Avamar: Windows VSS backups fail with "code 0x80070005 Access Is denied" error message
Summary: Windows Shadow Copy Service (VSS) backups fail with error 0x80070005 “Access is denied” and client allocation errors because avagent runs under an NT domain account lacking VSS and SQL sysadmin rights. ...
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
Windows VSS Backups Failure
Windows VSS system state backups fail with error messages similar to the following:
2015-12-11 07:17:22 avvss Error <8336>: VSS exception code 0x80070005 thrown creating object - 'code 0x80070005: Access is denied'
2015-12-11 07:17:22 avvss Error <0000>: Failed to allocate VSS client, exiting
Avagentservice might be configured to run with an NT domain account due to Avamar SQL backups also occurring on that same client.- The NT Authority/SYSTEM account has not been granted the sysadmin role in SQL Server Management Studio, which is required to back up SQL databases.
Cause
Root Cause of the Windows VSS Backups Failure
The root cause of failing with "Access is denied" error is due to the Backup Agent (Avagent) service being configured with an NT domain account. This account does not have sufficient permissions for VSS shadow copy operations.
By default, the Avagent service is configured to run with the local SYSTEM account, which has the necessary rights. However, when the service is configured to run with an NT domain account, it lacks the required permissions, leading to the "Access is denied" error.
The specific error code associated with this issue is 0x80070005, which indicates an access denied error.
Error code: 0x80070005
Error message: Access is denied
Contributing Factors
- The NT domain account used to configure the
Avagentservice does not have the sysadmin role in SQL Server Management Studio, which is required to back up SQL databases. - The Avamar SQL backups are also occurring on the same client, which may be related to the configuration of the
Avagentservice.
Resolution
Resolving Windows VSS Backups Failure
To resolve the Windows VSS backups failure, follow these steps:
- Open
regediton the Windows client to edit the registry and follow best practices to change regedit. - Browse to the
HKLM/System/CurrentControlSet/Services/VSSregistry key. - Right-click the
VssAccessControlkey and add a new DWORD (32-bit) value. - Name it with the domain\username of the
Avagentservice account and set the value to 1. - Exit the Registry Editor (reboot not necessary).
Verification and Additional Steps
- After completing the above steps, verify that the issue has been successfully resolved by checking the backup logs for any error messages related to VSS backups.
- No specific tools or software are required for this resolution beyond the Windows Registry Editor (
regedit).
Note: Ensure you have the necessary permissions to edit the registry and that you follow best practices for making changes to
regedit to avoid any potential issues.
Caution: Editing the registry can cause system instability if not done correctly. Proceed with caution and consider backing up the registry before making changes.
Affected Products
Avamar, Avamar Client for WindowsArticle Properties
Article Number: 000025623
Article Type: Solution
Last Modified: 24 سبتمبر 2026
Version: 5
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.