Fix it now
Microsoft’s published cause for 0x8004DE40 and 0x8004DE88 is that the client is having trouble connecting to the cloud. The documented fixes are about TLS – which protocol versions and cipher suites the machine will negotiate – and then about device registration, not about the account.
Enable-TlsCipherSuite -Name "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384" -Position 0
dsregcmd /leave
dsregcmd /join
- Confirm the device is actually on the internet, which is the first check Microsoft lists.
- Confirm the machine supports and prioritises the TLS 1.2 cipher suites the service expects. The four Microsoft names are TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 and TLS_DHE_RSA_WITH_AES_128_GCM_SHA256.
- Check the TLS protocol checkboxes: run
inetcpl.cpl, open the Advanced tab, and confirm the TLS options are enabled. - If the device is joined to Entra ID, leave and rejoin with the two dsregcmd commands above, then restart the computer.
- If none of that helps, reset the OneDrive client and let it re-synchronise.
The message users see for 0x8004DE40 is “Login was either interrupted or unsuccessful. Please try logging in again.” For 0x8004DE88 it is “We can’t sign into your account, please try again later.” Both point at the same cause.
If the client signs in and stays signed in after a reboot, you are done. The next section explains what has to line up for a token exchange to complete.
Why it happens
A modern sign-in is a token exchange, not a password check. The client sends the user to the identity service, receives tokens back, caches them, and refreshes them silently from then on. Several separate things have to work: name resolution and a clear path to the identity endpoints, a TLS connection both ends can agree on, a clock inside the accepted window, a writable place to keep the token cache, and an account that is enabled and licensed.
Microsoft’s published cause for 0x8004DE40 and 0x8004DE88 is the second of those. The article says the codes indicate the client is having trouble connecting to the cloud, and its resolutions are almost entirely about TLS: whether the machine supports the cipher suites the service front door expects, and whether the TLS protocol versions are enabled at all. That is why hardened machines and old builds fail here while everything else on them looks fine.
The failure is easy to misread because it presents as a sign-in problem, so people look at the account. A machine that cannot negotiate a current TLS version fails here rather than anywhere obviously TLS-shaped, and a long time gets spent checking licences before anyone checks a protocol setting.
The other four codes in this family have no published meaning. Microsoft has dedicated articles for 0x8004de40, 0x8004de88, 0x8004de80, 0x8004de86 and 0x8004deef, and none for 0x8004DEF0, 0x8004DEB4, 0x8004DEED or 0x8004DEF7. Treat any of them as sign-in did not complete, and work the same list in the same order.
The machine cannot negotiate the cipher suites the service expects
You have this one if An older or hardened machine, often one a security script has been run against, and browsers on it behave oddly on some sites too.
- Enable and prioritise the four TLS 1.2 cipher suites Microsoft names, using
Enable-TlsCipherSuitewith-Position 0to put each at the top. - Where a hardening policy disabled them, correct the policy rather than the machine, or it will come back at the next refresh.
- Reboot and retest before changing anything else, so you know which change worked.
Enable what the service needs rather than forcing one configuration and disabling everything else. Over-tightening here reliably breaks something else on the same machine within a day.
TLS protocol versions are turned off
You have this one if The same machine fails in several unrelated applications that all use the system TLS stack.
- Run
inetcpl.cpl, open the Advanced tab and confirm the TLS options are enabled. - Apply outstanding Windows updates and reboot; older builds need updates before they can use current protocol versions at all.
- Retest the client before making further changes.
The device registration is not usable
You have this one if The machine is joined to Entra ID, other sign-in symptoms are present, and browser sign-in works while the client does not.
- Confirm BitLocker recovery is escrowed for the machine.
- Run
dsregcmd /leave, thendsregcmd /join, then restart the computer. Microsoft lists exactly this sequence for these codes. - Confirm the device state afterwards with
dsregcmd /status.
A proxy or filtering appliance is in front of the identity endpoints
You have this one if netsh winhttp show proxy names a proxy and the same machine signs in on a phone hotspot.
- Have the identity and Office endpoints allowed through without authentication and without decryption.
- Check any PAC file logic for those host names; it is often out of step with the firewall rules.
- Confirm the machine is not falling back to a proxy configured for a different network it visited earlier.
- Retest on the network where it has to work, not on a hotspot.
The account is not in a state that can sign in
You have this one if Browser sign-in also fails, or succeeds and then reports that no licence is assigned.
- Check in the admin centre that the account is enabled and licensed.
- Check whether the password has expired or been reset recently.
- Check whether a conditional access policy or a sign-in restriction applies to this client or location.
- Fix the account state first; nothing on the client will help while the account itself is refusing.
Full reference
Splitting client problems from account problems
| Test | What it tells you |
|---|---|
| Browser signs in, the client does not | Client-side: TLS, proxy or device state |
| Neither browser nor client signs in | Account state, licensing, or a conditional access policy |
| Works on a hotspot, fails in the office | Proxy, filtering or TLS inspection |
| Fails for one Windows user only | That profile’s cached credentials |
| The whole office fails at once | A network policy change, or a service incident |
The cipher suites Microsoft names
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
These have to be supported and prioritised on the client. Enable-TlsCipherSuite -Name "<suite>" -Position 0 puts one at the top of the list; run it for each suite you need to promote, and check the result before rebooting. On older platforms Microsoft’s guidance also covers adding the TLS 1.1 and 1.2 registry keys and, where connectivity errors persist, disabling DHE cipher suites.
Which codes are documented
| Code | Documented | What Microsoft says |
|---|---|---|
0x8004DE40 |
Yes | OneDrive is having trouble connecting to the cloud |
0x8004DE88 |
Yes | Same article, same cause |
0x8004DEF0 |
No | No published meaning |
0x8004DEB4 |
No | No published meaning |
0x8004DEED |
No | No published meaning |
0x8004DEF7 |
No | No published meaning |
Resetting the client
A reset stops the OneDrive client, clears its local configuration and starts it again, after which it re-synchronises. Files in the cloud are untouched and files already on disk are not deleted; the client re-checks them, which takes a while on a large synced folder. Do it after the TLS and device checks rather than before, because a reset that appears to work can mask a protocol problem that returns a week later.
When everything on this list is clean
- Check the clock. Token validation is time-sensitive and a large offset produces sign-in failures with no obvious clock symptom.
- Check the service health page in the admin centre before spending longer on one machine.
- Compare against a second machine on the same network with the same account. Two machines behaving differently is a machine problem; two behaving identically is a network or account problem.
- Check whether an endpoint security product is intercepting HTTPS on this machine, because inspection produces exactly this class of failure and hides the real certificate.
- For a machine that has been off the network for a long time, apply updates before anything else. Protocol support and root certificates both age.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x8004DE40 |
OneDrive is having trouble connecting to the cloud; the message shown is that login was either interrupted or unsuccessful | Microsoft Learn |
0x8004DE88 |
Same published cause: the client cannot connect, with the message that it cannot sign into your account | Microsoft Learn |
0x8004DEF0 |
Seen during client sign-in; no published meaning | not published by the vendor |
0x8004DEB4 |
Seen during client sign-in; no published meaning | not published by the vendor |
0x8004DEED |
Seen during client sign-in; no published meaning | not published by the vendor |
0x8004DEF7 |
Seen during client sign-in; no published meaning | not published by the vendor |
Confirm the fix worked
- The application signs in without prompting after a restart.
- OneDrive shows the correct account and a completed sync in its activity centre.
- File, Account in Word shows the expected account and product.
- A second reboot leaves sign-in silent rather than prompting again.
- The cipher suite change is still in place after a policy refresh, not reverted by a hardening baseline.
Questions people ask about this
Do I need to buy anything to fix this?
No. Microsoft’s documented causes and fixes for these codes are connectivity and TLS configuration on the client. If the browser signs in and then reports no licence assigned, that is a genuine licensing gap and a different problem with a different error.
Does resetting OneDrive delete my files?
No. The reset stops the client, clears its local configuration and starts it again, after which it re-synchronises. Files in the cloud are untouched. On a large synced folder the re-check takes a while, so give it time.
Why is my colleague on the same network fine?
Because most causes here are per-machine: protocol settings, a hardening baseline, a local security agent, device registration. When the whole office fails at once you are looking at a network change or a service incident instead.
Is this a password problem?
Not according to Microsoft. The published cause is that the client cannot connect to the cloud, and the documented resolutions are TLS settings and device re-registration. Check the account, by all means, but do not start there.
What do the other 0x8004DExx codes mean?
Microsoft publishes dedicated articles for a few values in this range and nothing for the rest, including the four in this article’s list. Treat an undocumented one as sign-in did not complete and work the same checks in the same order.
