IPSEC_MM_POLICY_PRUNED
The Main Mode policy was successfully added, but some of the requested offers are not supported.
WARNING_IPSEC_MM_POLICY_PRUNED is Windows status 13024 (0x000032E0) associated with addition of an IPsec Main Mode policy with unsupported offers removed. For WARNING_IPSEC_MM_POLICY_PRUNED, the system meaning is “The Main Mode policy was successfully added, but some of the requested offers are not supported.” Preserve the value at the API boundary because subsequent cleanup or logging calls can overwrite the last-error state.
Operational meaning
For WARNING_IPSEC_MM_POLICY_PRUNED, the key question is whether at least one supported Main Mode offer remains and the caller evaluates the effective policy rather than assuming every requested offer was installed. The value describes addition of an IPsec Main Mode policy with unsupported offers removed; it does not prove that the whole domain, DNS service, network, servicing stack, application package, or operating system has failed.
Likely impact: The add operation can succeed with a weaker or narrower effective policy than requested, so compliance validation is required. For WARNING_IPSEC_MM_POLICY_PRUNED, record the scope that was actually tested instead of escalating from one rejected object or phase to a system-wide outage.
Where this result appears
WARNING_IPSEC_MM_POLICY_PRUNEDcan appear while processing addition of an IPsec Main Mode policy with unsupported offers removed.WARNING_IPSEC_MM_POLICY_PRUNEDcan appear while adding or validating Main Mode or Quick Mode policy offers.WARNING_IPSEC_MM_POLICY_PRUNEDcan appear while classifying IKE negotiation status values returned by policy or VPN components.WARNING_IPSEC_MM_POLICY_PRUNEDcan appear while a firewall, VPN, or IPsec management tool that exposes Win32 policy status.
Typical causes
- For
WARNING_IPSEC_MM_POLICY_PRUNED, one or more encryption, integrity, DH, or authentication offers are unsupported. - For
WARNING_IPSEC_MM_POLICY_PRUNED, policy was copied from another Windows release. - For
WARNING_IPSEC_MM_POLICY_PRUNED, provider capability differs across hosts. - For
WARNING_IPSEC_MM_POLICY_PRUNED, the caller interprets a warning as total failure.
Diagnostic sequence
- capture
WARNING_IPSEC_MM_POLICY_PRUNEDimmediately after the failing or status-returning call and record whether the API uses Win32, DNS_STATUS, HRESULT conversion, or callback semantics. - identify the exact target involved in addition of an IPsec Main Mode policy with unsupported offers removed, including stable GUIDs, DNs, zone names, package identities, file hashes, policy names, or process identifiers as applicable.
- prove the state boundary: at least one supported Main Mode offer remains and the caller evaluates the effective policy rather than assuming every requested offer was installed.
- collect requested Main Mode offers and effective installed offers before restarting services, deleting objects, rebuilding packages, or changing policy.
- correlate OS build and cryptographic providers with IKEEXT operational events, Windows Filtering Platform events, IPsec security audits, policy export, peer configuration, and packet capture.
- for
WARNING_IPSEC_MM_POLICY_PRUNED, determine whether the result is a failure, warning, informational completion, continuation request, or marker constant before choosing retry behavior. - for
WARNING_IPSEC_MM_POLICY_PRUNED, after changing one responsible condition, repeat the same smallest operation and verify both success and absence of unintended partial effects.
Evidence to preserve
- For
WARNING_IPSEC_MM_POLICY_PRUNED, collect requested Main Mode offers. - For
WARNING_IPSEC_MM_POLICY_PRUNED, collect effective installed offers. - For
WARNING_IPSEC_MM_POLICY_PRUNED, collect OS build and cryptographic providers. - For
WARNING_IPSEC_MM_POLICY_PRUNED, collect policy export before and after. - For
WARNING_IPSEC_MM_POLICY_PRUNED, collect IKEEXT events during a test negotiation.
For WARNING_IPSEC_MM_POLICY_PRUNED, correlate this evidence with IKEEXT operational events, Windows Filtering Platform events, IPsec security audits, policy export, peer configuration, and packet capture. Preserve raw identifiers and the first detailed diagnostic: translating everything to 13024 can hide whether the cause was validation, topology, authorization, replication, policy, file I/O, packaging, or an intentional continuation state.
Recovery and retry
The recovery objective for WARNING_IPSEC_MM_POLICY_PRUNED is to review the pruned offers, confirm the remaining set meets security requirements, and replace unsupported proposals explicitly rather than retrying unchanged.
For WARNING_IPSEC_MM_POLICY_PRUNED, retry only after the recorded boundary changes and prior completion is known. Read-only discovery for WARNING_IPSEC_MM_POLICY_PRUNED can usually be repeated with bounded backoff; directory mutations, DNS updates, policy installation, servicing actions, and PRI writes require a state check first. Backoff for WARNING_IPSEC_MM_POLICY_PRUNED cannot repair malformed input, unsupported structure, identity collision, missing authority, or incompatible package metadata.
Telemetry and support fields
- For
WARNING_IPSEC_MM_POLICY_PRUNED, recordipsec_mm_policy_pruned_operation— producing API, command, callback, or servicing phase. - For
WARNING_IPSEC_MM_POLICY_PRUNED, recordipsec_mm_policy_pruned_target— stable object, zone, policy, package, file, or account identity. - For
WARNING_IPSEC_MM_POLICY_PRUNED, recordipsec_mm_policy_pruned_state_beforeandipsec_mm_policy_pruned_requested_state. - For
WARNING_IPSEC_MM_POLICY_PRUNED, recordipsec_mm_policy_pruned_first_status— earliest component-specific code before translation. - For
WARNING_IPSEC_MM_POLICY_PRUNED, recordipsec_mm_policy_pruned_server,ipsec_mm_policy_pruned_process, UTC timestamp, and correlation ID.
A support bundle for WARNING_IPSEC_MM_POLICY_PRUNED should include decimal 13024, hexadecimal 0x000032E0, the smallest reproducible request, target identity, effective configuration, and evidence from the owning Windows component. When documenting WARNING_IPSEC_MM_POLICY_PRUNED, remove secrets from exported logs but keep SIDs, GUIDs, package-family names, record types, and hashes when they are needed to distinguish objects.
Difference from nearby results
WARNING_IPSEC_QM_POLICY_PRUNED applies to Quick Mode data protection; this warning concerns Main Mode peer authentication and key establishment This distinction determines whether the correct next step is input correction, topology repair, continuation, policy review, package rebuild, or no error handling at all.
Practical validation scenario
A policy contains a deprecated Main Mode offer and a current one. Windows installs the current offer and warns that the deprecated proposal was pruned. A negative test should reproduce WARNING_IPSEC_MM_POLICY_PRUNED with the responsible condition preserved; the recovery test should alter only that condition and confirm the intended final state.
Developer and administrator guidance
Developers should model WARNING_IPSEC_MM_POLICY_PRUNED explicitly in the result domain instead of collapsing every nonzero value into “failed.” Administrators should capture evidence before destructive remediation and use the component that owns addition of an IPsec Main Mode policy with unsupported offers removed. Monitoring for WARNING_IPSEC_MM_POLICY_PRUNED should suppress range markers and classify warning, informational, cancellation, and continuation values separately from terminal failures.
References
- Microsoft: exact Win32 system error range — official context relevant to
WARNING_IPSEC_MM_POLICY_PRUNED. - Microsoft: Audit IPsec Main Mode — official context relevant to
WARNING_IPSEC_MM_POLICY_PRUNED. - Microsoft: Windows Filtering Platform diagnostics — official context relevant to
WARNING_IPSEC_MM_POLICY_PRUNED.
Looking for a different code? Search another status or error code.
