Fix it now
Neither code is an activation code. 0x80070422 is Win32 error 1058, which Microsoft publishes as a service that cannot be started because it is disabled; 0x80070426 is Win32 error 1062, the service has not been started. The service is Software Protection, sppsvc, and until it runs nothing on the machine can activate.
sc qc sppsvc
sc config sppsvc start= delayed-auto
net start sppsvc
slmgr /dlv
- Read the
START_TYPEline fromsc qc sppsvcbefore you change anything.DISABLEDis the whole answer for 0x80070422 and tells you somebody or something set it that way. - Note the space after
start=in the second command. Microsoft documents that space as required, and without it sc.exe fails rather than doing nothing visible. - If
net start sppsvcreturns an error of its own, stop and read it. That is a different fault from a disabled service and the next section separates the two. - To see the text behind any code on this machine, run
slui.exe 0x2a 0x80070422. That is Microsoft’s documented way to read an activation code rather than looking it up.
Finding sppsvc stopped is not a fault. It is configured to start on demand and shut down when idle, so what matters is the start type, not the state.
If slmgr /dlv now returns a licence status you can stop here. If the service will not stay started, the next section covers the four reasons it does not.
Why it happens
Both codes are ordinary Windows service errors that reach you through an activation dialogue. Microsoft publishes 0x80070422 as Win32 error 1058, ERROR_SERVICE_DISABLED, “The service cannot be started, either because it is disabled or because it has no enabled devices associated with it”, and 0x80070426 as Win32 error 1062, ERROR_SERVICE_NOT_ACTIVE, “The service has not been started”. Nothing in either sentence mentions licensing, which is why the same pair turns up in Windows Update and the Store.
The service they are complaining about is Software Protection. It owns the licence store, evaluates licences, talks to activation services and answers every question Windows asks about its own state. With it disabled, the components that depend on it return whatever the service control manager handed them, and you get a licensing-shaped error for a service-shaped problem.
The distinction that saves the most time is between the start type and the running state. Software Protection is configured to start automatically after a delay and to stop itself once it has nothing to do, so a stopped service on a healthy machine means nothing at all. A start type of DISABLED means something set it deliberately. A start type that is correct while the service still refuses to start means the service is failing, and those two situations have nothing in common except the code on screen.
One code in this article is worth treating with suspicion. Microsoft publishes no description for 0xC004F07B on any support or documentation page, and neither does it publish anything for the Security-SPP events 902, 903 and 16394 that people are routinely told to read. You can still read what your own machine says about a code: slui.exe 0x2a <code> is documented and prints the text Windows itself holds.
The start type has been set to Disabled
You have this one if sc qc sppsvc reports START_TYPE as DISABLED, and the Start button is greyed out in the Services console.
- Set it back:
sc config sppsvc start= delayed-auto. The space after the equals sign is required. - Start it:
net start sppsvc. - Confirm with
sc query sppsvc, which should report RUNNING at least briefly. - Retry activation with
slmgr /atoand read the result withslmgr /dlv.
If the setting reverts after a reboot, something with higher precedence is writing it. Chase that rather than setting the value again.
A tuning, privacy or hardening script switched it off
You have this one if The machine was recently run through an optimiser or a security baseline, and several other services are disabled alongside it.
- Check the other licensing services the same scripts usually touch: Client License Service (
ClipSVC) and Windows License Manager Service (LicenseManager). - Check the Windows Update service too, since a disabled one returns the same 0x80070422 from a completely different place.
- Restore each to its normal configuration and start it.
- Remove the entry from the script or baseline, or it comes back at the next run.
Group Policy is enforcing the disabled state
You have this one if The service reverts to Disabled after every reboot or policy refresh, on domain-joined machines only.
- Produce a policy report:
gpresult /h C:\report.html, and read the System Services section. - The setting lives under Computer Configuration, Policies, Windows Settings, Security Settings, System Services.
- Have it corrected centrally rather than on the client, then run
gpupdate /forceand start the service.
The service is configured correctly and still will not start
You have this one if net start sppsvc returns an error of its own rather than completing.
- Confirm the Remote Procedure Call service is running:
sc query RpcSs. - Read the failure in Event Viewer under Windows Logs, System, filtered on the Service Control Manager source.
- Repair the component store first, then the system files:
DISM /Online /Cleanup-Image /RestoreHealth, thensfc /scannow. - Reboot and try again before concluding anything about licensing.
DISM before sfc. sfc repairs from the component store, so repairing that store first gives it a healthy source to copy from.
Full reference
What each command in this article is for
| Command | What it does | Documented by |
|---|---|---|
sc qc sppsvc |
Shows the configured start type | sc.exe config reference |
sc query sppsvc |
Shows the current running state | sc.exe reference |
sc config sppsvc start= delayed-auto |
Sets the start type. Accepted values are boot, system, auto, demand, disabled and delayed-auto | sc.exe config reference |
net start sppsvc |
Starts the service and prints its own error if it fails | Microsoft’s tokens.dat repair article |
slmgr /dlv |
Detailed licence status. Does not require elevation | Slmgr.vbs options |
slui.exe 0x2a <code> |
Prints the text Windows holds for an activation error code | KMS activation known issues |
A wrong start= value is one of the easier ways to make a machine worse. sc config will accept disabled just as readily as delayed-auto, and there is no confirmation prompt.
The registry value behind the start type
The service configuration lives at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sppsvc. The Start value holds the start type: 2 for automatic, 3 for manual, 4 for disabled. Reading it is a reasonable check; writing it is not the right tool, because sc config does the same job with validation.
Export the key before changing anything under Services. A wrong value there can leave a machine unable to boot, and that is a far larger problem than an activation error.
If sc config reports success and the value returns to 4, the fault is not on this machine. Something with higher precedence is writing it: a policy, a management tool, or a scheduled script. Editing the value again only resets the clock on the next refresh.
Codes and events in this family that Microsoft does not publish
Four of the six entries this article covers have no published description anywhere on learn.microsoft.com or support.microsoft.com. That is worth knowing before you spend an afternoon on a code someone has glossed for you confidently.
| Entry | What can be said about it |
|---|---|
0xC004F07B |
Returned by the licensing service. No published description. Read the machine’s own text with slui.exe 0x2a 0xC004F07B |
| Event ID 902 | Written to the Application log by the Security-SPP source. No published description |
| Event ID 903 | Same source, same position. No published description |
| Event ID 16394 | Same source. Appears frequently on healthy machines, which is the main thing to know about it |
Microsoft does document a handful of events from this source, and where you need an event to base a decision on, those are the ones to look for rather than the numbers above. When an undocumented code is all you have, the honest approach is to treat it as a symptom and diagnose the service state directly, which is what the commands in this article do.
When the service starts and immediately stops
- Check the Application log filtered on the Security-SPP source for entries written at the moment it stopped.
- Check your endpoint protection product’s own log for a block or a quarantine at the same timestamp. Activators patch licensing binaries, so a detection here is not automatically a false positive.
- If the product supports it, add the vendor’s recommended exclusion rather than turning protection off and leaving it off.
- Report a genuine false positive to the vendor. A machine left unprotected to make an activation error go away is a worse outcome than the error.
Confirming this was never a licensing problem
Once the service starts, slmgr /dlv returns a full status rather than an error, and that output tells you what the machine actually holds: the edition, the channel, the partial key and the licence status. If that output was already correct before the service was disabled, nothing about your entitlement changed while it was down. A machine that cannot check its licence is in a different position from one that has a bad licence, and only the second is a purchasing question.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80070422 |
Win32 error 1058, ERROR_SERVICE_DISABLED: the service cannot be started because it is disabled | Microsoft Learn |
0x80070426 |
Win32 error 1062, ERROR_SERVICE_NOT_ACTIVE: the service has not been started | Microsoft Learn |
0xC004F07B |
Returned by the licensing service alongside the service errors above. Read the machine’s own text with slui.exe 0x2a | not published by the vendor |
Event ID 902 |
Written to the Application log by the Security-SPP source. No published description | not published by the vendor |
Event ID 903 |
Written by the same source. No published description | not published by the vendor |
Event ID 16394 |
Written by the same source, routinely and on healthy machines. No published description | not published by the vendor |
Confirm the fix worked
sc qc sppsvcreports a start type other than DISABLED.net start sppsvccompletes, or reports that the service is already running.slmgr /dlvreturns a full licence status rather than an error.- Settings, System, Activation loads and reports a state.
- Reboot, then repeat the
sc qccheck, which is what proves nothing is putting the service back to Disabled.
Questions people ask about this
Should the Software Protection service be running all the time?
No. It starts on demand and stops when idle, so finding it stopped proves nothing. The start type is what matters. Disabled is wrong; automatic with a delayed start is the normal configuration.
Why does 0x80070422 also appear in Windows Update?
Because it is a generic service error rather than an activation one. Microsoft publishes it as Win32 error 1058, a service that cannot be started because it is disabled. Any component that asks for a disabled service can return it, so identify which service the failing component needs before assuming this is about licensing.
Do I need to buy anything to clear this?
No. Your entitlement is untouched. The machine is unable to check its licence, which is not the same as having a bad one. Fix the service, run slmgr /dlv, and read the status before considering anything else.
Is Automatic as good as delayed automatic?
It will work. Delayed start is the shipped configuration and keeps the service out of the way during boot, so return it to delayed automatic unless you have a specific reason not to.
What does 0xC004F07B mean?
Microsoft does not publish a description for it. You can read what your own machine says with slui.exe 0x2a 0xC004F07B, which is documented. Treat any page that gives you a confident one-line meaning for it with caution, because the vendor is not the source of that sentence.
