The message “A referral was returned from the server” has two unrelated meanings. When one executable fails during Run as administrator, Windows is commonly enforcing User Account Control: Only elevate executable files that are signed and validated. When the message appears in Active Directory or LDAP tools, it may instead be a genuine directory referral (error 8235/0x202B). Identify the branch first, then use the narrowest fix.
First, identify which error you have
| What you see | Most likely cause |
|---|---|
| One old .exe fails when launched with Run as administrator | UAC code-signing policy or an invalid/untrusted signature |
| An installer or driver downloaded from the internet fails | Signature validation, SmartScreen, or a damaged download |
| Several unrelated programs fail after a security-policy change | Local or domain UAC policy |
| A Citrix published application fails to launch | Application-specific UAC/signature compatibility |
The message appears in Get-ADUser, LDAP, or domain-management software |
Active Directory referral |
| The text includes 8235, 0x202B, LDAP, domain, forest, or naming context | Active Directory referral |
Microsoft documents the elevation policy and its registry mapping in its UAC settings reference. A directory referral is a different subsystem and needs domain, DNS, or replication troubleshooting.
Check the executable’s digital signature first
- Right-click the executable and choose Properties.
- Open Digital Signatures, if that tab exists.
- Select the signature, choose Details, and confirm that Windows reports it as valid.
- Review the signer, timestamp, and certificate path.
No Digital Signatures tab usually means the file is unsigned. That does not by itself prove malware, but an unsigned file can be blocked when signature validation is required. Prefer a current build downloaded from the publisher, avoid cracked or repacked copies, compare the publisher’s checksum when supplied, and ask the vendor for a signed release if a legitimate program is unsigned or has a broken certificate.
Optional PowerShell check
Get-AuthenticodeSignature -FilePath "C:PathProgram.exe" |
Format-List Status,StatusMessage,SignerCertificate,Path
Valid means validation succeeded in the current environment; NotSigned, HashMismatch, or UnknownError require further investigation of the file and certificate chain.
Recommended Free Tools
#1 Best Overall
Fix the specific UAC policy
Use this only when the application is trusted, genuinely needs elevation, and no supported signed replacement is available. The policy is documented as disabled by default, although an organization can enable it through Group Policy or MDM.
Local Security Policy (Pro, Enterprise, Education and managed editions)
- Press Win + R, enter
secpol.msc, and press Enter. - Open Local Policies > Security Options.
- Open User Account Control: Only elevate executable files that are signed and validated.
- Set it to Disabled, then select Apply and OK.
- Sign out and back in, or restart Windows, and test the program.
- Set the policy back to Enabled when testing or installation is complete.
Microsoft lists the policy path and edition applicability in its Local Policies Security Options documentation. Windows Home generally does not include this snap-in.
Registry method (including Windows Home)
Create a restore point or export the relevant key before editing the registry.
Rank #2
- Press Win + R, type
regedit, and press Enter. - Go to
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem. - Find the DWORD
ValidateAdminCodeSignaturesand set it to0. - Sign out or restart, then test the application.
- Restore the value to
1when signature enforcement is required again.
From an elevated Command Prompt, the same change can be made with:
reg query "HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem" /v ValidateAdminCodeSignatures
reg add "HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem" /v ValidateAdminCodeSignatures /t REG_DWORD /d 0 /f
reg add "HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem" /v ValidateAdminCodeSignatures /t REG_DWORD /d 1 /f
Run these commands only in an elevated terminal and not on a managed computer without approval. They change the registry-backed policy described by Microsoft’s UAC documentation.
Do not disable UAC as the default workaround
ValidateAdminCodeSignatures controls signature validation for elevated executables. EnableLUA controls the broader “Run all administrators in Admin Approval Mode” behavior. Setting EnableLUA to 0 or moving the UAC slider to Never notify weakens protections far beyond this one policy. Do not begin there, and do not leave UAC disabled permanently. A Citrix article documents EnableLUA=0 for a particular XenApp VDA launch problem; that environment-specific workaround should not be generalized. On Citrix MCS, any approved change may need to be made in the master image and propagated through the catalog.
If the signature is valid but the error remains
- The certificate chain may lack a trusted root or intermediate, or revocation/timestamp validation may fail.
- The file may have been modified after signing.
- Your organization may not trust the publisher; administrators can manage the Trusted Publishers store.
- Defender, App Control for Business, AppLocker, Smart App Control, or endpoint security may be blocking it.
- A signed launcher may start an unsigned helper executable.
- You may be elevating an old copy in Downloads instead of the installed copy.
- A domain, MDM, or security-baseline policy may be reapplying the setting.
- UIAccess applications have a separate secure-location policy; do not confuse it with
ValidateAdminCodeSignatures.
Compatibility mode can help with obsolete APIs or behavior, but it does not repair a missing or invalid signature. Built-in tools such as Narrator or Magnifier require additional checks of system-file integrity, servicing, catalogs, and policy rather than copying executables from another PC.
Check domain management before changing a work PC
Group Policy or MDM can override local settings. Generate a report with:
gpresult /h "%USERPROFILE%Desktopgpresult.html"
gpresult /r
Open the HTML report and search for Only elevate executable files that are signed and validated. An elevated PowerShell check is:
Rank #4
- Mastering Microsoft Endpoint Manager: Deploy and manage Windows 10, Windows 11, and Windows 365 on both physical and cloud PCs
- ABIS BOOK
- Packt Publishing
Get-ItemProperty `
-Path "HKLM:SOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem" `
-Name ValidateAdminCodeSignatures,EnableLUA
For long-term remediation, replace the obsolete program, obtain an enterprise-supported signed build, or have administrators approve and govern the vendor certificate instead of weakening an entire fleet.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When the message is an Active Directory referral
If the error occurs in AD or LDAP administration, changing UAC will not help. Capture the complete command and check for error 8235 or 0x202B. Then:
- Identify the domain, forest, naming context, and server being queried.
- Verify DNS resolution and domain-controller discovery.
- Confirm that the account and tool target the correct domain or naming context.
- Check replication and whether the referenced object or partition is moving or unavailable.
- Use the appropriate domain controller or global catalog.
- Review Directory Service and DNS event logs, and involve the domain administrator.
A directory referral means the server is directing the request elsewhere; it is not evidence that an executable is unsigned. A separate explanation of this 8235/0x202B context is available from Server Scheduler.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallPractical order of operations
- Record the exact message, failing file, and context.
- Separate application-launch cases from AD/LDAP cases.
- Verify the file’s source and signature.
- Install a current signed vendor build if available.
- Check whether
ValidateAdminCodeSignaturesis enabled. - Temporarily disable only that policy for a trusted legacy application when necessary.
- Sign out or restart, test, and restore the policy.
- If it still fails, investigate certificate trust, endpoint controls, child processes, or central policy.
Frequently Asked Questions
Can compatibility mode fix this error?
It may correct legacy application behavior, but it does not fix an unsigned, altered, or untrusted executable. Verify the signature and policy first.
Does running as administrator solve it?
No. The message commonly appears precisely when Windows is trying to elevate an executable whose signature cannot satisfy the active policy.
Can Windows Home use the registry fix?
The registry value is available, but Windows Home generally lacks Local Security Policy and Group Policy Editor. Central management or security software can still override local changes.
Why did the error appear after an update?
Users have reported timing after updates, but that does not establish that a specific update caused it. Check the file, certificate chain, and current policy before assigning blame.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →The Bottom Line
For a desktop executable, replace it with a signed build whenever possible. If a trusted legacy program cannot be replaced, temporarily change only ValidateAdminCodeSignatures, restart, test, and restore it. If the message comes from AD or LDAP tools, troubleshoot the directory referral instead of changing UAC.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




