Quick answer
QuickBooks payroll service connection error means QuickBooks Desktop Payroll cannot reach Intuit's payroll servers, so sending payroll, direct deposit, e-filing and tax table downloads stop. Confirm whether the subscription is active or the connection is blocked: check the service key and EIN, then repair internet settings, TLS and Windows components, and retest.
What the QuickBooks payroll service connection error means
QuickBooks Desktop Payroll is a connected service. Pay runs, direct deposit submissions, e-files, e-payments and tax table downloads all have to reach Intuit. When that fails, QuickBooks stops the action and reports a connection error instead of a payroll result: nothing is sent and no money moves.
Connection failures also look like update failures. Intuit documents error codes PS032, PS033, PS036, PS101 and PS107 for payroll downloads and lists three causes: incorrect internet settings, a firewall that blocks payroll updates, and a damaged file in the CPS folder — the payroll component store QuickBooks uses to stage downloads.
| What you see | What it points to | Start with |
|---|---|---|
| PS032, PS033, PS036, PS101 or PS107 | Blocked internet settings, a firewall rule or a damaged CPS file on the payroll download path | Step 3 |
| A connection or server error with no code, or a send that hangs | QuickBooks cannot complete the online check at all | Step 2 |
| A subscription message, or a service key status that is not Active | An entitlement problem, not a network problem | Step 1 |
QuickBooks Online Payroll runs in a browser and does not use the Desktop connection stack, the CPS folder or the QuickBooks Tool Hub. If you sign in to QuickBooks Online, treat the issue as an Online payroll problem and skip these Desktop steps.
Subscription problem or connection problem: how to tell
A subscription problem is about entitlement: the network works, but Intuit says payroll is not active for this company file. A connection problem is about transport: the subscription is active, but the request never arrives. Test entitlement first; it takes two minutes and decides everything that follows.
Open the company file and go to Employees → My Payroll Service → Manage Service Key. The Service Name and Status must show as Active. Then open Company → My Company, select Edit, and compare the Federal Employer Identification No. with the EIN on the subscription. A key that does not match the file's EIN cannot validate on any network.
If the key is not Active or the EIN differs, work through payroll subscription errors first. If both check out, the problem is the connection path.
Symptoms of a payroll service connection failure
- The payroll action stops with a connection or server error, and no paycheck status is recorded.
- Employees → Get Payroll Updates cannot finish even though web browsing works normally.
- The failure repeats at the same point, or only one computer in a multi-user setup is affected.
- A browser test succeeds, which narrows the problem to QuickBooks, TLS or a security filter.
Common causes, ranked
- A firewall, proxy, VPN or HTTPS-inspection filter blocks the connection. QuickBooks must reach Intuit on ports 80 and 443 with a clean TLS handshake, and appliances that decrypt traffic break that handshake. VPN clients frequently block it outright.
- TLS 1.2 is disabled, or Windows components are damaged. QuickBooks Desktop uses Internet Explorer components for secure connections; Intuit requires TLS 1.2, Internet Explorer 11 and .NET Framework 4.5.2 or later, and damaged .NET, MSXML or Visual C++ components fail the same way.
- The Windows date, time or time zone is wrong. Certificate validation compares timestamps, so a clock off by hours makes a valid certificate look invalid.
- Payroll is sent in multi-user mode. Payroll transmissions and subscription checks want single-user mode, and a shared file session can interrupt the send.
- A damaged CPS folder. An interrupted download leaves broken files behind, and every retry hits the same damaged component store.
- An outdated QuickBooks release. Older releases can fail to negotiate current security requirements; Intuit lists installing the latest update among the fixes.
Before you begin
- Back up the company file with File → Back Up Company and copy the backup off the machine.
- Write down the exact error text and code, plus your payroll service: Basic, Enhanced or Assisted.
- Sign in with a Windows administrator account, and have the payroll PIN and service key ready.
- Press F2 to record the QuickBooks release and edition.
Back up and note the original state first. Steps 3, 7 and 8 change Windows internet settings, firewall rules and a QuickBooks program folder. Write down the original proxy and firewall values so you can undo a change if it affects something else.
How to fix a QuickBooks payroll service connection error
Confirm the service key and EIN are active and matching
Open Employees → My Payroll Service → Manage Service Key and confirm the status reads Active. Select Edit, compare the key against your subscription email, correct it if needed, select Next, clear Open Payroll Setup, then select Finish. Then open Company → My Company → Company Information, select Edit, and compare the Federal Employer Identification No. with the EIN on the subscription. If the status is not Active or the EIN differs, fix that first; the payroll setup guide covers key entry.
Menu naming changed. Older releases label the window Employees → My Payroll Service → Manage Payroll Service. Current releases use Manage Service Key.
Rule out an Intuit outage, then test the network path
Open a browser and load a secure site, then check Intuit's service status page for an outage; no local fix helps if Intuit is down. Flush the DNS cache: press Windows + R, type cmd, press Enter, and run ipconfig /flushdns. If the office network is the suspect, tether the computer to a phone hotspot and retry. Success on the hotspot proves an office firewall, proxy or VPN is filtering the traffic.
Restore QuickBooks internet settings and enable TLS 1.2
In QuickBooks, go to Help → Internet Connection Setup. Choose Use my computer's Internet connection settings to establish a connection when this program accesses the Internet, select Next → Advanced Connection Settings → Restore Advanced Settings. Open Internet Options with Windows + R and inetcpl.cpl. On the Connections tab, open LAN settings and clear Use a proxy server for your LAN only if your network does not need one. On the Advanced tab, under Security, select Use TLS 1.2 and clear TLS 1.0 and 1.1, then select Apply and retry.
Correct the Windows date, time and time zone
Right-click the clock and select Adjust date/time. Turn on Set time automatically and Set time zone automatically, then select Sync now. Confirm the time zone, because an accurate clock set to the wrong zone still fails certificate validation. Restart QuickBooks and retry.
Retry in a clean single-user session as administrator
Close the company file and QuickBooks. Open Task Manager with Ctrl + Shift + Esc and end any QBW32.exe, QBDBMgrN.exe, QBCFMonitorService.exe and QBUpdate.exe tasks. Right-click the QuickBooks icon and choose Run as administrator, open the company file, and switch to single-user mode with File → Switch to Single-User Mode. Retry the payroll action.
Repair Windows components with the QuickBooks Tool Hub
Download and install the current QuickBooks Tool Hub from Intuit, then close QuickBooks. Under Program Problems, run Quick Fix my Program. Under Installation Issues, run QuickBooks Install Diagnostic Tool, which repairs the .NET, MSXML and Visual C++ components connected services depend on, then run QuickBooks TLS 1.2 Tool. Let each tool finish, restart the computer, and retry. The Tool Hub guide explains the tools in order.
Allow QuickBooks through the firewall and antivirus
Change one rule at a time. Write down each rule you add. Never disable firewall or antivirus protection permanently to test payroll; add exceptions instead, and re-enable everything after the test.
Add QBW32.exe, QBUpdate.exe and QBDBMgrN.exe as allowed programs for private and public networks, and allow outbound traffic on ports 80 and 443. In antivirus tools, exclude the QuickBooks program folder and the company-file folder. If a firewall or proxy performs HTTPS inspection, ask IT to exempt Intuit traffic. The firewall and ports guide lists the rules QuickBooks needs.
Rename the CPS folder and run a manual payroll update
Close QuickBooks and back up the company file first. The CPS folder holds staged payroll downloads, not company data, but rename it instead of deleting it so the change is reversible.
In File Explorer, open your QuickBooks program folder — for example C:\Program Files (x86)\Intuit\QuickBooks 2024; your release folder may differ. Open Components\Payroll and rename CPS to CPS.old. Reopen the company file, go to Employees → Get Payroll Updates, select Download Entire Update, then select Update. This manual update also refreshes subscription data. If it still fails, the problem is in the connection path; return to Steps 2 and 3.
Verify QuickBooks can reach payroll services
- Confirm Manage Service Key still shows Active with the correct EIN.
- Run Get Payroll Updates and confirm the tax table version matches Intuit's current release.
- Open the Payroll Center and confirm no update or connection reminders appear.
- Send your next scheduled payroll and watch Employees → View Payroll Run Status move from Sent to Intuit to Sent to Bank to Payroll processed.
If the payroll connection error keeps coming back
Restart Windows in Safe Mode with Networking and retry. That removes antivirus, VPN clients and startup filters; if payroll works there, a third-party tool is the culprit. If every computer fails at once, have IT allowlist Intuit payroll and update traffic and stop HTTPS inspection for those hosts. If one computer fails while others succeed, compare its TLS settings, clock and proxy setup with a working machine. When the error persists with an Active subscription, matching EIN and an open network, contact Intuit payroll support with the exact code, your service key status and the steps you completed. Do not send the same pay run repeatedly against a failing connection; a duplicate submission is worse than a delayed one.
Prevention
- Keep QuickBooks Desktop updated, and confirm TLS 1.2 stays selected after major Windows updates.
- Send payroll in single-user mode on a stable wired connection, not over a VPN.
- Verify the service key status and EIN after every restore, migration or legal-name change.
Frequently asked questions
How do I tell a payroll subscription error from a connection error?
Check Manage Service Key. If the status is not Active, or the EIN does not match the subscription, it is an entitlement problem and no network change will fix it. If the status is Active and the EIN matches but payroll still cannot reach Intuit, the connection path is the problem.
Why does QuickBooks use Internet Explorer settings on Windows 10 and 11?
QuickBooks Desktop uses Internet Explorer components for secure connections, so Internet Options TLS and proxy settings still govern how it reaches Intuit. That is why Intuit requires Internet Explorer 11 and TLS 1.2 even if you never open the browser.
Does a connection error affect company data or paychecks already sent?
No. A failed connection stops the send before Intuit processes anything. The risk is resending a pay run that did go through, which can create duplicate direct deposits.
Can I send payroll while the company file is in multi-user mode?
Send in single-user mode instead. Multi-user sessions can interrupt the payroll transmission, and switching with File → Switch to Single-User Mode removes that variable in seconds.
Sources & further reading
- Fix PSXXX errors when downloading payroll updates — Intuit QuickBooks Help
- TLS 1.2 for QuickBooks Desktop for Windows — Intuit QuickBooks Help
- Fix subscription has lapsed error in QuickBooks Desktop — Intuit QuickBooks Help
- Change your Employer Identification Number (EIN) for payroll — Intuit QuickBooks Help