Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Redmond desk6 min

How to Fix the “A Referral Was Returned From the Server” Windows Error

The Windows message “A referral was returned from the server” can indicate UAC signature enforcement or an Active Directory referral. Identify the branch and fix it safely.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The message “A referral was returned from the server” has two unrelated meanings. When one executable fails during Run as administrator, Windows is commonly enforcing User Account Control: Only elevate executable files that are signed and validated. When the message appears in Active Directory or LDAP tools, it may instead be a genuine directory referral (error 8235/0x202B). Identify the branch first, then use the narrowest fix.

First, identify which error you have

What you see Most likely cause
One old .exe fails when launched with Run as administrator UAC code-signing policy or an invalid/untrusted signature
An installer or driver downloaded from the internet fails Signature validation, SmartScreen, or a damaged download
Several unrelated programs fail after a security-policy change Local or domain UAC policy
A Citrix published application fails to launch Application-specific UAC/signature compatibility
The message appears in Get-ADUser, LDAP, or domain-management software Active Directory referral
The text includes 8235, 0x202B, LDAP, domain, forest, or naming context Active Directory referral

Microsoft documents the elevation policy and its registry mapping in its UAC settings reference. A directory referral is a different subsystem and needs domain, DNS, or replication troubleshooting.

Check the executable’s digital signature first

  1. Right-click the executable and choose Properties.
  2. Open Digital Signatures, if that tab exists.
  3. Select the signature, choose Details, and confirm that Windows reports it as valid.
  4. Review the signer, timestamp, and certificate path.

No Digital Signatures tab usually means the file is unsigned. That does not by itself prove malware, but an unsigned file can be blocked when signature validation is required. Prefer a current build downloaded from the publisher, avoid cracked or repacked copies, compare the publisher’s checksum when supplied, and ask the vendor for a signed release if a legitimate program is unsigned or has a broken certificate.

Optional PowerShell check

Get-AuthenticodeSignature -FilePath "C:PathProgram.exe" |
  Format-List Status,StatusMessage,SignerCertificate,Path

Valid means validation succeeded in the current environment; NotSigned, HashMismatch, or UnknownError require further investigation of the file and certificate chain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fix the specific UAC policy

Use this only when the application is trusted, genuinely needs elevation, and no supported signed replacement is available. The policy is documented as disabled by default, although an organization can enable it through Group Policy or MDM.

Local Security Policy (Pro, Enterprise, Education and managed editions)

  1. Press Win + R, enter secpol.msc, and press Enter.
  2. Open Local Policies > Security Options.
  3. Open User Account Control: Only elevate executable files that are signed and validated.
  4. Set it to Disabled, then select Apply and OK.
  5. Sign out and back in, or restart Windows, and test the program.
  6. Set the policy back to Enabled when testing or installation is complete.

Microsoft lists the policy path and edition applicability in its Local Policies Security Options documentation. Windows Home generally does not include this snap-in.

Registry method (including Windows Home)

Create a restore point or export the relevant key before editing the registry.

  1. Press Win + R, type regedit, and press Enter.
  2. Go to HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem.
  3. Find the DWORD ValidateAdminCodeSignatures and set it to 0.
  4. Sign out or restart, then test the application.
  5. Restore the value to 1 when signature enforcement is required again.

From an elevated Command Prompt, the same change can be made with:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
reg query "HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem" /v ValidateAdminCodeSignatures
reg add "HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem" /v ValidateAdminCodeSignatures /t REG_DWORD /d 0 /f
reg add "HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem" /v ValidateAdminCodeSignatures /t REG_DWORD /d 1 /f

Run these commands only in an elevated terminal and not on a managed computer without approval. They change the registry-backed policy described by Microsoft’s UAC documentation.

Do not disable UAC as the default workaround

ValidateAdminCodeSignatures controls signature validation for elevated executables. EnableLUA controls the broader “Run all administrators in Admin Approval Mode” behavior. Setting EnableLUA to 0 or moving the UAC slider to Never notify weakens protections far beyond this one policy. Do not begin there, and do not leave UAC disabled permanently. A Citrix article documents EnableLUA=0 for a particular XenApp VDA launch problem; that environment-specific workaround should not be generalized. On Citrix MCS, any approved change may need to be made in the master image and propagated through the catalog.

If the signature is valid but the error remains

  • The certificate chain may lack a trusted root or intermediate, or revocation/timestamp validation may fail.
  • The file may have been modified after signing.
  • Your organization may not trust the publisher; administrators can manage the Trusted Publishers store.
  • Defender, App Control for Business, AppLocker, Smart App Control, or endpoint security may be blocking it.
  • A signed launcher may start an unsigned helper executable.
  • You may be elevating an old copy in Downloads instead of the installed copy.
  • A domain, MDM, or security-baseline policy may be reapplying the setting.
  • UIAccess applications have a separate secure-location policy; do not confuse it with ValidateAdminCodeSignatures.

Compatibility mode can help with obsolete APIs or behavior, but it does not repair a missing or invalid signature. Built-in tools such as Narrator or Magnifier require additional checks of system-file integrity, servicing, catalogs, and policy rather than copying executables from another PC.

Check domain management before changing a work PC

Group Policy or MDM can override local settings. Generate a report with:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
gpresult /h "%USERPROFILE%Desktopgpresult.html"
gpresult /r

Open the HTML report and search for Only elevate executable files that are signed and validated. An elevated PowerShell check is:

Rank #4
Mastering Microsoft Endpoint Manager: Deploy and manage Windows 10, Windows 11, and Windows 365 on both physical and cloud PCs
  • Mastering Microsoft Endpoint Manager: Deploy and manage Windows 10, Windows 11, and Windows 365 on both physical and cloud PCs
  • ABIS BOOK
  • Packt Publishing
Get-ItemProperty `
  -Path "HKLM:SOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem" `
  -Name ValidateAdminCodeSignatures,EnableLUA

For long-term remediation, replace the obsolete program, obtain an enterprise-supported signed build, or have administrators approve and govern the vendor certificate instead of weakening an entire fleet.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When the message is an Active Directory referral

If the error occurs in AD or LDAP administration, changing UAC will not help. Capture the complete command and check for error 8235 or 0x202B. Then:

  1. Identify the domain, forest, naming context, and server being queried.
  2. Verify DNS resolution and domain-controller discovery.
  3. Confirm that the account and tool target the correct domain or naming context.
  4. Check replication and whether the referenced object or partition is moving or unavailable.
  5. Use the appropriate domain controller or global catalog.
  6. Review Directory Service and DNS event logs, and involve the domain administrator.

A directory referral means the server is directing the request elsewhere; it is not evidence that an executable is unsigned. A separate explanation of this 8235/0x202B context is available from Server Scheduler.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Practical order of operations

  1. Record the exact message, failing file, and context.
  2. Separate application-launch cases from AD/LDAP cases.
  3. Verify the file’s source and signature.
  4. Install a current signed vendor build if available.
  5. Check whether ValidateAdminCodeSignatures is enabled.
  6. Temporarily disable only that policy for a trusted legacy application when necessary.
  7. Sign out or restart, test, and restore the policy.
  8. If it still fails, investigate certificate trust, endpoint controls, child processes, or central policy.

Frequently Asked Questions

Can compatibility mode fix this error?

It may correct legacy application behavior, but it does not fix an unsigned, altered, or untrusted executable. Verify the signature and policy first.

Does running as administrator solve it?

No. The message commonly appears precisely when Windows is trying to elevate an executable whose signature cannot satisfy the active policy.

Can Windows Home use the registry fix?

The registry value is available, but Windows Home generally lacks Local Security Policy and Group Policy Editor. Central management or security software can still override local changes.

Why did the error appear after an update?

Users have reported timing after updates, but that does not establish that a specific update caused it. Check the file, certificate chain, and current policy before assigning blame.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

For a desktop executable, replace it with a signed build whenever possible. If a trusted legacy program cannot be replaced, temporarily change only ValidateAdminCodeSignatures, restart, test, and restore it. If the message comes from AD or LDAP tools, troubleshoot the directory referral instead of changing UAC.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.