Fix it now
Microsoft documents 0x8004de40 and 0x8004de88 as OneDrive having trouble connecting to the cloud, with the message that login was either interrupted or unsuccessful. The published causes are no internet connectivity, TLS deprecation, an incorrect cipher suite configuration, and missing or disabled TLS protocols.
Enable-TlsCipherSuite -Name "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384" -Position 0
Enable-TlsCipherSuite -Name "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256" -Position 1
Enable-TlsCipherSuite -Name "TLS_DHE_RSA_WITH_AES_256_GCM_SHA384" -Position 2
Enable-TlsCipherSuite -Name "TLS_DHE_RSA_WITH_AES_128_GCM_SHA256" -Position 3
- Check the machine has working internet access at all before anything else. It is the first cause Microsoft lists and it is skipped more often than it should be.
- Those four suites are the TLS 1.2 cipher suites Azure Front Door requires, and they must be prioritised at the top of the machine’s list. That ordering is the documented fix, not merely enabling them.
- Confirm the TLS protocols are enabled: press Windows and R, run
inetcpl.cpl, open the Advanced tab and check the TLS boxes, then apply. - If the machine is Entra joined and still failing, rejoin it:
dsregcmd /leavethendsregcmd /join, and restart the device. - As a last step, reset the sync app:
%localappdata%\Microsoft\OneDrive\onedrive.exe /reset, falling back toC:\Program Files\Microsoft OneDrive\onedrive.exe /resetand then the Program Files (x86) path.
Two codes in this family are not connection problems at all. 0x8004ded7 means the sync app is out of date, and 0x8004dedc means the account is being used in a different region. Both are covered below and neither is fixed by anything above.
If the client signs in and syncs, stop here. If you have one of the other codes in this family, the next section says which fix belongs to which, because they do not share one.
Why it happens
The sync app makes its own HTTPS connections, separate from your browser, using the Windows secure channel stack and the system proxy configuration. That is why this error confuses people: a browser can be perfectly happy while the client fails, because the two do not share TLS settings, proxy resolution or certificate trust behaviour. Microsoft’s own article on 0x8004de40 lists TLS deprecation and cipher suite configuration ahead of anything to do with the client itself.
The cipher suite detail is the part that gets missed. Four TLS 1.2 suites are required and must be at the top of the machine’s priority list: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 and TLS_DHE_RSA_WITH_AES_128_GCM_SHA256. A machine covered by a hardening baseline that trimmed or reordered the list will fail here while a machine next to it works, and nothing in the error hints at ordering.
The rest of this family are separate problems that happen to arrive as similar-looking hex. Two are documented as a proxy pair: 0x8004de44 and 0x8004de42 mean your proxy settings require authentication, and Microsoft states that authenticated proxies are not supported by the OneDrive sync app. That is a hard limitation, not a preference. One is a client version problem, and one is a geography problem. Reading which code you actually have is worth more than any amount of Schannel work.
The cipher suite list has been trimmed or reordered
You have this one if TLS is enabled, the browser works, and the machine is covered by a security baseline or a third-party hardening tool.
- List what the machine will offer with
Get-TlsCipherSuite | Select-Object Name. - Confirm the four required suites are present and at the top; enable and position them with
Enable-TlsCipherSuiteas above. - Put the change back into policy properly rather than leaving a local override that the next refresh undoes.
The proxy requires authentication
You have this one if 0x8004de44 or 0x8004de42, with a message that your proxy settings require authentication.
- Allow the Microsoft 365 endpoints through without proxy authentication. Authenticated proxies are not supported by the sync app and no client-side setting changes that.
- Check what background processes actually see with
netsh winhttp show proxy, which is a machine-level setting and not the browser’s. - Microsoft’s documented fallback for 0x8004de44 is to reset the Windows Settings app and reinstall OneDrive, once the proxy itself is no longer authenticating.
Error 0x80048823 is documented with the same proxy-authentication meaning, so treat it as part of this pair if you see it.
The sync app is out of date
You have this one if 0x8004ded7 on OneDrive for work or school.
- Update Windows, then download and install the current OneDrive release.
- Confirm the version has actually changed before retesting; a failed update looks exactly like no update.
- This is the one code in this family where reinstalling the client is the documented answer.
The account is being used in a different region
You have this one if 0x8004dedc, typically for a user who has moved country or whose account was created in the wrong geography.
- Escalate to a tenant administrator; this is not fixable on the device.
- The administrator sets the user’s preferred data location to the correct geography and waits at least 24 hours for it to propagate.
- They then move the OneDrive with
Start-SPOUserAndContentMove -UserPrincipalName <upn> -DestinationDataLocation <geo>. - A valid Multi-Geo subscription covering users in satellite geographies is a prerequisite, and the maximum OneDrive size that can be moved is 5 TB.
No amount of TLS or proxy work on the client will change this one. It is a tenant configuration.
TLS inspection is breaking the handshake
You have this one if The certificate presented for Microsoft 365 hosts is issued by your own security appliance rather than a public authority.
- Bypass Microsoft 365 domains from TLS decryption, traffic interception, deep packet inspection and content filtering, which is Microsoft’s own recommendation.
- Apply the bypass to the full published set of required endpoints; Microsoft states plainly that selective allow-listing is not supported and causes service incidents.
- If the appliance must stay in the path, make sure its issuing CA is trusted by the machine account and not only by the signed-in user.
Full reference
Which code is which
| Code | Documented meaning | Where the fix lives |
|---|---|---|
| 0x8004de40 | OneDrive is having trouble connecting to the cloud | The machine: TLS protocols and cipher suite order |
| 0x8004de88 | Documented with 0x8004de40, same meaning and resolution | The machine, as above |
| 0x8004de44 | Your proxy settings require authentication | The network: allow the endpoints without proxy authentication |
| 0x8004de42 | Your proxy settings require authentication | The network, as above |
| 0x8004ded7 | You are using an old version of OneDrive | The client: update it |
| 0x8004dedc | You are trying to use OneDrive in a different region | The tenant: preferred data location and a geo move |
Read the pattern before you change anything
| What you see | Most likely layer |
|---|---|
| Browser works, client fails, corporate network only | Proxy or TLS inspection applied to background processes |
| Fails on every network including a phone tether | Local TLS configuration or a hardening policy on the machine |
| Only machines in one group fail | A baseline or policy trimmed that group’s cipher suites |
| Fails instantly | The request is refused or dropped outright |
| Fails after several seconds | A timeout: the request is being swallowed rather than refused |
| One user fails everywhere, on any machine | Not this family – check 0x8004dedc and the account’s region |
Down-level Windows
On Windows 7 and 8 and on Windows Server 2008 R2 and 2012, TLS 1.1 and 1.2 are not enabled by default and Microsoft’s article points at the Easy Fix tool to enable them, with KB 3140245 for Windows 8. It also notes that disabling the DHE cipher suites can help where those platforms still fail after the protocols are enabled. On current Windows 10 and 11 builds the protocols are on by default, so if you find them disabled, something disabled them and will do so again at the next policy refresh.
What the network team needs to hear
- Microsoft recommends bypassing Microsoft 365 domains from TLS decryption, interception, deep packet inspection and content filtering.
- Selective allow-listing is explicitly unsupported: apply the guidance to the full published set of required endpoints, not to the handful you found in a capture.
- Traffic intermediation devices such as proxies and VPN services should be bypassed for that traffic, with browsers configured to send Microsoft 365 requests directly to egress.
- Authenticated proxies are not supported by the OneDrive sync app at all, so ‘we will just add credentials’ is not an option.
- That traffic is already encrypted and authenticated end to end, which is the argument to make rather than asking the security team to trust you.
When the client genuinely is the problem
The instinct to reinstall OneDrive is usually wrong for 0x8004de40, because the client is stopped at the network layer and a fresh copy will be stopped in the same place. It is right for 0x8004ded7, where the documented cause is an old version. It is worth one attempt for 0x8004de44 after the proxy has stopped authenticating, because Microsoft’s own resolution for that code is to reset the Windows Settings app and reinstall the app. Knowing which of those you have is the difference between a five-minute fix and an afternoon in the registry.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x8004de40 |
OneDrive is having trouble connecting to the cloud; documented causes are no internet connectivity, TLS deprecation, incorrect cipher suite configuration, and missing or disabled TLS protocols | Microsoft Learn |
0x8004de88 |
Documented on the same page as 0x8004de40, with the same meaning and the same resolution | Microsoft Learn |
0x8004de44 |
Your proxy settings require authentication. Authenticated proxies are not supported by the OneDrive sync app; the documented fallback is to reset the Windows Settings app and reinstall OneDrive | Microsoft Support |
0x8004de42 |
Your proxy settings require authentication – the same documented pair as 0x8004de44, and the same unsupported condition | Microsoft Support |
0x8004ded7 |
You are using an old version of OneDrive for work or school; download and install the latest version | Microsoft Support |
0x8004dedc |
You are trying to use OneDrive for work or school in a different region; an administrator relocates the account with Start-SPOUserAndContentMove after setting the preferred data location | Microsoft Support |
Confirm the fix worked
Get-TlsCipherSuitelists the four required suites, and they are at the top of the order.- The OneDrive icon returns to a normal synced state and a file uploads and downloads end to end.
- The certificate served for a Microsoft 365 host is issued by a public authority, proving inspection is bypassed.
- The machine keeps syncing after a reboot without anyone signing in again.
- If the code was 0x8004ded7, the installed OneDrive version number has actually changed.
Questions people ask about this
Do I need to buy anything to fix this?
Not for 0x8004de40 or 0x8004de88 – those are TLS, cipher suite and proxy configuration. The one exception in this family is 0x8004dedc, which is a region problem and needs a Multi-Geo subscription covering users in satellite geographies before the account can be moved.
Will reinstalling OneDrive help?
It depends which code you have, and this is where the old advice went wrong. For 0x8004de40 the client is stopped at the network layer and a reinstall changes nothing. For 0x8004ded7 an out-of-date client is the documented cause, so updating or reinstalling is exactly right.
Why does the browser work when the sync app does not?
They do not share plumbing. The browser has its own TLS implementation and proxy handling; the sync app uses the Windows stack and the system proxy. A machine can load the OneDrive web app perfectly while the client cannot open a connection.
Can we just put credentials on the proxy for OneDrive?
No. Microsoft states that authenticated proxies are not supported by the sync app. The endpoints have to be allowed through without proxy authentication.
Is bypassing TLS inspection for Microsoft 365 safe?
It is Microsoft’s own recommendation: bypass Microsoft 365 domains from TLS decryption, interception, deep packet inspection and content filtering, across the full published endpoint set rather than a selection of it.
