Fix it now
Office is refusing licence data that did not come from Microsoft’s licensing service. Microsoft publishes no description for 0xC004F027, so read the vendor’s own text on the machine with /ddescr before acting. The repair is to remove every installed key, clear any pinned KMS host, and activate with a key you can account for.
cd "C:\Program Files\Microsoft Office\root\Office16"
cscript ospp.vbs /ddescr:0xC004F027
cscript ospp.vbs /dstatus
cscript ospp.vbs /unpkey:XXXXX
cscript ospp.vbs /remhst
cscript ospp.vbs /inpkey:XXXXX-XXXXX-XXXXX-XXXXX-XXXXX
cscript ospp.vbs /act
- Note the last five characters of every key
/dstatusreports, and run/unpkey:once for each. There is often more than one. /remhstremoves the KMS host name and resets the port to 1688. If an activator pinned a loopback address as a host, that is what clears it.- Before you install a genuine key, deal with whatever wrote the data. Removing licence state on a machine that still runs an activator at logon buys you a few days.
- Take a restore point or a snapshot first if this is a machine you cannot rebuild.
Reinstalling Office on its own does not clear this. The licensing store sits outside the Office program files and survives an ordinary uninstall.
If /dstatus reports a licensed status that survives a reboot, you are done. If it reverts, something is putting the state back and the next section covers it.
Why it happens
Volume editions of Office do not keep their entitlement in the program files. They keep it in a protected licensing store made of signed licence files and a token store, both maintained by the Software Protection Platform. The service re-reads that store and checks what it finds, and this code is what comes back when the check does not pass.
Microsoft publishes no description for 0xC004F027, and none for 0xC004F023, 0xC004F01D, 0xC004F006, 0xC004F02A or 0xC004D319 either. That is worth knowing before you accept a confident one-line meaning from anywhere. What you can do is ask the machine: cscript ospp.vbs /ddescr:0xC004F027 prints the text Office itself holds for the code, and that is the only description with the vendor behind it.
In the field, the overwhelming majority of these are installations where a third-party activator, KMS emulator or loader has written into the licensing store. That is an observation about where the code turns up rather than a published cause, and it matters because it changes what the repair has to include. If you clear the store and leave the thing that wrote it, the state comes back.
It also explains why the error survives the fixes people try first. Reinstalling Office replaces the program files and leaves the licensing store where it is. An Office repair does the same. Until the state is cleared and a legitimate key installed, every attempt hits the same refusal.
An activator or KMS emulator is still on the machine
You have this one if /dstatus reports a KMS host name of 127.0.0.1 or localhost, or Task Scheduler holds a task nobody recognises that runs a script at logon.
- Open Task Scheduler and look through the library for tasks that trigger at logon or startup and run a script from a temp or user folder. Disable anything you cannot account for.
- Open
services.mscand check for services with generic names and no publisher information. - Run a full scan with your antivirus product and let it quarantine what it finds rather than skipping it.
- Clear the pinned host:
cscript ospp.vbs /remhst, then remove the keys and install a legitimate one.
Many activators install a persistence task deliberately, because their activation lapses. Clear the store without removing the task and the same state returns within days.
Licence state remains after the keys were removed
You have this one if You have already run /unpkey: for every key and installed a genuine one, and the refusal is unchanged.
- Reset the licensing status:
cscript ospp.vbs /rearm, which Microsoft documents as resetting the licensing status for all installed Office product keys. - Reboot, then install the key and run
/act. - If it still fails, remove Office completely with Microsoft’s Support and Recovery Assistant, which clears remnants an ordinary uninstall leaves behind.
- Reinstall from a Microsoft source, install your key, and activate before signing in with any account.
The key itself came from a grey-market source
You have this one if The key cost far less than the licence it claims to be, arrived by email with no paperwork, and either fails or activates and then reverts.
- Check the channel in
/dstatus. A key sold to you as retail that reports a volume channel was not the seller’s to sell. - Remove it:
cscript ospp.vbs /unpkey:<last five>. - Obtain a key issued against a real agreement or a genuine perpetual licence, and keep the paperwork.
Keys harvested from volume agreements are routinely blocked once the source is identified, and a blocked key returns 0xC004C003 rather than this code.
Antivirus quarantined files the licensing store referenced
You have this one if Activation worked until a scan ran, and the quarantine log lists items under the Office or Windows licensing folders.
- Read the quarantine log and note what was removed. Do not restore anything the scanner identified as an activator.
- Repair the component store:
DISM /Online /Cleanup-Image /RestoreHealth. - Then repair system files from it:
sfc /scannow. - Reinstall the key and activate.
Full reference
Telling the variants apart
| What you see | Where the fault actually is |
|---|---|
/dstatus shows a KMS host name of 127.0.0.1 or localhost |
Something is emulating a KMS host on the machine itself |
| An unfamiliar scheduled task re-runs at every logon | The persistence mechanism. Clearing the store alone will not hold |
| The error appeared right after an antivirus clean-up | The scanner removed the activator and left the licence state behind |
| Keys removed and reinstalled, refusal unchanged | Licence state remains. Rearm, then rebuild if needed |
| A genuine key that reports a channel you did not buy | A key sourced from somewhere it should not have been |
The switches this repair uses
| Switch | What Microsoft says it does |
|---|---|
/dstatus |
Displays licence information for installed product keys |
/unpkey:<last five> |
Uninstalls an installed key, identified by its last five digits as shown by /dstatus |
/remhst |
Removes the KMS host name and resets the port to the default 1688 |
/rearm |
Resets the licensing status for all installed Office product keys |
/inpkey:<key> |
Installs a product key, replacing an existing key |
/ddescr:<code> |
Displays the description for a supplied error code |
Take a restore point or a virtual machine snapshot before rebuilding licensing state, and be prepared to reactivate Windows as well as Office. Both sit on the same Software Protection Platform, and a machine that ran an activator has usually had both touched.
Treating the machine, not just the licence
An activator is not a licensing shortcut with a licensing-shaped risk. It runs with high privilege, it disables or patches parts of the licensing stack, and it commonly arrives bundled with other payloads. A machine that has run one needs a full antivirus scan and, in a business, a decision about whether it can be trusted at all rather than just relicensed. Your documents are not touched by any of this; the question is what else was.
If this is a managed estate
- Find out how widely it has spread. One machine is an incident; twenty is a process problem, usually a shared image or a build document that nobody owns.
- Check whether a volume agreement already covers these devices. If it does, the fix costs nothing but the clean-up and an activation against your own host.
- Rebuild the reference image from Microsoft media, deploy with the product ID that matches your licence, and run
OSPPREARM.EXEbefore Sysprep so the deployed machines get unique Office client machine IDs. - Remove local administrator rights where an activator was run by a user. That is what actually stops the next one.
The six codes and what is knowable about them
0xC004F027, 0xC004F023, 0xC004F01D, 0xC004F006, 0xC004F02A and 0xC004D319 have no published descriptions. The 0xC004D prefix on the last one belongs to a different part of the platform from the 0xC004F codes, which is a hint about where it comes from and not a meaning. Run /ddescr: against each one you actually see, write down what the machine says, and work from that rather than from a table someone assembled without a source.
When a licence is the actual fix
No registry edit or repair turns tampered licence data into a valid entitlement. The store refuses the licence because the licence is not real, and every workaround you find online is another way of making the same tamper stick a little longer. What ends this permanently is a key issued against a genuine licence. Arco supplies Office LTSC 2024 Professional Plus as a perpetual, per-device licence, and can tell you before you buy whether Professional Plus or Standard covers the applications you actually use.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0xC004F027 |
Returned when the licensing service refuses the licence data it finds. No published description; read the machine’s own text with ospp.vbs /ddescr: | not published by the vendor |
0xC004F023 |
Same licensing layer, no published description | not published by the vendor |
0xC004F01D |
Same layer, no published description | not published by the vendor |
0xC004F006 |
Same layer, no published description | not published by the vendor |
0xC004F02A |
Same layer, no published description | not published by the vendor |
0xC004D319 |
Carries the 0xC004D prefix used by a different part of the platform. No published description | not published by the vendor |
Confirm the fix worked
cscript ospp.vbs /dstatusreports a licensed status with the channel you expect.- The KMS host name line is empty or names your own host, not a loopback address.
- An Office application opens with no Unlicensed Product wording in the title bar.
- Reboot, wait, and re-run
/dstatusto confirm the state holds rather than reverting. - A full antivirus scan completes with nothing outstanding in quarantine that you have chosen to ignore.
Questions people ask about this
What does 0xC004F027 mean exactly?
Microsoft does not publish a description for it. Run cscript ospp.vbs /ddescr:0xC004F027 on the machine and read what Office itself says. That is the only wording with the vendor behind it.
Will reinstalling Office clear this?
On its own, usually not. The licensing store sits outside the Office program files and survives an ordinary uninstall. Remove the keys, clear the pinned host, rearm, and if that fails use Microsoft’s Support and Recovery Assistant to strip the installation completely.
Is my data at risk?
Your documents are not touched. The risk from an activator is different: it runs with high privilege, alters parts of the licensing stack, and is frequently bundled with other payloads. Treat a machine that ran one as needing a full scan, not just a licence fix.
Can I keep using Office while I sort this out?
For a while. Microsoft publishes that an unlicensed installation shows Unlicensed Product in the title bar and that most features are disabled. Nothing is deleted.
Do I have to buy a licence, or is there a free route?
If your organisation already holds a volume agreement, the fix costs nothing: clear the state and activate against your own KMS host, MAK or directory object. If there is no agreement behind the installation, there is no free route.
