Resolving DCOM Event 10016 Errors for SIMATIC NET SServCfg.exe

David Krause10 min read
OPC / OPC UASiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

Event Viewer on a Windows Server 2003 host running SIMATIC NET PC Software V6.4 together with SIMATIC NCM PC V5.4 SP1 fills with repeated DCOM 10016 entries. The source executable is SServCfg.exe, the SIMATIC NET Configuration Service, registered under CLSID {96B2BC2E-7A2A-4152-9937-AE39765B0749}. The error states that the machine's default authorization parameters do not grant Local Activation to the COM server application for the SID NT AUTHORITY\NETWORK SERVICE (S-1-5-20). OPC and OPC XML-DA traffic still works, but the log noise hides real faults and consumes disk space.

This reference documents the root cause of the 10016 entries on a Server 2003 5.2.3790 SP1 host, the role of SServCfg.exe, the official Microsoft workaround for the 10016 class of error, and the Siemens-specific considerations when the affected COM server belongs to SIMATIC NET.

Problem Details

Event Viewer / Application log on the OPC server repeatedly shows events with the following text (French locale, translated):

Log Name:      Application
Source:        Microsoft-Windows-DistributedCOM
Event ID:      10016
The application-specific permission settings do not grant Local Activation
permission for the COM Server application with CLSID
{96B2BC2E-7A2A-4152-9937-AE39765B0749}
to the user NT AUTHORITY\NETWORK SERVICE (S-1-5-20).
This security permission can be modified using the Component Services
administrative tool.

Key facts captured from the source incident:

  • Affected host: Windows Server 2003 Standard Edition, build 5.2.3790, Service Pack 1
  • Siemens stack: SIMATIC NET PC Software V6.4 with SIMATIC NCM PC V5.4 SP1
  • Triggering service: SServCfg.exe (SIMATIC NET Configuration Service)
  • Target SID: S-1-5-20 / NT AUTHORITY\NETWORK SERVICE
  • Requested access: Local Activation for the COM server application
  • No functional impact reported on the OPC/OPC XML-DA communication itself
Note: Event 10016 is logged as a warning that a permission was denied, but Windows does not abort the COM call by default. The event exists so administrators can audit the access policy. Treat the entry as informational unless OPC traffic actually fails.

Root Cause

DCOM event 10016 is generated when a client process calls CoCreateInstance (or another activation API) against a COM server whose launch and activation ACL does not contain the calling identity. The DCOM subsystem records the denial, returns E_ACCESSDENIED to the kernel-mode SCM, and continues. The actual COM call may still succeed because Windows retries with the Interactive User identity or the calling process is already running.

In the SIMATIC NET environment the calling identity is typically the NetworkService account that hosts the S7/OPC service pool. The CLSID {96B2BC2E-7A2A-4152-9937-AE39765B0749} resolves to SServCfg.exe, the SIMATIC NET Configuration Service that maintains the S7/IE/PN communication configuration store. The 10016 entries reappear every time the service is restarted or a client re-activates the COM object.

Per Microsoft's official documentation, 10016 is logged by Windows when Microsoft components try to access DCOM components without the required permissions; the event is informational and the documented resolution is to grant the missing access through Component Services or to ignore the events. See DCOM event ID 10016 is logged in Windows - Microsoft Learn for the canonical description.

Why Server 2003 is special

Windows Server 2003 pre-dates the consolidated DCOMCNFG UI improvements in later Windows releases. The launch and activation ACLs of COM applications are stored in HKEY_CLASSES_ROOT\AppID\<AppID GUID> and are edited either through Component Services (dcomcnfg.exe) or by direct ACL editing with regedit. Both paths are covered below for the Server 2003 build used in the incident.

Is SServCfg.exe Required?

Yes. SServCfg.exe is the executable for the SIMATIC NET Configuration Service. It hosts the COM classes used by SIMATIC NCM PC Manager and the OPC server to read and write the S7/IE/PN station and connection configuration. If the service is stopped, configuration downloads from NCM PC fail and any OPC tag that depends on a re-read of the project fails to start.

Recommended state on a production OPC/OPC XML-DA host:

  • Startup type: Automatic
  • Log-on account: LocalSystem or a dedicated domain service account with the privileges listed in the SIMATIC NET V6.4 installation manual
  • Status: Running

Disabling the service is therefore not a valid workaround; the DCOM ACL must be corrected instead.

Solution: Grant Local Activation to NETWORK SERVICE

The Microsoft-published workaround is to add the missing Launch and Activation permission for the calling SID to the affected COM application. Two equivalent procedures are described: the GUI path (preferred for first-time fixes) and the registry path (used for scripted rollouts and for SIMATIC NET hosts that run headless).

Prerequisites

  1. Log on interactively as a member of the local Administrators group.
  2. Have the SIMATIC NET V6.4 installation media available in case a repair-install is required.
  3. Close all OPC client applications and stop the SIMATIC NET services to avoid the ACL being read while you are editing it: net stop "S7EPA", net stop "SimaticNet" (or the equivalent service name set by the installer).
  4. Open the Event Viewer so you can confirm the new CLSID matches {96B2BC2E-7A2A-4152-9937-AE39765B0749}.

Method 1 - Component Services (dcomcnfg.exe)

  1. Click Start → Run, type dcomcnfg, and press Enter to open Component Services.
  2. Expand Component Services → Computers → My Computer → DCOM Config.
  3. From the View menu enable Details. Right-click the column header and choose to display Application ID.
  4. Locate the entry whose Application ID equals {96B2BC2E-7A2A-4152-9937-AE39765B0749} (the friendly name is SServCfg). If the entry is missing, the SIMATIC NET Configuration Service has not been started at least once; start the service from services.msc and refresh.
  5. Right-click the entry and choose Properties.
  6. On the Security tab, under Launch and Activation Permissions, click Edit.
  7. If the dialog warns that the ACL is not editable, you are not running with full administrator token. Re-launch dcomcnfg with elevated rights on Server 2003 by running runas /user:<hostname>\Administrator dcomcnfg from an elevated command prompt.
  8. Click Add, type NETWORK SERVICE, validate, and press OK.
  9. Tick the Local Activation allow checkbox. Leave the other permissions at their default values.
  10. Click OK twice and close Component Services.
Note: Some Windows Server 2003 builds ship the Component Services ACL editor with a read-only view for SYSTEM-owned ACLs. If you cannot edit the entry, fall back to Method 2 (registry ACL) or to subinacl as documented in the Microsoft Learn article cited above.

Method 2 - Registry ACL (headless or scripted)

  1. Open regedit as Administrator.
  2. Navigate to HKEY_CLASSES_ROOT\AppID\{96B2BC2E-7A2A-4152-9937-AE39765B0749}. Confirm the (Default) value reads SServCfg.
  3. Right-click the AppID key, choose Permissions, click Advanced, and confirm the owner is NT SERVICE\TrustedInstaller or Administrators. If the owner is SYSTEM and the ACL is locked, take ownership first.
  4. Use the subinacl tool to push the Launch and Activation ACE: subinacl /keyreg "HKCR\AppID\{96B2BC2E-7A2A-4152-9937-AE39765B0749}" /grant="NT AUTHORITY\NETWORK SERVICE"=LA
  5. Alternatively, on hosts where subinacl is not available, export the key, edit the binary ACL with a utility such as SetACL, and re-import.
  6. Reboot the host or restart the SIMATIC NET services so the new ACL is read.

Method 3 - Suppress the event (when the events are purely informational)

If OPC and OPC XML-DA traffic are working and the customer does not need the audit entries, the events can be suppressed using the Microsoft-recommended procedure to ignore 10016 entries. See the Microsoft Learn workaround for the registry-based suppression. Suppression should only be applied after the SIMATIC NET service has been validated end-to-end; it is not a substitute for the ACL fix.

Verification

  1. Clear the Application log or note the current event count.
  2. Restart the SIMATIC NET Configuration Service: net stop "S7EPA", net start "S7EPA", or use services.msc.
  3. Force a client activation by opening SIMATIC NCM PC Manager and reading the project, or by running an OPC XML-DA browse on the configured URL.
  4. Wait one minute and re-inspect the Application log. No new DCOM 10016 entries with CLSID {96B2BC2E-7A2A-4152-9937-AE39765B0749} should appear.
  5. Confirm SIMATIC NET functionality:
    • OPC DA server starts and exposes the expected tag set.
    • OPC XML-DA wrapper responds on the configured HTTP port.
    • S7/IE/PN connections report Connected in NCM PC Diagnostics.
  6. Optionally, run dcomperm (from the Windows 2003 Resource Kit) to dump the resolved ACL on the AppID and confirm the ACE for S-1-5-20 with 0x1 (Local Activation) is present.

SIMATIC NET-Specific Considerations

Service accounts used by SIMATIC NET V6.4

SIMATIC NET V6.4 uses several service identities depending on the installed components:

Service Executable Recommended Account
SIMATIC NET Configuration Service SServCfg.exe LocalSystem
S7DOS Helper s7dosvs.exe LocalSystem
OPC Server OPC.SimaticNET.exe (or wrapper) LocalSystem or domain service account
SNMP OPC Server (optional) SNMPOPC.exe LocalSystem

When any of these services runs under NETWORK SERVICE, the host records 10016 entries against their respective CLSIDs. The fix is identical: add NETWORK SERVICE to the Launch and Activation ACL of the affected AppID.

Interaction with NCM PC V5.4 SP1

NCM PC V5.4 SP1 calls the SServCfg COM interface during project download. If the NetworkService identity cannot launch the COM server, the download fails with a generic DCOM error and NCM PC records a project commit failure. Granting Local Activation fixes the download and removes the 10016 entries.

Firmware/Software update path

Siemens has released subsequent SIMATIC NET versions (V7.x, V8.x, V15/V16) where the 10016 noise is reduced because the installers apply the correct ACL during setup. If a Server 2003 host can be retired, migrating to a current SIMATIC NET release on a supported Windows Server eliminates the recurring events. Confirm the current SIMATIC NET version, hotfix level, and supported Windows version in the official Siemens Industry Online Support portal before any upgrade planning.

Troubleshooting Matrix

Symptom Likely Cause Action
10016 entries for CLSID 96B2BC2E, OPC works Missing Local Activation ACE for NETWORK SERVICE Apply Method 1 or Method 2
10016 entries plus OPC tag read failures SServCfg service stopped or disabled Start SIMATIC NET Configuration Service, recheck ACL
Cannot edit ACL in dcomcnfg Not running with full admin token on Server 2003 Use runas /user:<host>\Administrator dcomcnfg or switch to Method 2
Events reappear after fix Another component is the calling identity (e.g. SYSTEM, IUSR) Inspect the new 10016 entry and grant the correct SID
Different CLSID reported in 10016 Another DCOM server (Windows shell, WMI, etc.) is the target Refer to the Microsoft Q&A on multiple DCOM errors: Multiple DCOM errors in the event viewer
Windows Firewall blocks COM activation Default scope changed or GPO restricts DCOM Allow exception for %ProgramFiles%\Siemens\Automation\SimaticNet\SServCfg.exe on TCP 135 plus the dynamic RPC range

Diagnostic Commands

# Confirm the CLSID to executable mapping
reg query "HKCR\CLSID\{96B2BC2E-7A2A-4152-9937-AE39765B0749}" /s | findstr /i "LocalServer32 AppID"

# Inspect the AppID ACL owner and current ACEs
reg query "HKCR\AppID\{96B2BC2E-7A2A-4152-9937-AE39765B0749}" /s

# Resolve NETWORK SERVICE SID
whoami /user /upn

# Filter DCOM 10016 events from the last 24 hours
wevtutil qe Application "/q:*[System[EventID=10016 and TimeCreated[timediff(@SystemTime) <= 86400000]]]" /f:text

# Restart the SIMATIC NET Configuration Service and trigger a reactivation
net stop "S7EPA"
net start "S7EPA"

Rollout Checklist

  1. Capture the current Application log size and 10016 count as the baseline.
  2. Schedule a maintenance window; stop OPC clients and SIMATIC NET services.
  3. Apply the ACL change via dcomcnfg on one host and verify the log clears.
  4. Export the registry branch to a .reg file or to a subinacl script for the remaining hosts.
  5. Re-enable SIMATIC NET services and validate OPC tag read/write.
  6. Document the fix in the change record, including the version strings of SIMATIC NET, NCM PC, and Windows Server.

FAQ

What is SServCfg.exe in SIMATIC NET V6.4?

SServCfg.exe is the SIMATIC NET Configuration Service. It hosts the COM classes that SIMATIC NCM PC Manager and the OPC server use to read and write the S7, Industrial Ethernet, and PROFINET connection configuration store on the PC.

Can I just stop the service that produces the DCOM 10016 error?

No. The service is required for NCM PC to download projects and for the OPC server to expose its tag set. The correct fix is to grant NT AUTHORITY\NETWORK SERVICE the missing Local Activation right on AppID {96B2BC2E-7A2A-4152-9937-AE39765B0749}, not to disable the service.

Will fixing this DCOM 10016 entry affect OPC XML-DA traffic?

No. The event is informational and is recorded when the COM activation is denied. Granting Local Activation to NETWORK SERVICE removes the log noise without changing the data path. Re-verify OPC DA and OPC XML-DA browse and read operations after the change.

Which Microsoft tool edits the COM ACL on Windows Server 2003?

Use Component Services (dcomcnfg.exe) for interactive fixes, or the subinacl utility and regedit for scripted fixes. Microsoft documents the suppression path in the DCOM event ID 10016 support article.

Are there later SIMATIC NET versions that no longer log 10016 for this CLSID?

Yes. SIMATIC NET V7.x and later releases ship installers that apply the correct DCOM ACL during setup, which greatly reduces the 10016 noise on supported Windows Server versions. Confirm the supported Windows version and current hotfix level in Siemens Industry Online Support before planning an upgrade.

Back to blog