Fix it now
Microsoft publishes 0x80070426 as Win32 error 1062, ERROR_SERVICE_NOT_ACTIVE, “the service has not been started”. The service that performs Office licensing work is Software Protection, sppsvc, and while it cannot start the activation call has nowhere to go. Your key and your entitlement are not involved.
sc query sppsvc
sc qc sppsvc
sc config sppsvc start= delayed-auto
net start sppsvc
- Read
START_TYPEfromsc qc sppsvcbefore changing anything.DISABLEDis the fault; anything else means the service is failing rather than switched off. - The space after
start=is required. Microsoft documents that, and without it sc.exe fails. - Retry activation from the Office folder:
cd "C:\Program Files\Microsoft Office\root\Office16"thencscript ospp.vbs /act. - If the machine also carries an Office Software Protection Platform service from an older Office release, check it the same way:
sc query osppsvc.
Finding the service stopped is normal. It starts on demand and shuts down when idle, so the start type is what matters, not the state.
If activation completes you are done. If the service will not start or will not stay started, the next section separates the two cases.
Why it happens
This is a service error reaching you through an activation dialogue. Microsoft publishes 0x80070426 as Win32 error 1062, ERROR_SERVICE_NOT_ACTIVE: “The service has not been started.” There is nothing licensing-specific in that sentence, which is why the same code turns up in unrelated places whenever a component asks for a service that is not running.
Office does not talk to Microsoft or to your KMS host directly. It asks the Software Protection Platform service to do it. On current Office that is sppsvc, the same service Windows activation uses, which is why an Office activation failure and a Windows activation failure on the same machine often have one cause. Some machines that have carried older Office releases also have a separate Office Software Protection Platform service; where it exists it is worth checking, and where it does not, its absence is not a fault.
The nuance that saves time is the same one that applies to every on-demand service. A stopped service on a healthy machine means nothing at all, because it is designed to start when something needs it and shut down again afterwards. What produces this code is a service set to disabled, or one that starts and immediately fails.
That distinction tells you where to look. A start type of disabled means something set it deliberately: a hardening baseline, a Group Policy preference, or one of the many tuning scripts that switch off services they do not recognise. A correct start type with a service that will not start means a broken dependency, a damaged binary or something blocking it.
A tuning or hardening script disabled the service
You have this one if sc qc sppsvc reports DISABLED, and somebody recently ran an optimiser, a privacy tool or a security baseline on the machine.
- Re-enable it:
sc config sppsvc start= delayed-auto. - Start it:
net start sppsvc. - Find the script or baseline that disabled it and remove that entry, or the change returns at the next run.
- If Group Policy is responsible, correct it under Computer Configuration, Policies, Windows Settings, Security Settings, System Services rather than on the client.
Many published tuning scripts disable licensing services on the assumption that the machine will never need to reactivate. It will.
The service will not start
You have this one if The start type is correct and net start sppsvc returns an error rather than completing.
- Read the failure in Event Viewer, under Windows Logs, System, filtered on the Service Control Manager source.
- Confirm the Remote Procedure Call service is running:
sc query RpcSs. - Repair the component store, then the system files:
DISM /Online /Cleanup-Image /RestoreHealth, thensfc /scannow. - Reboot and try again before drawing any conclusion about Office.
Endpoint protection is blocking the licensing binary
You have this one if The service starts and stops within seconds, and your security product logs a block or a quarantine at the same timestamp.
- Read the security product’s log and identify what it acted on.
- Update the product’s definitions, which frequently resolves a false positive on its own.
- Add the vendor’s recommended exclusion if it supports one, then restart the service and retry activation.
Check this properly rather than assuming a false positive. Activators patch these binaries, so a detection here can be entirely genuine.
A required COM class is not registered
You have this one if You see 0x80040154 as well as, or instead of, 0x80070426. Microsoft publishes that code as REGDB_E_CLASSNOTREG, “class not registered”.
- Run
sfc /scannow, followed byDISM /Online /Cleanup-Image /RestoreHealthif it reports files it could not fix. - Reboot, because component registration is often completed during startup.
- If Office itself is implicated, run an Online Repair from Settings, Apps, Installed apps, the Office entry, then Modify.
- Retry activation.
The service is fine and the error came from elsewhere
You have this one if The service is running, the start type is correct, and activation still fails with the same code.
- Restart the licensing service explicitly:
net stop sppsvcthennet start sppsvc. - Check the Application log for Security-SPP entries around the time of the failure.
- If the machine also fails to activate Windows, treat this as a platform fault rather than an Office one and repair the image.
- Read the vendor’s text for whatever code you have:
slui.exe 0x2a <code>on Windows, orcscript ospp.vbs /ddescr:<code>in Office.
Full reference
Reading the service state
| What sc reports | What it means |
|---|---|
| Start type DISABLED | Something set it deliberately. Re-enable it and find out what |
| Start type correct, state STOPPED, starts on demand | Normal. Look elsewhere for the activation fault |
| Start attempt fails immediately | Missing or damaged files, or a blocked binary |
| Service starts then stops within seconds | A failing dependency, or a security product terminating it |
| The service is missing entirely | System file damage. Repair the image before anything else |
The commands, and what is documented about them
| Command | Notes |
|---|---|
sc query sppsvc |
Current state |
sc qc sppsvc |
Configured start type |
sc config sppsvc start= delayed-auto |
Accepted start= values are boot, system, auto, demand, disabled and delayed-auto. The space after the equals sign is required |
net stop sppsvc / net start sppsvc |
Stops and starts the service. This is the documented pair used in Microsoft’s own licensing repair procedures |
cscript ospp.vbs /act |
Activates installed Office product keys |
slui.exe 0x2a <code> |
Prints the text Windows holds for an activation error code |
cscript ospp.vbs /osppsvcrestart appears in a lot of guidance and is not in Microsoft’s documented ospp.vbs option list, which covers /act, /inpkey, /unpkey, /inslic, /dstatus, /dstatusall, /dhistoryacterr, /dinstid, /actcid, /rearm and /ddescr, plus the KMS client switches. Restart the service with net stop and net start instead, which is what Microsoft’s own procedures use.
The registry value behind the start type
The configuration lives at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sppsvc, and the Start value holds the start type: 2 automatic, 3 manual, 4 disabled. Reading it is a fair check. Writing it is the wrong tool, because sc config does the same job with validation and no chance of a typo landing somewhere else in the key.
Export the key before changing anything under Services. On a server this is not a mistake you want to discover after a reboot.
Codes and events in this article that Microsoft does not publish
| Entry | What can honestly be said |
|---|---|
0xC004F075 |
Returned by the licensing service alongside the service errors. No published description |
| Event ID 1003 | No published description. Written by the licensing platform to the Application log |
| Event ID 16384 | No published description. Appears routinely on healthy machines |
Do not build a diagnosis on the absence of an undocumented event. If you need an event to base a decision on, Microsoft documents a handful from this source and those are the ones to look for. For a code, slui.exe 0x2a or ospp.vbs /ddescr: gives you the vendor’s own wording in a couple of seconds, which is a better basis than a table nobody can source.
Why it worked last month
Activation is not continuous. Office and Windows re-check on a schedule, so a service disabled today can go unnoticed for weeks until the next check falls due. That is also why the machine that reports this is often not the machine somebody changed, and why the useful question is what ran across the estate rather than what happened on this desk.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80070426 |
Win32 error 1062, ERROR_SERVICE_NOT_ACTIVE: the service has not been started | Microsoft Learn |
0x80040154 |
REGDB_E_CLASSNOTREG: class not registered | Microsoft Learn |
0xC004F075 |
Returned by the licensing service alongside the service errors. No published description | not published by the vendor |
Event ID 1003 |
Written by the licensing platform to the Application log. No published description | not published by the vendor |
Event ID 16384 |
Written by the same source, routinely and on healthy machines. No published description | not published by the vendor |
Confirm the fix worked
sc qc sppsvcreports a start type other than DISABLED.net start sppsvccompletes, or reports the service is already running.cscript ospp.vbs /actcompletes without an error.cscript ospp.vbs /dstatusreports a licensed status.- Reboot and confirm the start type has not reverted and Office is still licensed.
Questions people ask about this
Should the service be running all the time?
No. It starts on demand and shuts down when idle, so finding it stopped proves nothing. The start type is what matters: disabled is wrong, automatic with a delayed start is the normal configuration.
Is ospp.vbs /osppsvcrestart a real switch?
It is not in Microsoft’s documented ospp.vbs option list. Restart the service with net stop sppsvc and net start sppsvc, which is the pair Microsoft’s own licensing repair procedures use.
Is it safe to leave the service enabled?
Yes. It is a standard Windows component that performs licensing operations. Disabling it does not improve privacy or performance in any measurable way, and it breaks activation, which is what you are here to fix.
Does this cost anything to fix?
No. There is no licensing element to this error. Your key is untouched and your entitlement is intact. It is a service configuration problem.
What does 0xC004F075 mean?
Microsoft does not publish a description for it. Read what your own machine says with slui.exe 0x2a 0xC004F075, or cscript ospp.vbs /ddescr:0xC004F075 in Office, and treat that as the authority.
