Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix 0xC004F30D

0xC004F30D to 0xC004F310: Certificate Thumbprint Rejected at Activation

11 min read Updated October 4, 2026 Windows Activation & Licensing

Fix it now

None of these four codes has a published meaning, so do not try to decode them. Establish two facts instead: which issuance licences are installed on this machine, and which certificates the licensing service considers usable. Those two lists tell you where the problem is.

Run these on the affected machine in an elevated Command Prompt, in order

slmgr /lil
slmgr /ltc
slui.exe 0x2a 0xC004F30D
  1. slmgr /lil lists the installed token-based activation issuance licences. Nothing listed means no policy is present, and that is a different problem from a rejected certificate.
  2. slmgr /ltc lists the valid token-based activation certificates that can activate installed software. Nothing listed means no certificate available to this machine satisfies any installed issuance licence.
  3. Read what slui.exe 0x2a prints for the code you actually have. That is Microsoft’s own wording for your build and the only authoritative description available.
  4. If a thumbprint is listed, use exactly that one: slmgr /fta <thumbprint> <PIN>.
  5. If the certificate was recently reissued, its thumbprint changed. Either issue a card from the original template and authority, or have a fresh issuance licence produced for the new credential and install it with slmgr /ilc <path>.

Issuance licences are validated at run time by the Software Protection service rather than at install time, so slmgr /ilc completing successfully does not mean the policy inside the file matches your certificate.

If that fixed it you can stop here. If not, the next section covers what the two lists are telling you and what to ask the team that produced your issuance licence.

Why it happens

An issuance licence is a signed licence file installed on the machine ahead of time, usually with an .xrm-ms extension. It is the local statement of entitlement for token-based activation, and it is what the licensing service tests a presented certificate against. Because it is signed, it cannot be edited to accept something new: a changed policy means a newly issued file from whoever holds the signing authority in your organisation.

This article used to describe the four codes as a graduation of refusals – thumbprint, trust point, certificate property, and no acceptable credential at all. That description is not published anywhere on learn.microsoft.com or support.microsoft.com, and neither is any meaning for 0xC004F30D, 0xC004F30E, 0xC004F30F or 0xC004F310. It has been removed rather than restated. What is documented is the tooling, and the tooling is enough to work with.

The two commands that matter are slmgr /lil, which lists installed issuance licences, and slmgr /ltc, which lists valid token-based activation certificates that can activate installed software. Read them as a pair. Nothing from /lil means there is no policy on the machine. Something from /lil and nothing from /ltc means no credential available here satisfies that policy. Something from both, and activation still failing, means the credential and the policy disagree in a way you will need the policy’s author to explain.

Renewal is the situation that produces most of these reports, and it is worth understanding even without a published code meaning. A thumbprint is a hash of the whole certificate, so any change at all produces a different value. Renewing a certificate, reissuing it from a different template, or issuing it from a subordinate authority that was rebuilt all change the thumbprint even though the subject name looks identical in the properties dialogue. Nothing about the certificate appears to have changed, and the machine treats it as an entirely different credential.

The issuance licence is missing, or the wrong one is installed

You have this one if slmgr /lil returns nothing, or lists a licence for a different product or edition from the one installed.

  1. Obtain the correct issuance licence file for the installed edition from whoever administers your token activation policy.
  2. Install it: slmgr /ilc <full path to the .xrm-ms file>.
  3. Confirm it registered with slmgr /lil.
  4. Restart the licensing service so the policy is loaded: net stop sppsvc then net start sppsvc, then retry slmgr /fta.

Microsoft documents Event ID 12321 with HR=0xC004F011 for exactly this state: the token issuance licence is not installed.

The certificate was renewed and no longer matches

You have this one if Activation worked before the card was reissued or the certificate renewed, and the subject name looks unchanged.

  1. Run slmgr /ltc and record the thumbprint the machine now sees.
  2. Compare it with the value the issuance licence was built around. Your PKI team holds that.
  3. Either reissue the card from the original template and authority so the policy matches again, or have a fresh issuance licence produced against the new credential.
  4. Install the replacement with slmgr /ilc <path>, then run slmgr /fta <thumbprint> <PIN>.

Renewal is the most common trigger in this whole range, precisely because nothing visible about the certificate appears to have changed.

The certificate authority was rebuilt or migrated

You have this one if The certificate is valid and its chain builds cleanly, and activation is still refused.

  1. Export the certificate and inspect the chain, including which root it terminates at.
  2. Compare that root with the one your policy was designed around.
  3. If the authority has been rebuilt or migrated, the issuance licence has to be reissued to match.
  4. Import the correct root and intermediate certificates into the machine stores so the chain the service builds is the one you expect.

The wrong certificate is being selected from a multi-certificate card

You have this one if The card holds several certificates – signing, encryption, authentication – and only one is intended for activation.

  1. Enumerate what is on the card and cross-reference it with slmgr /ltc, which shows only the ones the licensing service will consider.
  2. Pass the thumbprint explicitly rather than letting anything choose: slmgr /fta <thumbprint> <PIN>.
  3. Do that even when only one certificate is present, so a wrong selection fails unambiguously rather than silently.

The certificate is outside its validity window

You have this one if Everything looks right and validation still fails, on a machine whose clock is wrong or a certificate issued for a future date.

  1. Check the machine’s time with w32tm /query /status and correct it with w32tm /resync.
  2. Check the certificate’s not-before and not-after dates against the corrected time.
  3. A certificate that is not yet valid fails the same tests as one that has expired.
  4. Retry once the two agree.

Full reference

What is published about these four codes

Code Status
0xC004F30D No published meaning found on learn.microsoft.com or support.microsoft.com
0xC004F30E No published meaning found
0xC004F30F No published meaning found
0xC004F310 No published meaning found

That is not a satisfying table, and it is the accurate one. Older versions of this article assigned each value a specific refusal – thumbprint, trust point, property, and no acceptable credential. Those assignments were not sourced. The related code Microsoft does publish in this area is 0xC004F011, SL_E_LICENSE_FILE_NOT_INSTALLED, which appears in Event ID 12321 when the issuance licence is absent.

Reading the two lists together

slmgr /lil slmgr /ltc What it means
Nothing Nothing No issuance licence installed. Install one with slmgr /ilc
A licence Nothing No credential available here satisfies that policy. You need a different card, not a different command
A licence A thumbprint A usable pairing exists. Activate with slmgr /fta <thumbprint> <PIN>
A licence for another product Anything The wrong issuance licence for this edition. Get the right file

The commands and what they are documented to do

Command Documented behaviour
slmgr /lil Lists installed token-based activation issuance licences
slmgr /ltc Lists valid token-based activation certificates that can activate installed software
slmgr /fta <thumbprint> [<PIN>] Forces token-based activation using the identified certificate. The optional PIN unlocks the private key without a prompt
slmgr /ilc <license_file> Installs the specified licence file. Validated at run time by the Software Protection service, not at install time
slmgr /ril <ILID> <ILvID> Removes an installed issuance licence. Requires both the issuance licence ID and its version ID

Do not remove issuance licences with slmgr /ril while experimenting. Removing the wrong one can take a working machine out of an activated state, and reinstating it needs the original file, which is usually held centrally rather than on the machine. Confirm you have that file before removing anything, and note that the switch needs both an issuance licence ID and a version ID, so a half-remembered command will not do what you expect.

Questions to put to the policy’s author

  • Which thumbprint, or which set of thumbprints, was this issuance licence built to accept?
  • Which root does the policy expect the credential to chain to, and has that authority been rebuilt or migrated?
  • Which certificate template should the cards be issued from, and has it changed?
  • Is there a newer issuance licence covering the credentials we are now issuing?
  • Which edition is this issuance licence for? A file for another product will install cleanly and never activate anything.

Those five questions resolve this class of problem far more reliably than any amount of work on the endpoint, because the policy lives in a signed file that the endpoint cannot alter. If the answer to any of them has changed since the licence was produced, a new licence file is the fix.

Why reinstalling Windows does not help

A rebuild removes the installed issuance licence along with everything else, and the mismatch is reproduced exactly on the fresh installation as soon as you reinstall the same file and present the same card. The variable is the pairing of policy and credential, and neither of those lives in the operating system.

Every code this article covers

Code What it points at Source
0xC004F30D Reported when token-based activation refuses the certificate presented. No published meaning; read the machine’s own text with slui.exe 0x2a not published by the vendor
0xC004F30E Reported in the same token activation family. No published meaning not published by the vendor
0xC004F30F Reported in the same token activation family. No published meaning not published by the vendor
0xC004F310 Reported in the same token activation family. No published meaning not published by the vendor

Confirm the fix worked

  1. slmgr /lil lists the issuance licence you intended to install.
  2. slmgr /ltc lists the thumbprint you activated with.
  3. slmgr /dlv reports a licence status of Licensed.
  4. The Application log shows no further licensing warnings after your attempt.
  5. Repeat the activation on a second machine with the same card, to confirm the policy rather than the endpoint was the variable.

Questions people ask about this

Can I edit the issuance licence to accept a new thumbprint?

No. It is a signed licence file, and any modification invalidates the signature. A changed policy means a newly issued file from whoever holds the signing authority in your organisation.

Where do I find the value the licence expects?

From the team that produced it. slmgr /ltc shows what the machine can offer, but the authoritative value belongs to the policy rather than the endpoint.

Why does this article not say what each code means?

Because no acceptable source publishes a meaning for any of the four, and the neat four-step gradation earlier versions offered was invented. Run slui.exe 0x2a followed by your code to get Microsoft’s own wording for your build.

Is a new licence purchase ever the answer?

Not for this. These are certificate and policy problems inside an entitlement you already hold in the issuance licence, and a refused attempt consumes nothing.

slmgr /ilc succeeded. Why is activation still failing?

Because licence files are validated at run time by the Software Protection service rather than when they are installed. A successful install means the file was accepted, not that the policy inside it matches the certificate you are presenting.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix 0xC004D401: Security Processor Reports a System File Mismatch License Error 0xC004F027 and 0xC004FE00: Windows Detected Licence Tampering License Error 0xC004C003: The Activation Server Has Blocked This Product Key License Error 0xC004E021 and 0xC004E022: Genuine Data in Your Licence Is Inconsistent
โ† Back to Knowledge Base