Fix it now
Microsoft publishes 0x803F9000 and 0x803F9001 as “The license is expired or corrupt”, with a documented remedy: run the troubleshooter for Windows apps to reset the Store cache. The two codes that travel with them, 0x803F9008 and 0x803F9009, mean something simpler – the device is offline.
w32tm /resync
netsh winhttp show proxy
- Confirm the device is genuinely online, and online through a path that is not a captive portal. If you are looking at 0x803F9008 or 0x803F9009 rather than 0x803F9000, that is the whole diagnosis – Microsoft publishes those two as the device being offline.
- Run Microsoft’s documented remedy for 0x803F9000 and 0x803F9001: the troubleshooter for Windows apps, which resets the Store cache. On current Windows it sits with the other troubleshooters on the Troubleshoot page in Settings, under System.
- Check the clock. An expiry check compares a stored date against the system clock, so a machine that thinks it is next year considers everything expired.
w32tm /resynccorrects it. - Read the proxy the system account actually uses. Licensing traffic is a signed exchange, and a proxy that re-signs TLS or demands credentials the service cannot supply breaks it.
- Sign out of the Store or the work account, sign back in, and let the licence be fetched again.
Check the subscription in the portal once, so you are not chasing a local problem that does not exist. An active subscription plus a failing device means the device. An expired subscription means the subscription, and no local repair touches it.
If that fixed it you can stop here. If not, the next section covers what the four codes say and where the licence the device is complaining about actually lives.
Why it happens
Store apps, subscription entitlements and several Microsoft 365 licensing paths are handled by the client licence service rather than by the Software Protection service that handles Windows activation itself. It keeps licences locally so that applications start when the network is slow or absent. That is a convenience, and it is also how a machine ends up holding a stale answer long after the real entitlement changed.
Microsoft publishes 0x803F9000 and 0x803F9001 with identical text: the licence is expired or corrupt, and to help resolve the error you should try running the troubleshooter for Windows apps to reset the Store cache. Two things are worth taking from that. The published meaning does not distinguish between an expiry and a corruption, so do not build a diagnosis on which of the two you got. And the documented first move is a cache reset, not a licence purchase.
The other two codes are where the v1 version of this article went wrong. It described 0x803F9008 and 0x803F9009 as licence acquisition failing against an unusable cache. Microsoft publishes both of them as: your device is offline, and your device needs to be online to use this product. That changes the order of work entirely. If you have one of those, you check the network before you touch anything else.
Two things poison a local licence reliably. The first is a device that has been off the network past the point where it needed to refresh, which is common on machines that live in a drawer between projects. The second is licensing traffic that reaches the internet but not intact – a proxy performing TLS inspection, or one demanding credentials a background service has no way to supply. Both look like corruption from the machine’s point of view, and neither is.
The device is offline, or effectively offline
You have this one if 0x803F9008 or 0x803F9009, or a machine that works on a mobile hotspot and fails on the corporate network.
- Get it onto a connection with no captive portal and give it a few minutes.
- Check the proxy the system account uses with
netsh winhttp show proxy, which is not the same as the browser proxy. - Confirm no endpoint protection product is filtering the licensing service’s outbound connections.
- Retry the application once the path is clean.
The cached licence needs resetting
You have this one if 0x803F9000 or 0x803F9001 on a device that is demonstrably online, with a healthy subscription in the portal.
- Run the troubleshooter for Windows apps, which is Microsoft’s published remedy for these two codes and resets the Store cache.
- Sign out of the Store or the work account and sign back in so licences are fetched again.
- Open the affected application and let it acquire its licence.
- If the Store itself misbehaves, repair and then reset it from its entry in the installed applications list before doing anything more drastic.
The clock or the time zone is wrong
You have this one if The date is out by more than a few minutes, usually after a flat CMOS battery or a virtual machine restored from a snapshot.
- Correct the time zone and enable automatic time in Settings.
- Run
w32tm /resyncfrom an elevated prompt. - Confirm the Windows Time service is running with
sc query w32time. - Retry once the clock agrees with reality.
There is no /force parameter on w32tm /resync. Adding one makes w32tm report the argument as unexpected and print its usage block without resynchronising anything.
Licensing traffic is being intercepted rather than blocked
You have this one if A whole site fails together, and the same laptop works immediately on a home connection.
- Ask the network team to exempt Microsoft licensing and activation endpoints from TLS inspection rather than simply permitting them.
- Confirm the proxy does not require Basic authentication. Microsoft documents a related activation failure caused by exactly that, because the activation interface has no way to supply credentials.
- Retest from an unfiltered connection first, so you are asking for a change you have evidence for.
The subscription behind the product really has lapsed
You have this one if The portal shows the product as expired or the user’s seat as gone.
- Check Billing then Licenses in the admin centre, or the subscription page on the account, before any local work.
- Renew or reassign, then sign the user out and back in on the device.
- Only then look at the local cache. A local repair against a lapsed subscription changes nothing.
Full reference
What the four codes say
| Code | Published text | First move |
|---|---|---|
0x803F9000 |
The license is expired or corrupt. Try running the troubleshooter for Windows apps to reset the Store cache | Run the troubleshooter |
0x803F9001 |
Identical published text | Run the troubleshooter |
0x803F9008 |
Your device is offline. Your device needs to be online to use this product | Check the network |
0x803F9009 |
Identical published text to 0x803F9008 | Check the network |
Repair options, least destructive first
| Action | When to use it |
|---|---|
| Run the troubleshooter for Windows apps | Microsoft’s documented remedy for 0x803F9000 and 0x803F9001 |
| Sign out of the work or Microsoft account and back in | The entitlement changed recently and the device has not caught up |
| Repair the Microsoft Store from its advanced options | First attempt at the Store itself. Keeps application data |
| Reset the Microsoft Store from the same place | Second attempt. Clears the application’s local state |
| Rebuild the Software Protection store | Only for Windows activation problems, not for these codes. Different service, different store |
Do not reach for the Software Protection tokens.dat rebuild to fix a 0x803F9xxx code. That documented procedure – stop sppsvc, rename tokens.dat under %windir%\system32\spp\store\2.0, start sppsvc, run slmgr /rilc – repairs the Windows activation store. These codes come from the client licence service, which is a different component with a different store, and rebuilding the wrong one costs you your Windows activation state for nothing.
Where this article stops short, deliberately
Earlier versions of this guidance told readers to stop the client licence service and rename a tokens.dat file under a named path in ProgramData. No Microsoft page publishes that path or that procedure for the client licence service, so it is not in this article. Where you need to go further than the troubleshooter and a re-sign-in, the supported escalation is the Store’s own repair and reset options and, failing those, a support case with the codes and the Application log.
Telling a cache problem from a real expiry
- Check the portal once. An active subscription with an assigned seat and a failing device points at the device.
- Check whether the code is 0x803F9008 or 0x803F9009. Those two are published as the device being offline, and are not about a licence at all.
- Check the clock. A machine whose date is wrong will consider stored licences expired regardless of what the portal says.
- Check the system-level proxy with
netsh winhttp show proxy. Background services do not use the browser’s settings. - Only after those four does a cache reset tell you anything useful.
Why the same laptop keeps doing this
Almost always because it spends long periods off the network, or because it is being shut down abruptly rather than cleanly. Devices that need to renew an entitlement need to be online to do it, and one that surfaces for an hour a month will keep arriving at the same state. Bringing it online regularly and shutting it down properly removes most of these reports without anybody running a command.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x803F9000 |
The licence is expired or corrupt. Microsoft’s published remedy is to run the troubleshooter for Windows apps to reset the Store cache | Microsoft Learn |
0x803F9001 |
Microsoft publishes the same text as for 0x803F9000 | Microsoft Learn |
0x803F9008 |
Your device is offline. Your device needs to be online to use this product | Microsoft Learn |
0x803F9009 |
Microsoft publishes the same text as for 0x803F9008 | Microsoft Learn |
Confirm the fix worked
- The affected application starts fully licensed rather than in a reduced state.
- Settings, System, Activation shows a clean status with no subscription warning.
- The system clock and time zone are right, and
w32tm /resynccompletes without error. netsh winhttp show proxyshows the configuration you expect for this machine.- Reboot, wait for the machine to settle, and confirm the licence is still good rather than re-prompting.
Questions people ask about this
Does fixing this cost anything?
Not if the subscription behind the product is active. Every step here uses tools already on the machine. Only where the portal shows the subscription as expired are you looking at a licensing problem rather than a local one.
How do I tell a cache problem from a real expiry?
Check the portal once, before touching the device. An active subscription with an assigned seat plus a failing device means the device. An expired subscription means the subscription, and no amount of cache clearing will help.
Why do 0x803F9008 and 0x803F9009 appear alongside these?
Because they come from the same licensing flow, but they say something different. Microsoft publishes both as the device being offline and needing to be online to use the product. If you have one of those, check the connection before the cache.
Will I lose my installed apps?
No. Resetting the Store cache removes cached licence state, not applications. The apps stay installed and are relicensed when you sign back in, though anything licensed to an account you can no longer sign into will not come back.
Should I rename tokens.dat?
Not for these codes. The documented tokens.dat rebuild repairs the Windows activation store used by the Software Protection service. These codes come from the client licence service, and running the wrong repair loses your Windows activation without touching the problem.
