Glossary · Network & radio
Attach Reject Cause
Also known as: EMM cause, reject cause, 5GMM cause, registration reject
An attach reject cause is the numeric code a mobile network returns when it refuses to let a device register. In LTE it is the EMM cause carried in an Attach Reject or Tracking Area Update Reject message, defined in 3GPP TS 24.301; 5G uses a similar set of 5GMM causes from TS 24.501. The cause explains why registration failed — and tells the device what to do next.
Common EMM reject causes
| Cause | Name | Typical meaning |
|---|---|---|
| #2 | IMSI unknown in HSS | The home network does not know the subscriber, e.g. an unprovisioned profile |
| #3 | Illegal UE | Authentication failed or the identity is not accepted |
| #6 | Illegal ME | The device (IMEI) is blocked |
| #7 | EPS services not allowed | The subscription does not include LTE service |
| #11 | PLMN not allowed | No permission on this network — often a missing roaming agreement or barring |
| #12 | Tracking area not allowed | Service is not allowed in this area |
| #13 | Roaming not allowed in this tracking area | Roaming is allowed on the network, but not here |
| #14 | EPS services not allowed in this PLMN | LTE is not allowed on this network, though other RATs may be |
| #15 | No suitable cells in tracking area | The device should look for another tracking area |
| #17 | Network failure | A generic failure, also used by some steering platforms |
| #19 | ESM failure | The data-connection part of attach failed, often an APN issue |
| #22 | Congestion | The network is overloaded; the device must back off |
What the device does next
Reject causes change device behavior, not just logs:
- #11 adds the network to the forbidden PLMN list, so the device stops trying it automatically.
- #12, #13 and #15 add the tracking area to a forbidden list and send the device searching elsewhere.
- #3, #6 and #7 make the SIM unusable for LTE until the device restarts or the SIM is reinserted.
- #17 and #22 lead to retries and back-off timers rather than blocking.
That is why one badly chosen reject — for example from steering of roaming — can keep an IoT device off the network far longer than expected. In 5G SA, related 5GMM causes include #7 “5GS services not allowed”, #27 “N1 mode not allowed” and #62 “No network slices available”.
Why it matters for testing
“No service” is a symptom; the reject cause is the diagnosis. Telling #11 (a roaming agreement problem) apart from #15 (a coverage or RAT problem) or #19 (an APN problem) sends the fix to the right team. SimCheck.ai decodes radio signaling for each test, including the network’s reject cause, and shows failure reasons inline — see the roaming testing guide.
Last updated · SimCheck.ai team