Fix it now
None of these four codes has a published meaning, so do not try to decode them. Establish two facts instead: which issuance licences are installed on this machine, and which certificates the licensing service considers usable. Those two lists tell you where the problem is.
slmgr /lil
slmgr /ltc
slui.exe 0x2a 0xC004F30D
slmgr /lillists the installed token-based activation issuance licences. Nothing listed means no policy is present, and that is a different problem from a rejected certificate.slmgr /ltclists the valid token-based activation certificates that can activate installed software. Nothing listed means no certificate available to this machine satisfies any installed issuance licence.- Read what
slui.exe 0x2aprints for the code you actually have. That is Microsoft’s own wording for your build and the only authoritative description available. - If a thumbprint is listed, use exactly that one:
slmgr /fta <thumbprint> <PIN>. - If the certificate was recently reissued, its thumbprint changed. Either issue a card from the original template and authority, or have a fresh issuance licence produced for the new credential and install it with
slmgr /ilc <path>.
Issuance licences are validated at run time by the Software Protection service rather than at install time, so slmgr /ilc completing successfully does not mean the policy inside the file matches your certificate.
If that fixed it you can stop here. If not, the next section covers what the two lists are telling you and what to ask the team that produced your issuance licence.
Why it happens
An issuance licence is a signed licence file installed on the machine ahead of time, usually with an .xrm-ms extension. It is the local statement of entitlement for token-based activation, and it is what the licensing service tests a presented certificate against. Because it is signed, it cannot be edited to accept something new: a changed policy means a newly issued file from whoever holds the signing authority in your organisation.
This article used to describe the four codes as a graduation of refusals – thumbprint, trust point, certificate property, and no acceptable credential at all. That description is not published anywhere on learn.microsoft.com or support.microsoft.com, and neither is any meaning for 0xC004F30D, 0xC004F30E, 0xC004F30F or 0xC004F310. It has been removed rather than restated. What is documented is the tooling, and the tooling is enough to work with.
The two commands that matter are slmgr /lil, which lists installed issuance licences, and slmgr /ltc, which lists valid token-based activation certificates that can activate installed software. Read them as a pair. Nothing from /lil means there is no policy on the machine. Something from /lil and nothing from /ltc means no credential available here satisfies that policy. Something from both, and activation still failing, means the credential and the policy disagree in a way you will need the policy’s author to explain.
Renewal is the situation that produces most of these reports, and it is worth understanding even without a published code meaning. A thumbprint is a hash of the whole certificate, so any change at all produces a different value. Renewing a certificate, reissuing it from a different template, or issuing it from a subordinate authority that was rebuilt all change the thumbprint even though the subject name looks identical in the properties dialogue. Nothing about the certificate appears to have changed, and the machine treats it as an entirely different credential.
The issuance licence is missing, or the wrong one is installed
You have this one if slmgr /lil returns nothing, or lists a licence for a different product or edition from the one installed.
- Obtain the correct issuance licence file for the installed edition from whoever administers your token activation policy.
- Install it:
slmgr /ilc <full path to the .xrm-ms file>. - Confirm it registered with
slmgr /lil. - Restart the licensing service so the policy is loaded:
net stop sppsvcthennet start sppsvc, then retryslmgr /fta.
Microsoft documents Event ID 12321 with HR=0xC004F011 for exactly this state: the token issuance licence is not installed.
The certificate was renewed and no longer matches
You have this one if Activation worked before the card was reissued or the certificate renewed, and the subject name looks unchanged.
- Run
slmgr /ltcand record the thumbprint the machine now sees. - Compare it with the value the issuance licence was built around. Your PKI team holds that.
- Either reissue the card from the original template and authority so the policy matches again, or have a fresh issuance licence produced against the new credential.
- Install the replacement with
slmgr /ilc <path>, then runslmgr /fta <thumbprint> <PIN>.
Renewal is the most common trigger in this whole range, precisely because nothing visible about the certificate appears to have changed.
The certificate authority was rebuilt or migrated
You have this one if The certificate is valid and its chain builds cleanly, and activation is still refused.
- Export the certificate and inspect the chain, including which root it terminates at.
- Compare that root with the one your policy was designed around.
- If the authority has been rebuilt or migrated, the issuance licence has to be reissued to match.
- Import the correct root and intermediate certificates into the machine stores so the chain the service builds is the one you expect.
The wrong certificate is being selected from a multi-certificate card
You have this one if The card holds several certificates – signing, encryption, authentication – and only one is intended for activation.
- Enumerate what is on the card and cross-reference it with
slmgr /ltc, which shows only the ones the licensing service will consider. - Pass the thumbprint explicitly rather than letting anything choose:
slmgr /fta <thumbprint> <PIN>. - Do that even when only one certificate is present, so a wrong selection fails unambiguously rather than silently.
The certificate is outside its validity window
You have this one if Everything looks right and validation still fails, on a machine whose clock is wrong or a certificate issued for a future date.
- Check the machine’s time with
w32tm /query /statusand correct it withw32tm /resync. - Check the certificate’s not-before and not-after dates against the corrected time.
- A certificate that is not yet valid fails the same tests as one that has expired.
- Retry once the two agree.
Full reference
What is published about these four codes
| Code | Status |
|---|---|
0xC004F30D |
No published meaning found on learn.microsoft.com or support.microsoft.com |
0xC004F30E |
No published meaning found |
0xC004F30F |
No published meaning found |
0xC004F310 |
No published meaning found |
That is not a satisfying table, and it is the accurate one. Older versions of this article assigned each value a specific refusal – thumbprint, trust point, property, and no acceptable credential. Those assignments were not sourced. The related code Microsoft does publish in this area is 0xC004F011, SL_E_LICENSE_FILE_NOT_INSTALLED, which appears in Event ID 12321 when the issuance licence is absent.
Reading the two lists together
slmgr /lil |
slmgr /ltc |
What it means |
|---|---|---|
| Nothing | Nothing | No issuance licence installed. Install one with slmgr /ilc |
| A licence | Nothing | No credential available here satisfies that policy. You need a different card, not a different command |
| A licence | A thumbprint | A usable pairing exists. Activate with slmgr /fta <thumbprint> <PIN> |
| A licence for another product | Anything | The wrong issuance licence for this edition. Get the right file |
The commands and what they are documented to do
| Command | Documented behaviour |
|---|---|
slmgr /lil |
Lists installed token-based activation issuance licences |
slmgr /ltc |
Lists valid token-based activation certificates that can activate installed software |
slmgr /fta <thumbprint> [<PIN>] |
Forces token-based activation using the identified certificate. The optional PIN unlocks the private key without a prompt |
slmgr /ilc <license_file> |
Installs the specified licence file. Validated at run time by the Software Protection service, not at install time |
slmgr /ril <ILID> <ILvID> |
Removes an installed issuance licence. Requires both the issuance licence ID and its version ID |
Do not remove issuance licences with slmgr /ril while experimenting. Removing the wrong one can take a working machine out of an activated state, and reinstating it needs the original file, which is usually held centrally rather than on the machine. Confirm you have that file before removing anything, and note that the switch needs both an issuance licence ID and a version ID, so a half-remembered command will not do what you expect.
Questions to put to the policy’s author
- Which thumbprint, or which set of thumbprints, was this issuance licence built to accept?
- Which root does the policy expect the credential to chain to, and has that authority been rebuilt or migrated?
- Which certificate template should the cards be issued from, and has it changed?
- Is there a newer issuance licence covering the credentials we are now issuing?
- Which edition is this issuance licence for? A file for another product will install cleanly and never activate anything.
Those five questions resolve this class of problem far more reliably than any amount of work on the endpoint, because the policy lives in a signed file that the endpoint cannot alter. If the answer to any of them has changed since the licence was produced, a new licence file is the fix.
Why reinstalling Windows does not help
A rebuild removes the installed issuance licence along with everything else, and the mismatch is reproduced exactly on the fresh installation as soon as you reinstall the same file and present the same card. The variable is the pairing of policy and credential, and neither of those lives in the operating system.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0xC004F30D |
Reported when token-based activation refuses the certificate presented. No published meaning; read the machine’s own text with slui.exe 0x2a | not published by the vendor |
0xC004F30E |
Reported in the same token activation family. No published meaning | not published by the vendor |
0xC004F30F |
Reported in the same token activation family. No published meaning | not published by the vendor |
0xC004F310 |
Reported in the same token activation family. No published meaning | not published by the vendor |
Confirm the fix worked
slmgr /lillists the issuance licence you intended to install.slmgr /ltclists the thumbprint you activated with.slmgr /dlvreports a licence status of Licensed.- The Application log shows no further licensing warnings after your attempt.
- Repeat the activation on a second machine with the same card, to confirm the policy rather than the endpoint was the variable.
Questions people ask about this
Can I edit the issuance licence to accept a new thumbprint?
No. It is a signed licence file, and any modification invalidates the signature. A changed policy means a newly issued file from whoever holds the signing authority in your organisation.
Where do I find the value the licence expects?
From the team that produced it. slmgr /ltc shows what the machine can offer, but the authoritative value belongs to the policy rather than the endpoint.
Why does this article not say what each code means?
Because no acceptable source publishes a meaning for any of the four, and the neat four-step gradation earlier versions offered was invented. Run slui.exe 0x2a followed by your code to get Microsoft’s own wording for your build.
Is a new licence purchase ever the answer?
Not for this. These are certificate and policy problems inside an entitlement you already hold in the issuance licence, and a refused attempt consumes nothing.
slmgr /ilc succeeded. Why is activation still failing?
Because licence files are validated at run time by the Software Protection service rather than when they are installed. A successful install means the file was accepted, not that the policy inside it matches the certificate you are presenting.
