Take Ownership of the Resource: Open Command Prompt as Administrator
👇 See all 3 solutions below
What is Error 9102?
Windows System Error Code 9102, known as DNS_ERROR_NOT_ALLOWED_ON_SIGNED_ZONE, is a Cluster & Storage error that occurs during cluster, backup, and storage management. The error indicates that: This operation is not allowed on a zone that is signed or has signing keys. When this error is encountered, the Windows operating system was unable to complete the requested operation within the storage/cluster services subsystem. The error code 9102 is returned by the GetLastError() function and provides developers with a specific identifier to diagnose the root cause of the failure. The symbolic name DNS_ERROR_NOT_ALLOWED_ON_SIGNED_ZONE maps directly to this numeric code and is commonly referenced in Microsoft documentation, developer forums, and system logs. Understanding this error and its context within cluster, backup, and storage management is essential for effective troubleshooting.
Common Causes
- Your user account lacks NTFS permissions on the target file or folder
- User Account Control (UAC) is blocking the operation
- The file is owned by SYSTEM or TrustedInstaller and requires ownership transfer
- Group Policy or antivirus software is restricting access
Mastering the Windows Command Line: WMIC, Netsh, and Diskpart
An expert's guide to using native Windows command-line utilities for deep diagnostic reporting, network tracing, and disk volume management.
Read the full guide →Step-by-Step Solutions
- Open Command Prompt as Administrator
- Run: takeown /f "C:\path\to\file" /r /d y
- Then run: icacls "C:\path\to\file" /grant %username%:F /t
- Replace the path with the actual file or folder causing Error 9102 (DNS_ERROR_NOT_ALLOWED_ON_SIGNED_ZONE)
- Retry the operation that triggered Error 9102 (DNS_ERROR_NOT_ALLOWED_ON_SIGNED_ZONE)
Video Tutorials
Diagnostic Command
Run this PowerShell command to find related events in your system log:
Get-EventLog -LogName System -Newest 20 | Where-Object {$_.Message -like "*9102*" -or $_.Message -like "*DNS_ERROR_NOT_ALLOWED_ON_SIGNED_ZONE*"} | Format-List
💡 Open PowerShell as Administrator, paste the command above, and press Enter.
Prevention Tips
- Avoid modifying files in C:\Windows\System32 unless absolutely necessary
- Use 'Run as Administrator' when performing system-level operations
- Keep a backup admin account in case your primary account gets locked