Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix 0x8004de40

OneDrive 0x8004de40 and 0x8004de88: the sync app cannot reach the cloud

11 min read Updated October 4, 2026 Microsoft 365 & Entra ID

Fix it now

Microsoft documents 0x8004de40 and 0x8004de88 as OneDrive having trouble connecting to the cloud, with the message that login was either interrupted or unsuccessful. The published causes are no internet connectivity, TLS deprecation, an incorrect cipher suite configuration, and missing or disabled TLS protocols.

Run these in an elevated PowerShell session on the failing machine, then retest

Enable-TlsCipherSuite -Name "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384" -Position 0
Enable-TlsCipherSuite -Name "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256" -Position 1
Enable-TlsCipherSuite -Name "TLS_DHE_RSA_WITH_AES_256_GCM_SHA384" -Position 2
Enable-TlsCipherSuite -Name "TLS_DHE_RSA_WITH_AES_128_GCM_SHA256" -Position 3
  1. Check the machine has working internet access at all before anything else. It is the first cause Microsoft lists and it is skipped more often than it should be.
  2. Those four suites are the TLS 1.2 cipher suites Azure Front Door requires, and they must be prioritised at the top of the machine’s list. That ordering is the documented fix, not merely enabling them.
  3. Confirm the TLS protocols are enabled: press Windows and R, run inetcpl.cpl, open the Advanced tab and check the TLS boxes, then apply.
  4. If the machine is Entra joined and still failing, rejoin it: dsregcmd /leave then dsregcmd /join, and restart the device.
  5. As a last step, reset the sync app: %localappdata%\Microsoft\OneDrive\onedrive.exe /reset, falling back to C:\Program Files\Microsoft OneDrive\onedrive.exe /reset and then the Program Files (x86) path.

Two codes in this family are not connection problems at all. 0x8004ded7 means the sync app is out of date, and 0x8004dedc means the account is being used in a different region. Both are covered below and neither is fixed by anything above.

If the client signs in and syncs, stop here. If you have one of the other codes in this family, the next section says which fix belongs to which, because they do not share one.

Why it happens

The sync app makes its own HTTPS connections, separate from your browser, using the Windows secure channel stack and the system proxy configuration. That is why this error confuses people: a browser can be perfectly happy while the client fails, because the two do not share TLS settings, proxy resolution or certificate trust behaviour. Microsoft’s own article on 0x8004de40 lists TLS deprecation and cipher suite configuration ahead of anything to do with the client itself.

The cipher suite detail is the part that gets missed. Four TLS 1.2 suites are required and must be at the top of the machine’s priority list: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 and TLS_DHE_RSA_WITH_AES_128_GCM_SHA256. A machine covered by a hardening baseline that trimmed or reordered the list will fail here while a machine next to it works, and nothing in the error hints at ordering.

The rest of this family are separate problems that happen to arrive as similar-looking hex. Two are documented as a proxy pair: 0x8004de44 and 0x8004de42 mean your proxy settings require authentication, and Microsoft states that authenticated proxies are not supported by the OneDrive sync app. That is a hard limitation, not a preference. One is a client version problem, and one is a geography problem. Reading which code you actually have is worth more than any amount of Schannel work.

The cipher suite list has been trimmed or reordered

You have this one if TLS is enabled, the browser works, and the machine is covered by a security baseline or a third-party hardening tool.

  1. List what the machine will offer with Get-TlsCipherSuite | Select-Object Name.
  2. Confirm the four required suites are present and at the top; enable and position them with Enable-TlsCipherSuite as above.
  3. Put the change back into policy properly rather than leaving a local override that the next refresh undoes.

The proxy requires authentication

You have this one if 0x8004de44 or 0x8004de42, with a message that your proxy settings require authentication.

  1. Allow the Microsoft 365 endpoints through without proxy authentication. Authenticated proxies are not supported by the sync app and no client-side setting changes that.
  2. Check what background processes actually see with netsh winhttp show proxy, which is a machine-level setting and not the browser’s.
  3. Microsoft’s documented fallback for 0x8004de44 is to reset the Windows Settings app and reinstall OneDrive, once the proxy itself is no longer authenticating.

Error 0x80048823 is documented with the same proxy-authentication meaning, so treat it as part of this pair if you see it.

The sync app is out of date

You have this one if 0x8004ded7 on OneDrive for work or school.

  1. Update Windows, then download and install the current OneDrive release.
  2. Confirm the version has actually changed before retesting; a failed update looks exactly like no update.
  3. This is the one code in this family where reinstalling the client is the documented answer.

The account is being used in a different region

You have this one if 0x8004dedc, typically for a user who has moved country or whose account was created in the wrong geography.

  1. Escalate to a tenant administrator; this is not fixable on the device.
  2. The administrator sets the user’s preferred data location to the correct geography and waits at least 24 hours for it to propagate.
  3. They then move the OneDrive with Start-SPOUserAndContentMove -UserPrincipalName <upn> -DestinationDataLocation <geo>.
  4. A valid Multi-Geo subscription covering users in satellite geographies is a prerequisite, and the maximum OneDrive size that can be moved is 5 TB.

No amount of TLS or proxy work on the client will change this one. It is a tenant configuration.

TLS inspection is breaking the handshake

You have this one if The certificate presented for Microsoft 365 hosts is issued by your own security appliance rather than a public authority.

  1. Bypass Microsoft 365 domains from TLS decryption, traffic interception, deep packet inspection and content filtering, which is Microsoft’s own recommendation.
  2. Apply the bypass to the full published set of required endpoints; Microsoft states plainly that selective allow-listing is not supported and causes service incidents.
  3. If the appliance must stay in the path, make sure its issuing CA is trusted by the machine account and not only by the signed-in user.

Full reference

Which code is which

Code Documented meaning Where the fix lives
0x8004de40 OneDrive is having trouble connecting to the cloud The machine: TLS protocols and cipher suite order
0x8004de88 Documented with 0x8004de40, same meaning and resolution The machine, as above
0x8004de44 Your proxy settings require authentication The network: allow the endpoints without proxy authentication
0x8004de42 Your proxy settings require authentication The network, as above
0x8004ded7 You are using an old version of OneDrive The client: update it
0x8004dedc You are trying to use OneDrive in a different region The tenant: preferred data location and a geo move

Read the pattern before you change anything

What you see Most likely layer
Browser works, client fails, corporate network only Proxy or TLS inspection applied to background processes
Fails on every network including a phone tether Local TLS configuration or a hardening policy on the machine
Only machines in one group fail A baseline or policy trimmed that group’s cipher suites
Fails instantly The request is refused or dropped outright
Fails after several seconds A timeout: the request is being swallowed rather than refused
One user fails everywhere, on any machine Not this family – check 0x8004dedc and the account’s region

Down-level Windows

On Windows 7 and 8 and on Windows Server 2008 R2 and 2012, TLS 1.1 and 1.2 are not enabled by default and Microsoft’s article points at the Easy Fix tool to enable them, with KB 3140245 for Windows 8. It also notes that disabling the DHE cipher suites can help where those platforms still fail after the protocols are enabled. On current Windows 10 and 11 builds the protocols are on by default, so if you find them disabled, something disabled them and will do so again at the next policy refresh.

What the network team needs to hear

  • Microsoft recommends bypassing Microsoft 365 domains from TLS decryption, interception, deep packet inspection and content filtering.
  • Selective allow-listing is explicitly unsupported: apply the guidance to the full published set of required endpoints, not to the handful you found in a capture.
  • Traffic intermediation devices such as proxies and VPN services should be bypassed for that traffic, with browsers configured to send Microsoft 365 requests directly to egress.
  • Authenticated proxies are not supported by the OneDrive sync app at all, so ‘we will just add credentials’ is not an option.
  • That traffic is already encrypted and authenticated end to end, which is the argument to make rather than asking the security team to trust you.

When the client genuinely is the problem

The instinct to reinstall OneDrive is usually wrong for 0x8004de40, because the client is stopped at the network layer and a fresh copy will be stopped in the same place. It is right for 0x8004ded7, where the documented cause is an old version. It is worth one attempt for 0x8004de44 after the proxy has stopped authenticating, because Microsoft’s own resolution for that code is to reset the Windows Settings app and reinstall the app. Knowing which of those you have is the difference between a five-minute fix and an afternoon in the registry.

Every code this article covers

Code What it points at Source
0x8004de40 OneDrive is having trouble connecting to the cloud; documented causes are no internet connectivity, TLS deprecation, incorrect cipher suite configuration, and missing or disabled TLS protocols Microsoft Learn
0x8004de88 Documented on the same page as 0x8004de40, with the same meaning and the same resolution Microsoft Learn
0x8004de44 Your proxy settings require authentication. Authenticated proxies are not supported by the OneDrive sync app; the documented fallback is to reset the Windows Settings app and reinstall OneDrive Microsoft Support
0x8004de42 Your proxy settings require authentication – the same documented pair as 0x8004de44, and the same unsupported condition Microsoft Support
0x8004ded7 You are using an old version of OneDrive for work or school; download and install the latest version Microsoft Support
0x8004dedc You are trying to use OneDrive for work or school in a different region; an administrator relocates the account with Start-SPOUserAndContentMove after setting the preferred data location Microsoft Support

Confirm the fix worked

  1. Get-TlsCipherSuite lists the four required suites, and they are at the top of the order.
  2. The OneDrive icon returns to a normal synced state and a file uploads and downloads end to end.
  3. The certificate served for a Microsoft 365 host is issued by a public authority, proving inspection is bypassed.
  4. The machine keeps syncing after a reboot without anyone signing in again.
  5. If the code was 0x8004ded7, the installed OneDrive version number has actually changed.

Questions people ask about this

Do I need to buy anything to fix this?

Not for 0x8004de40 or 0x8004de88 – those are TLS, cipher suite and proxy configuration. The one exception in this family is 0x8004dedc, which is a region problem and needs a Multi-Geo subscription covering users in satellite geographies before the account can be moved.

Will reinstalling OneDrive help?

It depends which code you have, and this is where the old advice went wrong. For 0x8004de40 the client is stopped at the network layer and a reinstall changes nothing. For 0x8004ded7 an out-of-date client is the documented cause, so updating or reinstalling is exactly right.

Why does the browser work when the sync app does not?

They do not share plumbing. The browser has its own TLS implementation and proxy handling; the sync app uses the Windows stack and the system proxy. A machine can load the OneDrive web app perfectly while the client cannot open a connection.

Can we just put credentials on the proxy for OneDrive?

No. Microsoft states that authenticated proxies are not supported by the sync app. The endpoints have to be allowed through without proxy authentication.

Is bypassing TLS inspection for Microsoft 365 safe?

It is Microsoft’s own recommendation: bypass Microsoft 365 domains from TLS decryption, interception, deep packet inspection and content filtering, across the full published endpoint set rather than a selection of it.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix LargeObject and ExceededAllowedLength: Entra ID rejects an oversized object License Error Intune 0x8018002b and 0x80180014: MDM scope, UPN suffix and platform settings block enrolment License Error SharePoint Online is out of storage space: tenant and site quota errors Free Fix Error 80090016 in Teams and Outlook: the TPM keyset does not exist
โ† Back to Knowledge Base