Hello,
The error code 0x80070002 in your DirectAccess setup indicates that the system cannot locate a required file or configuration element. Since you mentioned that you updated the DirectAccess server and manually entered the certificate hash, the failure is likely tied to the IPsec configuration not matching the new certificate binding. DirectAccess relies on IPsec tunnels that are authenticated using the server certificate, so if the certificate renewal or hash entry is incorrect, the IPsec service will fail to establish connections.
First, confirm that the new certificate is installed in the Local Computer > Personal store and that it has both the correct Enhanced Key Usage (EKU) for server authentication and the proper subject name (usually the FQDN of the DirectAccess server). Then, verify that the certificate is accessible to the Network Policy and Access Services (NPAS) role. You can check this by opening the Remote Access Management console, navigating to DirectAccess and VPN > Edit > Infrastructure Servers, and ensuring the certificate is properly bound.
Next, review the IPsec policies by running Get-DAServer in PowerShell and checking the CertificateHash value. If the hash does not match the current certificate’s thumbprint, update it using Set-DAServer -CertificateHash <new_thumbprint>. After that, restart the IPsec Policy Agent service (ipsec.sys) and the Remote Access Management service to reload the configuration.
If the error persists, check the system event logs under Applications and Services Logs > Microsoft > Windows > IPsec > Operational. Event IDs such as 4653 or 4654 will indicate mismatched or missing certificate bindings. Also, confirm that the CRL (Certificate Revocation List) is reachable from the DirectAccess server; a missing CRL can also trigger 0x80070002 errors during IPsec negotiation.
If all of these checks are correct and the issue continues, it may point to corruption in the DirectAccess configuration store. In that case, re-run the DirectAccess setup wizard to regenerate the IPsec policies with the new certificate. This ensures the Group Policy Objects (GPOs) pushed to clients are consistent with the server configuration.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
HP.