Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix 0xC004F302

0xC004F302: Silent Activation Fails on Entra Joined Windows 11 PCs

11 min read Updated October 5, 2026 Windows Activation & Licensing

Fix it now

Microsoft publishes no meaning for 0xC004F302, 0xC004F026 or 0xC004F04F, so start from what is documented instead: silent activation needs a joined device, an assigned seat, an eligible activated base edition and a clear path to the licensing endpoints. Check those four before you repair anything.

Run these on the failing device in an elevated Command Prompt, in order

dsregcmd /status
slmgr /dlv
netsh winhttp show proxy
slmgr /ato
  1. In the dsregcmd /status output, read the Device State block. Microsoft Entra joined is AzureAdJoined YES with DomainJoined NO; hybrid joined is both YES. A Microsoft Entra registered device is not supported for subscription activation.
  2. In the same output, read AzureAdPrt in the SSO State block. NO means the signed-in user has no primary refresh token and nothing will be presented to the licensing service.
  3. In slmgr /dlv, confirm the base edition is Pro or Pro Education and reads as Licensed. The step-up sits on a base licence; it does not replace one.
  4. Confirm the user holds an assigned seat in the Microsoft 365 admin centre under Users, Active users, Licenses and Apps.
  5. If your tenant uses Conditional Access, check the documented exclusion before touching the machine again – it is a known cause of exactly this failure and it is covered in the next section.

Do not install an Enterprise key on a device that is meant to activate through a subscription. It creates a second, competing licensing state and makes the eventual diagnosis harder.

If that fixed it you can stop here. If not, the next section covers what silent activation actually needs and why none of these three codes tells you which part failed.

Why it happens

Silent activation exists so that nobody types a key. The device presents the signed-in user’s token, the licensing service returns an entitlement, and Windows applies it in the background. For that to work, several things have to be true at once: the device is Microsoft Entra joined or Microsoft Entra hybrid joined, the user holds an assigned licence, the base edition is one with a documented step-up path and is already activated, and the licensing and identity endpoints are reachable without interference.

None of the three codes in this record tells you which of those failed, and it is worth being blunt about why. Microsoft publishes no meaning for 0xC004F302, 0xC004F026 or 0xC004F04F on learn.microsoft.com or support.microsoft.com. Earlier versions of this article assigned each of them a specific reading – a missing local licence, a licence the operation depended on, missing management information – and those readings were reverse-engineered from the story rather than taken from the vendor. Run slui.exe 0x2a 0xC004F302 on the machine and you will get Microsoft’s own text for your build, which is a better starting point than anyone’s summary.

So diagnose from the requirements rather than from the code. Microsoft documents that Microsoft Entra registered devices and workgroup devices are not supported for subscription activation, and that only Windows Pro to Windows Enterprise and Windows Pro Education to Windows Education are supported step-ups. It documents that devices attempt to renew about every 30 days and must be connected to the internet to acquire or renew. And it documents a Conditional Access interaction that produces exactly this class of failure on devices that have been offline for a while.

That Conditional Access detail is the one most often missed, and it is set out in the table below. In short: without the documented cloud-app exclusion, a device that has been offline for an extended period may not reactivate automatically.

The device is registered rather than joined

You have this one if dsregcmd /status shows a workplace-joined or registered device rather than AzureAdJoined YES.

  1. Read the Device State block and match it against the documented combinations: AzureAdJoined YES with DomainJoined NO is Entra joined; both YES is hybrid joined.
  2. A registered device carries the user’s identity but not the device relationship subscription activation depends on. It has to be properly joined.
  3. Once the join is right, sign out and back in and confirm AzureAdPrt reads YES.
  4. Then run slmgr /ato and read slmgr /dlv.

The base edition is not eligible, or is not activated

You have this one if slmgr /dlv shows Home, or shows Pro in a grace or notification state, and the step-up never lands.

  1. Confirm the edition with winver and the state with slmgr /dlv.
  2. Windows Home has no documented step-up path. The device needs an eligible base edition first.
  3. Activate the base edition by its usual route – firmware key, digital licence or the key you hold – and confirm it reads Licensed.
  4. Run slmgr /ato again and let the step-up apply on top.

A Conditional Access policy is blocking the licensing call

You have this one if Devices that have been off the network for a while fail to reactivate, while machines in daily use are fine.

  1. Exclude the documented cloud app from your Conditional Access policies using Select Excluded Cloud Apps: Universal Store Service APIs and Web Application, or Windows Store for Business, AppID 45a330b1-b1ec-4cc1-9161-9f03992aa49f.
  2. Check the client build first. On Windows 11 version 23H2 with KB5034848 or later the exclusion is no longer required, because the user is prompted to sign in instead.
  3. Where that prompt is the mechanism in play, tell the user to expect it: it appears as a toast and on the Activation page in Settings.

Licensing traffic is being inspected rather than merely allowed

You have this one if Whole sites or subnets fail together, and a device on a mobile connection activates immediately.

  1. Check the system-level proxy the service actually uses with netsh winhttp show proxy. It is not the browser’s setting.
  2. Ask for Microsoft licensing, activation and identity endpoints to be exempted from TLS inspection rather than simply permitted.
  3. Confirm the proxy does not require Basic authentication; Microsoft documents an activation failure caused by exactly that, because the activation interface cannot supply credentials.
  4. Retest on an unfiltered connection before requesting a network change, so the request comes with evidence.

The seat is not there, or the user is on a sixth device

You have this one if The machine is joined and healthy and the tenant is the thing that has changed.

  1. Check Licenses and Apps for the user in the admin centre. No seat means nothing will be returned.
  2. Count the devices that user signs into. The licence covers five; on a sixth, the least recently used device reverts to Pro or Pro Education.
  3. Assign a seat, or reduce the device count, then sign out and back in on the machine you care about.

Full reference

What silent activation requires, as documented

Requirement Detail
Device join Microsoft Entra joined or Microsoft Entra hybrid joined. Workgroup and Microsoft Entra registered devices are not supported
Base edition Windows Pro stepping up to Windows Enterprise, or Windows Pro Education stepping up to Windows Education
Licence A Windows Enterprise E3 or E5 subscription assigned to the signed-in user
Connectivity Devices attempt to renew about every 30 days and must be connected to the internet to acquire or renew
Device count Up to five devices per user licence. A sixth reverts the least recently used device
Conditional Access Exclude the Universal Store Service APIs and Web Application / Windows Store for Business cloud app, unless the client is Windows 11 23H2 with KB5034848 or later
Tenant type Available for commercial and GCC tenants. Not available on GCC High or DoD tenants

Reading dsregcmd without guessing

AzureAdJoined EnterpriseJoined DomainJoined Device state
YES NO NO Microsoft Entra joined
NO NO YES Domain joined
YES NO YES Microsoft Entra hybrid joined
NO YES YES On-premises DRS joined

AzureAdPrt in the SSO State block is the other line that matters. It reads YES when a primary refresh token is present for the signed-in user. AzureAdPrtExpiryTime tells you when it lapses if it is not renewed. A device with no PRT has nothing to present, and every minute spent on the licensing store is wasted until that is fixed.

Where to look for evidence

Source What it tells you
dsregcmd /status Join state, tenant, and whether a usable primary refresh token exists
slmgr /dlv Base edition, licence description, channel and current licence status
Application log, Security-SPP source Licensing service activity and the code behind each attempt
Admin centre, Licenses and Apps for the user Whether the entitlement exists at all, and whether an assignment error is recorded
netsh winhttp show proxy The proxy background services use, which is not the browser’s setting
slui.exe 0x2a <code> Microsoft’s own text for whichever code your build reported

Earlier guidance told readers to re-run a licence acquisition task in Task Scheduler under Microsoft, Windows, Subscription. No Microsoft page documents such a task path, so it is not in this article. Signing out and back in achieves the same thing through a route that is documented.

Repairing the local licensing store, if you get that far

  1. Reinstall the licence files: slmgr /rilc, which restores the known-good copies from %SystemRoot%\system32\oem and %SystemRoot%\System32\spp\tokens.
  2. Restart the licensing service: net stop sppsvc then net start sppsvc.
  3. Repair the component store with DISM /Online /Cleanup-Image /RestoreHealth, then run sfc /scannow.
  4. Reboot, sign in as the licensed user, and re-check slmgr /dlv.
  5. If licensing operations still fail, Microsoft’s documented tokens.dat rebuild is the next step, and it ends with installing the key using /ipk rather than removing anything with /upk.

How long to wait before calling it failed

Silent activation is a background operation and Microsoft publishes no guaranteed timing for it. What is published is the renewal cadence: about every 30 days, with an internet connection required. In practice, if a sign-out and sign-in cycle plus a reboot on a connected machine has not produced the step-up, treat it as failed rather than slow and work the requirements list above. Waiting longer on a device that is missing a prerequisite does not help.

Every code this article covers

Code What it points at Source
0xC004F302 Reported when a background subscription activation attempt does not complete. Microsoft publishes no meaning for this code; read the machine’s own text with slui.exe 0x2a 0xC004F302 not published by the vendor
0xC004F026 Seen alongside 0xC004F302 during licence operations. No published meaning not published by the vendor
0xC004F04F Seen alongside 0xC004F302 during licence operations. No published meaning not published by the vendor

Confirm the fix worked

  1. slmgr /dlv reports the expected edition with a licence status of Licensed.
  2. dsregcmd /status reports an Entra joined or hybrid joined device with AzureAdPrt YES for the signed-in user.
  3. Settings, System, Activation reports activation through the subscription rather than a product key.
  4. The user shows the expected product under Licenses and Apps in the admin centre, with no assignment error.
  5. Sign out, sign back in and reboot, then re-check that the state holds without anyone intervening.

Questions people ask about this

Does this mean I need to buy something?

Not on the evidence of the code, because Microsoft does not publish what the code means. Check the assignment first: if the user holds a seat and the device is joined with a valid token, this is a device or network problem and every step here is free.

Should I install a key to work around it?

No. A device meant to activate through a subscription should not have a key typed into it. That creates a second licensing state competing with the entitlement, and it makes the real fault harder to find later.

We use Conditional Access. Is that relevant?

Very. Microsoft documents that organisations using Conditional Access need to exclude the Universal Store Service APIs and Web Application cloud app, or Windows Store for Business depending on the tenant, both with AppID 45a330b1-b1ec-4cc1-9161-9f03992aa49f. Without it, a device that has been offline for a while may not reactivate. On Windows 11 23H2 with KB5034848 or later the exclusion is no longer needed.

Why did it work on the previous build of this machine?

Most often because a prerequisite changed rather than because the store decayed: a rebuild that came back Entra registered instead of joined, a base edition that is no longer activated, or a user whose seat moved. Work the requirements list before assuming corruption.

Is this available in every tenant?

No. Microsoft documents subscription activation as available for commercial and GCC tenants, and not available on GCC High or DoD tenants.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix 0xC004F047: VAMT Proxy Activation Fails on a Stale Policy Cache License Error 0xC004C017: Product Key Blocked in Your Country or Region License Error 0x803F8001 and 0x803F8003: No Usable Entitlement for the Signed-In Account License Error 0xC004F041 and 0xC004F039: Your KMS Host Is Not Activated or Enabled
โ† Back to Knowledge Base