| Logon type | Logon title | Description |
|---|---|---|
| 2 | Interactive | A user logged on to this computer. |
| 3 | Network | A user or computer logged on to this computer from the network. |
| 4 | Batch | Batch logon type is used by batch servers, where processes may be executing on behalf of a user without their direct intervention. |
| 5 | Service | A service was started by the Service Control Manager. |
| 7 | Unlock | This workstation was unlocked. |
| 8 | NetworkCleartext | A user logged on to this computer from the network. The user’s password was passed to the authentication package in its unhashed form. The built-in authentication packages all hash credentials before sending them across the network. The credentials do not traverse the network in plaintext (also called cleartext). |
| Event ID (2000/XP/2003) | Event ID (Vista/7/8/2008/2012) | Description | Log Name |
|---|---|---|---|
| 528 | 4624 | Successful Logon | Security |
| 529 | 4625 | Failed Login | Security |
| 680 | 4776 | Successful /Failed Account Authentication | Security |
| 624 | 4720 | A user account was created | Security |
| 636 | 4732 | A member was added to a security-enabled local group | Security |
| 632 | 4728 | A member was added to a security-enabled global group | Security |
| 2934 | 7030 | Service Creation Errors | System |
| 2944 | 7040 | The start type of the IPSEC Services service was changed from disabled to auto start. | System |
| 2949 | 7045 | Service Creation | System |
- EoS = Event-o-Pedia
- MS = Microsoft Official
- ME = Manage Engine
- UWS = Ultimate Windows Security
- [512] EoP MS ME UWS – Windows NT is starting up
- [513] EoP MS ME UWS – Windows is shutting down
- [514] EoP MS ME UWS – An authentication package has been loaded by the Local Security Authority
- [515] EoP MS ME UWS – A trusted logon process has registered with the Local Security Authority
- [516] EoP MS ME UWS – Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits
- [517] EoP MS ME UWS – The audit log was cleared
- [518] EoP MS ME UWS – A notification package has been loaded by the Security Account Manager
- [519] EoP MS ME UWS – A process is using an invalid local procedure call (LPC) port
- [520] EoP MS ME UWS – The system time was changed
- [521] EoP MS ME UWS – Unable to log events to security log
- [528] EoP MS ME UWS – Successful Logon
- [529] EoP MS ME UWS – Logon Failure – Unknown user name or bad password
- [530] EoP MS ME UWS – Logon Failure – Account logon time restriction violation
- [531] EoP MS ME UWS – Logon Failure – Account currently disabled
- [532] EoP MS ME UWS – Logon Failure – The specified user account has expired
- [533] EoP MS ME UWS – Logon Failure – User not allowed to logon at this computer
- [534] EoP MS ME UWS – Logon Failure – The user has not been granted the requested logon type at this machine
- [535] EoP MS ME UWS – Logon Failure – The specified account’s password has expired
- [536] EoP MS ME UWS – Logon Failure – The NetLogon component is not active
- [537] EoP MS ME UWS – Logon failure – The logon attempt failed for other reasons.
- [538] EoP MS ME UWS – User Logoff
- [539] EoP MS ME UWS – Logon Failure – Account locked out
- [540] EoP MS ME UWS – Successful Network Logon
- [551] EoP MS ME UWS – User initiated logoff
- [552] EoP MS ME UWS – Logon attempt using explicit credentials
- [560] EoP MS ME UWS – Object Open
- [561] EoP MS ME UWS – Handle Allocated
- [562] EoP MS ME UWS – Handle Closed
- [563] EoP MS ME UWS – Object Open for Delete
- [564] EoP MS ME UWS – Object Deleted
- [565] EoP MS ME UWS – Object Open (Active Directory)
- [566] EoP MS ME UWS – Object Operation (Active Directory)
- [567] EoP MS ME UWS – Object Access Attempt
- [576] EoP MS ME UWS – Special privileges assigned to new logon
- [577] EoP MS ME UWS – Privileged Service Called
- [578] EoP MS ME UWS – Privileged object operation
- [592] EoP MS ME UWS – A new process has been created
- [593] EoP MS ME UWS – A process has exited
- [594] EoP MS ME UWS – A handle to an object has been duplicated
- [595] EoP MS ME UWS – Indirect access to an object has been obtained
- [596] EoP MS ME UWS – Backup of data protection master key
- [600] EoP MS ME UWS – A process was assigned a primary token
- [601] EoP MS ME UWS – Attempt to install service
- [602] EoP MS ME UWS – Scheduled Task created
- [608] EoP MS ME UWS – User Right Assigned
- [609] EoP MS ME UWS – User Right Removed
- [610] EoP MS ME UWS – New Trusted Domain
- [611] EoP MS ME UWS – Removing Trusted Domain
- [612] EoP MS ME UWS – Audit Policy Change
- [613] EoP MS ME UWS – IPSec policy agent started
- [614] EoP MS ME UWS – IPSec policy agent disabled
- [615] EoP MS ME UWS – IPSEC PolicyAgent Service
- [616] EoP MS ME UWS – IPSec policy agent encountered a potentially serious failure.
- [617] EoP MS ME UWS – Kerberos Policy Changed
- [618] EoP MS ME UWS – Encrypted Data Recovery Policy Changed
- [619] EoP MS ME UWS – Quality of Service Policy Changed
- [620] EoP MS ME UWS – Trusted Domain Information Modified
- [621] EoP MS ME UWS – System Security Access Granted
- [622] EoP MS ME UWS – System Security Access Removed
- [623] EoP MS ME UWS – Per User Audit Policy was refreshed
- [624] EoP MS ME UWS – User Account Created
- [625] EoP MS ME UWS – User Account Type Changed
- [626] EoP MS ME UWS – User Account Enabled
- [627] EoP MS ME UWS – Change Password Attempt
- [628] EoP MS ME UWS – User Account password set
- [629] EoP MS ME UWS – User Account Disabled
- [630] EoP MS ME UWS – User Account Deleted
- [631] EoP MS ME UWS – Security Enabled Global Group Created
- [632] EoP MS ME UWS – Security Enabled Global Group Member Added
- [633] EoP MS ME UWS – Security Enabled Global Group Member Removed
- [634] EoP MS ME UWS – Security Enabled Global Group Deleted
- [635] EoP MS ME UWS – Security Enabled Local Group Created
- [636] EoP MS ME UWS – Security Enabled Local Group Member Added
- [637] EoP MS ME UWS – Security Enabled Local Group Member Removed
- [638] EoP MS ME UWS – Security Enabled Local Group Deleted
- [639] EoP MS ME UWS – Security Enabled Local Group Changed
- [640] EoP MS ME UWS – General Account Database Change
- [641] EoP MS ME UWS – Security Enabled Global Group Changed
- [642] EoP MS ME UWS – User Account Changed
- [643] EoP MS ME UWS – Domain Policy Changed
- [644] EoP MS ME UWS – User Account Locked Out
- [645] EoP MS ME UWS – Computer Account Created
- [646] EoP MS ME UWS – Computer Account Changed
- [647] EoP MS ME UWS – Computer Account Deleted
- [648] EoP MS ME UWS – Security Disabled Local Group Created
- [649] EoP MS ME UWS – Security Disabled Local Group Changed
- [650] EoP MS ME UWS – Security Disabled Local Group Member Added
- [651] EoP MS ME UWS – Security Disabled Local Group Member Removed
- [652] EoP MS ME UWS – Security Disabled Local Group Deleted
- [653] EoP MS ME UWS – Security Disabled Global Group Created
- [654] EoP MS ME UWS – Security Disabled Global Group Changed
- [655] EoP MS ME UWS – Security Disabled Global Group Member Added
- [656] EoP MS ME UWS – Security Disabled Global Group Member Removed
- [657] EoP MS ME UWS – Security Disabled Global Group Deleted
- [658] EoP MS ME UWS – Security Enabled Universal Group Created
- [659] EoP MS ME UWS – Security Enabled Universal Group Changed
- [660] EoP MS ME UWS – Security Enabled Universal Group Member Added
- [661] EoP MS ME UWS – Security Enabled Universal Group Member Removed
- [662] EoP MS ME UWS – Security Enabled Universal Group Deleted
- [663] EoP MS ME UWS – Security Disabled Universal Group Created
- [664] EoP MS ME UWS – Security Disabled Universal Group Changed
- [665] EoP MS ME UWS – Security Disabled Universal Group Member Added
- [666] EoP MS ME UWS – Security Disabled Universal Group Member Removed
- [667] EoP MS ME UWS – Security Disabled Universal Group Deleted
- [668] EoP MS ME UWS – Group Type Changed
- [669] EoP MS ME UWS – Add SID History
- [670] EoP MS ME UWS – Add SID History
- [671] EoP MS ME UWS – User Account Unlocked
- [672] EoP MS ME UWS – Authentication Ticket Granted
- [673] EoP MS ME UWS – Service Ticket Granted
- [674] EoP MS ME UWS – Ticket Granted Renewed
- [675] EoP MS ME UWS – Pre-authentication failed
- [676] EoP MS ME UWS – Authentication Ticket Request Failed
- [677] EoP MS ME UWS – Service Ticket Request Failed
- [678] EoP MS ME UWS – Account Mapped for Logon by
- [679] EoP MS ME UWS – The name: %2 could not be mapped for logon by: %1
- [680] EoP MS ME UWS – Account Used for Logon by
- [681] EoP MS ME UWS – The logon to account: %2 by: %1 from workstation: %3 failed.
- [682] EoP MS ME UWS – Session reconnected to winstation
- [683] EoP MS ME UWS – Session disconnected from winstation
- [684] EoP MS ME UWS – Set ACLs of members in administrators groups
- [685] EoP MS ME UWS – Account Name Changed
- [686] EoP MS ME UWS – Password of the following user accessed
- [687] EoP MS ME UWS – Basic Application Group Created
- [688] EoP MS ME UWS – Basic Application Group Changed
- [689] EoP MS ME UWS – Basic Application Group Member Added
- [690] EoP MS ME UWS – Basic Application Group Member Removed
- [691] EoP MS ME UWS – Basic Application Group Non-Member Added
- [692] EoP MS ME UWS – Basic Application Group Non-Member Removed
- [693] EoP MS ME UWS – Basic Application Group Deleted
- [694] EoP MS ME UWS – LDAP Query Group Created
- [695] EoP MS ME UWS – LDAP Query Group Changed
- [696] EoP MS ME UWS – LDAP Query Group Deleted
- [697] EoP MS ME UWS – Password Policy Checking API is called
- [806] EoP MS ME UWS – Per User Audit Policy was refreshed
- [807] EoP MS ME UWS – Per user auditing policy set for user
- [808] EoP MS ME UWS – A security event source has attempted to register
- [809] EoP MS ME UWS – A security event source has attempted to unregister
- [848] EoP MS ME UWS – The following policy was active when the Windows Firewall started
- [849] EoP MS ME UWS – An application was listed as an exception when the Windows Firewall started
- [850] EoP MS ME UWS – A port was listed as an exception when the Windows Firewall started
- [851] EoP MS ME UWS – A change has been made to the Windows Firewall application exception list
- [852] EoP MS ME UWS – A change has been made to the Windows Firewall port exception list
- [853] EoP MS ME UWS – The Windows Firewall operational mode has changed
- [854] EoP MS ME UWS – The Windows Firewall logging settings have changed
- [855] EoP MS ME UWS – A Windows Firewall ICMP setting has changed
- [856] EoP MS ME UWS – The Windows Firewall setting to allow unicast responses to multicast/broadcast traffic has changed
- [857] EoP MS ME UWS – The Windows Firewall setting to allow remote administration, allowing port TCP + [135] EoP MS ME UWS and DCOM/RPC, has changed
- [858] EoP MS ME UWS – Windows Firewall group policy settings have been applied
- [859] EoP MS ME UWS – The Windows Firewall group policy settings have been removed
- [860] EoP MS ME UWS – The Windows Firewall has switched the active policy profile
- [861] EoP MS ME UWS – The Windows Firewall has detected an application listening for incoming traffic
- [1100] EoP MS ME UWS – The event logging service has shut down
- [1101] EoP MS ME UWS – Audit events have been dropped by the transport.
- [1102] EoP MS ME UWS – The audit log was cleared
- [1104] EoP MS ME UWS – The security Log is now full
- [1105] EoP MS ME UWS – Event log automatic backup
- [1108] EoP MS ME UWS – The event logging service encountered an error
- [4608] EoP MS ME UWS – Windows is starting up
- [4609] EoP MS ME UWS – Windows is shutting down
- [4610] EoP MS ME UWS – An authentication package has been loaded by the Local Security Authority
- [4611] EoP MS ME UWS – A trusted logon process has been registered with the Local Security Authority
- [4612] EoP MS ME UWS – Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.
- [4614] EoP MS ME UWS – A notification package has been loaded by the Security Account Manager.
- [4615] EoP MS ME UWS – Invalid use of LPC port
- [4616] EoP MS ME UWS – The system time was changed.
- [4618] EoP MS ME UWS – A monitored security event pattern has occurred
- [4621] EoP MS ME UWS – Administrator recovered system from CrashOnAuditFail
- [4622] EoP MS ME UWS – A security package has been loaded by the Local Security Authority.
- [4624] EoP MS ME UWS – An account was successfully logged on
- [4625] EoP MS ME UWS – An account failed to log on
- [4626] EoP MS ME UWS – User/Device claims information
- [4627] EoP MS ME UWS – Group membership information.
- [4634] EoP MS ME UWS – An account was logged off
- [4646] EoP MS ME UWS – IKE DoS-prevention mode started
- [4647] EoP MS ME UWS – User initiated logoff
- [4648] EoP MS ME UWS – A logon was attempted using explicit credentials
- [4649] EoP MS ME UWS – A replay attack was detected
- [4650] EoP MS ME UWS – An IPsec Main Mode security association was established
- [4651] EoP MS ME UWS – An IPsec Main Mode security association was established
- [4652] EoP MS ME UWS – An IPsec Main Mode negotiation failed
- [4653] EoP MS ME UWS – An IPsec Main Mode negotiation failed
- [4654] EoP MS ME UWS – An IPsec Quick Mode negotiation failed
- [4655] EoP MS ME UWS – An IPsec Main Mode security association ended
- [4656] EoP MS ME UWS – A handle to an object was requested
- [4657] EoP MS ME UWS – A registry value was modified
- [4658] EoP MS ME UWS – The handle to an object was closed
- [4659] EoP MS ME UWS – A handle to an object was requested with intent to delete
- [4660] EoP MS ME UWS – An object was deleted
- [4661] EoP MS ME UWS – A handle to an object was requested
- [4662] EoP MS ME UWS – An operation was performed on an object
- [4663] EoP MS ME UWS – An attempt was made to access an object
- [4664] EoP MS ME UWS – An attempt was made to create a hard link
- [4665] EoP MS ME UWS – An attempt was made to create an application client context.
- [4666] EoP MS ME UWS – An application attempted an operation
- [4667] EoP MS ME UWS – An application client context was deleted
- [4668] EoP MS ME UWS – An application was initialized
- [4670] EoP MS ME UWS – Permissions on an object were changed
- [4671] EoP MS ME UWS – An application attempted to access a blocked ordinal through the TBS
- [4672] EoP MS ME UWS – Special privileges assigned to new logon
- [4673] EoP MS ME UWS – A privileged service was called
- [4674] EoP MS ME UWS – An operation was attempted on a privileged object
- [4675] EoP MS ME UWS – SIDs were filtered
- [4688] EoP MS ME UWS – A new process has been created
- [4689] EoP MS ME UWS – A process has exited
- [4690] EoP MS ME UWS – An attempt was made to duplicate a handle to an object
- [4691] EoP MS ME UWS – Indirect access to an object was requested
- [4692] EoP MS ME UWS – Backup of data protection master key was attempted
- [4693] EoP MS ME UWS – Recovery of data protection master key was attempted
- [4694] EoP MS ME UWS – Protection of auditable protected data was attempted
- [4695] EoP MS ME UWS – Unprotection of auditable protected data was attempted
- [4696] EoP MS ME UWS – A primary token was assigned to process
- [4697] EoP MS ME UWS – A service was installed in the system
- [4698] EoP MS ME UWS – A scheduled task was created
- [4699] EoP MS ME UWS – A scheduled task was deleted
- [4700] EoP MS ME UWS – A scheduled task was enabled
- [4701] EoP MS ME UWS – A scheduled task was disabled
- [4702] EoP MS ME UWS – A scheduled task was updated
- [4703] EoP MS ME UWS – A token right was adjusted
- [4704] EoP MS ME UWS – A user right was assigned
- [4705] EoP MS ME UWS – A user right was removed
- [4706] EoP MS ME UWS – A new trust was created to a domain
- [4707] EoP MS ME UWS – A trust to a domain was removed
- [4709] EoP MS ME UWS – IPsec Services was started
- [4710] EoP MS ME UWS – IPsec Services was disabled
- [4711] EoP MS ME UWS – PAStore Engine (1%)
- [4712] EoP MS ME UWS – IPsec Services encountered a potentially serious failure
- [4713] EoP MS ME UWS – Kerberos policy was changed
- [4714] EoP MS ME UWS – Encrypted data recovery policy was changed
- [4715] EoP MS ME UWS – The audit policy (SACL) on an object was changed
- [4716] EoP MS ME UWS – Trusted domain information was modified
- [4717] EoP MS ME UWS – System security access was granted to an account
- [4718] EoP MS ME UWS – System security access was removed from an account
- [4719] EoP MS ME UWS – System audit policy was changed
- [4720] EoP MS ME UWS – A user account was created
- [4722] EoP MS ME UWS – A user account was enabled
- [4723] EoP MS ME UWS – An attempt was made to change an account’s password
- [4724] EoP MS ME UWS – An attempt was made to reset an accounts password
- [4725] EoP MS ME UWS – A user account was disabled
- [4726] EoP MS ME UWS – A user account was deleted
- [4727] EoP MS ME UWS – A security-enabled global group was created
- [4728] EoP MS ME UWS – A member was added to a security-enabled global group
- [4729] EoP MS ME UWS – A member was removed from a security-enabled global group
- [4730] EoP MS ME UWS – A security-enabled global group was deleted
- [4731] EoP MS ME UWS – A security-enabled local group was created
- [4732] EoP MS ME UWS – A member was added to a security-enabled local group
- [4733] EoP MS ME UWS – A member was removed from a security-enabled local group
- [4734] EoP MS ME UWS – A security-enabled local group was deleted
- [4735] EoP MS ME UWS – A security-enabled local group was changed
- [4737] EoP MS ME UWS – A security-enabled global group was changed
- [4738] EoP MS ME UWS – A user account was changed
- [4739] EoP MS ME UWS – Domain Policy was changed
- [4740] EoP MS ME UWS – A user account was locked out
- [4741] EoP MS ME UWS – A computer account was created
- [4742] EoP MS ME UWS – A computer account was changed
- [4743] EoP MS ME UWS – A computer account was deleted
- [4744] EoP MS ME UWS – A security-disabled local group was created
- [4745] EoP MS ME UWS – A security-disabled local group was changed
- [4746] EoP MS ME UWS – A member was added to a security-disabled local group
- [4747] EoP MS ME UWS – A member was removed from a security-disabled local group
- [4748] EoP MS ME UWS – A security-disabled local group was deleted
- [4749] EoP MS ME UWS – A security-disabled global group was created
- [4750] EoP MS ME UWS – A security-disabled global group was changed
- [4751] EoP MS ME UWS – A member was added to a security-disabled global group
- [4752] EoP MS ME UWS – A member was removed from a security-disabled global group
- [4753] EoP MS ME UWS – A security-disabled global group was deleted
- [4754] EoP MS ME UWS – A security-enabled universal group was created
- [4755] EoP MS ME UWS – A security-enabled universal group was changed
- [4756] EoP MS ME UWS – A member was added to a security-enabled universal group
- [4757] EoP MS ME UWS – A member was removed from a security-enabled universal group
- [4758] EoP MS ME UWS – A security-enabled universal group was deleted
- [4759] EoP MS ME UWS – A security-disabled universal group was created
- [4760] EoP MS ME UWS – A security-disabled universal group was changed
- [4761] EoP MS ME UWS – A member was added to a security-disabled universal group
- [4762] EoP MS ME UWS – A member was removed from a security-disabled universal group
- [4763] EoP MS ME UWS – A security-disabled universal group was deleted
- [4764] EoP MS ME UWS – A groups type was changed
- [4765] EoP MS ME UWS – SID History was added to an account
- [4766] EoP MS ME UWS – An attempt to add SID History to an account failed
- [4767] EoP MS ME UWS – A user account was unlocked
- [4768] EoP MS ME UWS – A Kerberos authentication ticket (TGT) was requested
- [4769] EoP MS ME UWS – A Kerberos service ticket was requested
- [4770] EoP MS ME UWS – A Kerberos service ticket was renewed
- [4771] EoP MS ME UWS – Kerberos pre-authentication failed
- [4772] EoP MS ME UWS – A Kerberos authentication ticket request failed
- [4773] EoP MS ME UWS – A Kerberos service ticket request failed
- [4774] EoP MS ME UWS – An account was mapped for logon
- [4775] EoP MS ME UWS – An account could not be mapped for logon
- [4776] EoP MS ME UWS – The domain controller attempted to validate the credentials for an account
- [4777] EoP MS ME UWS – The domain controller failed to validate the credentials for an account
- [4778] EoP MS ME UWS – A session was reconnected to a Window Station
- [4779] EoP MS ME UWS – A session was disconnected from a Window Station
- [4780] EoP MS ME UWS – The ACL was set on accounts which are members of administrators groups
- [4781] EoP MS ME UWS – The name of an account was changed
- [4782] EoP MS ME UWS – The password hash an account was accessed
- [4783] EoP MS ME UWS – A basic application group was created
- [4784] EoP MS ME UWS – A basic application group was changed
- [4785] EoP MS ME UWS – A member was added to a basic application group
- [4786] EoP MS ME UWS – A member was removed from a basic application group
- [4787] EoP MS ME UWS – A non-member was added to a basic application group
- [4788] EoP MS ME UWS – A non-member was removed from a basic application group..
- [4789] EoP MS ME UWS – A basic application group was deleted
- [4790] EoP MS ME UWS – An LDAP query group was created
- [4791] EoP MS ME UWS – A basic application group was changed
- [4792] EoP MS ME UWS – An LDAP query group was deleted
- [4793] EoP MS ME UWS – The Password Policy Checking API was called
- [4794] EoP MS ME UWS – An attempt was made to set the Directory Services Restore Mode administrator password
- [4797] EoP MS ME UWS – An attempt was made to query the existence of a blank password for an account
- [4798] EoP MS ME UWS – A user’s local group membership was enumerated.
- [4799] EoP MS ME UWS – A security-enabled local group membership was enumerated
- [4800] EoP MS ME UWS – The workstation was locked
- [4801] EoP MS ME UWS – The workstation was unlocked
- [4802] EoP MS ME UWS – The screen saver was invoked
- [4803] EoP MS ME UWS – The screen saver was dismissed
- [4816] EoP MS ME UWS – RPC detected an integrity violation while decrypting an incoming message
- [4817] EoP MS ME UWS – Auditing settings on object were changed.
- [4818] EoP MS ME UWS – Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy
- [4819] EoP MS ME UWS – Central Access Policies on the machine have been changed
- [4820] EoP MS ME UWS – A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions
- [4821] EoP MS ME UWS – A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions
- [4822] EoP MS ME UWS – NTLM authentication failed because the account was a member of the Protected User group
- [4823] EoP MS ME UWS – NTLM authentication failed because access control restrictions are required
- [4824] EoP MS ME UWS – Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group
- [4825] EoP MS ME UWS – A user was denied the access to Remote Desktop. By default, users are allowed to connect only if they are members of the Remote Desktop Users group or Administrators group
- [4826] EoP MS ME UWS – Boot Configuration Data loaded
- [4830] EoP MS ME UWS – SID History was removed from an account
- [4864] EoP MS ME UWS – A namespace collision was detected
- [4865] EoP MS ME UWS – A trusted forest information entry was added
- [4866] EoP MS ME UWS – A trusted forest information entry was removed
- [4867] EoP MS ME UWS – A trusted forest information entry was modified
- [4868] EoP MS ME UWS – The certificate manager denied a pending certificate request
- [4869] EoP MS ME UWS – Certificate Services received a resubmitted certificate request
- [4870] EoP MS ME UWS – Certificate Services revoked a certificate
- [4871] EoP MS ME UWS – Certificate Services received a request to publish the certificate revocation list (CRL)
- [4872] EoP MS ME UWS – Certificate Services published the certificate revocation list (CRL)
- [4873] EoP MS ME UWS – A certificate request extension changed
- [4874] EoP MS ME UWS – One or more certificate request attributes changed.
- [4875] EoP MS ME UWS – Certificate Services received a request to shut down
- [4876] EoP MS ME UWS – Certificate Services backup started
- [4877] EoP MS ME UWS – Certificate Services backup completed
- [4878] EoP MS ME UWS – Certificate Services restore started
- [4879] EoP MS ME UWS – Certificate Services restore completed
- [4880] EoP MS ME UWS – Certificate Services started
- [4881] EoP MS ME UWS – Certificate Services stopped
- [4882] EoP MS ME UWS – The security permissions for Certificate Services changed
- [4883] EoP MS ME UWS – Certificate Services retrieved an archived key
- [4884] EoP MS ME UWS – Certificate Services imported a certificate into its database
- [4885] EoP MS ME UWS – The audit filter for Certificate Services changed
- [4886] EoP MS ME UWS – Certificate Services received a certificate request
- [4887] EoP MS ME UWS – Certificate Services approved a certificate request and issued a certificate
- [4888] EoP MS ME UWS – Certificate Services denied a certificate request
- [4889] EoP MS ME UWS – Certificate Services set the status of a certificate request to pending
- [4890] EoP MS ME UWS – The certificate manager settings for Certificate Services changed.
- [4891] EoP MS ME UWS – A configuration entry changed in Certificate Services
- [4892] EoP MS ME UWS – A property of Certificate Services changed
- [4893] EoP MS ME UWS – Certificate Services archived a key
- [4894] EoP MS ME UWS – Certificate Services imported and archived a key
- [4895] EoP MS ME UWS – Certificate Services published the CA certificate to Active Directory Domain Services
- [4896] EoP MS ME UWS – One or more rows have been deleted from the certificate database
- [4897] EoP MS ME UWS – Role separation enabled
- [4898] EoP MS ME UWS – Certificate Services loaded a template
- [4899] EoP MS ME UWS – A Certificate Services template was updated
- [4900] EoP MS ME UWS – Certificate Services template security was updated
- [4902] EoP MS ME UWS – The Per-user audit policy table was created
- [4904] EoP MS ME UWS – An attempt was made to register a security event source
- [4905] EoP MS ME UWS – An attempt was made to unregister a security event source
- [4906] EoP MS ME UWS – The CrashOnAuditFail value has changed
- [4907] EoP MS ME UWS – Auditing settings on object were changed
- [4908] EoP MS ME UWS – Special Groups Logon table modified
- [4909] EoP MS ME UWS – The local policy settings for the TBS were changed
- [4910] EoP MS ME UWS – The group policy settings for the TBS were changed
- [4911] EoP MS ME UWS – Resource attributes of the object were changed
- [4912] EoP MS ME UWS – Per User Audit Policy was changed
- [4913] EoP MS ME UWS – Central Access Policy on the object was changed
- [4928] EoP MS ME UWS – An Active Directory replica source naming context was established
- [4929] EoP MS ME UWS – An Active Directory replica source naming context was removed
- [4930] EoP MS ME UWS – An Active Directory replica source naming context was modified
- [4931] EoP MS ME UWS – An Active Directory replica destination naming context was modified
- [4932] EoP MS ME UWS – Synchronization of a replica of an Active Directory naming context has begun
- [4933] EoP MS ME UWS – Synchronization of a replica of an Active Directory naming context has ended
- [4934] EoP MS ME UWS – Attributes of an Active Directory object were replicated
- [4935] EoP MS ME UWS – Replication failure begins
- [4936] EoP MS ME UWS – Replication failure ends
- [4937] EoP MS ME UWS – A lingering object was removed from a replica
- [4944] EoP MS ME UWS – The following policy was active when the Windows Firewall started
- [4945] EoP MS ME UWS – A rule was listed when the Windows Firewall started
- [4946] EoP MS ME UWS – A change has been made to Windows Firewall exception list. A rule was added
- [4947] EoP MS ME UWS – A change has been made to Windows Firewall exception list. A rule was modified
- [4948] EoP MS ME UWS – A change has been made to Windows Firewall exception list. A rule was deleted
- [4949] EoP MS ME UWS – Windows Firewall settings were restored to the default values
- [4950] EoP MS ME UWS – A Windows Firewall setting has changed
- [4951] EoP MS ME UWS – A rule has been ignored because its major version number was not recognized by Windows Firewall
- [4952] EoP MS ME UWS – Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall
- [4953] EoP MS ME UWS – A rule has been ignored by Windows Firewall because it could not parse the rule
- [4954] EoP MS ME UWS – Windows Firewall Group Policy settings has changed. The new settings have been applied
- [4956] EoP MS ME UWS – Windows Firewall has changed the active profile
- [4957] EoP MS ME UWS – Windows Firewall did not apply the following rule
- [4958] EoP MS ME UWS – Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer
- [4960] EoP MS ME UWS – IPsec dropped an inbound packet that failed an integrity check
- [4961] EoP MS ME UWS – IPsec dropped an inbound packet that failed a replay check
- [4962] EoP MS ME UWS – IPsec dropped an inbound packet that failed a replay check
- [4963] EoP MS ME UWS – IPsec dropped an inbound clear text packet that should have been secured
- [4964] EoP MS ME UWS – Special groups have been assigned to a new logon
- [4965] EoP MS ME UWS – IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI).
- [4976] EoP MS ME UWS – During Main Mode negotiation, IPsec received an invalid negotiation packet.
- [4977] EoP MS ME UWS – During Quick Mode negotiation, IPsec received an invalid negotiation packet.
- [4978] EoP MS ME UWS – During Extended Mode negotiation, IPsec received an invalid negotiation packet.
- [4979] EoP MS ME UWS – IPsec Main Mode and Extended Mode security associations were established.
- [4980] EoP MS ME UWS – IPsec Main Mode and Extended Mode security associations were established
- [4981] EoP MS ME UWS – IPsec Main Mode and Extended Mode security associations were established
- [4982] EoP MS ME UWS – IPsec Main Mode and Extended Mode security associations were established
- [4983] EoP MS ME UWS – An IPsec Extended Mode negotiation failed
- [4984] EoP MS ME UWS – An IPsec Extended Mode negotiation failed
- [4985] EoP MS ME UWS – The state of a transaction has changed
- [5024] EoP MS ME UWS – The Windows Firewall Service has started successfully
- [5025] EoP MS ME UWS – The Windows Firewall Service has been stopped
- [5027] EoP MS ME UWS – The Windows Firewall Service was unable to retrieve the security policy from the local storage
- [5028] EoP MS ME UWS – The Windows Firewall Service was unable to parse the new security policy.
- [5029] EoP MS ME UWS – The Windows Firewall Service failed to initialize the driver
- [5030] EoP MS ME UWS – The Windows Firewall Service failed to start
- [5031] EoP MS ME UWS – The Windows Firewall Service blocked an application from accepting incoming connections on the network.
- [5032] EoP MS ME UWS – Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network
- [5033] EoP MS ME UWS – The Windows Firewall Driver has started successfully
- [5034] EoP MS ME UWS – The Windows Firewall Driver has been stopped
- [5035] EoP MS ME UWS – The Windows Firewall Driver failed to start
- [5037] EoP MS ME UWS – The Windows Firewall Driver detected critical runtime error. Terminating
- [5038] EoP MS ME UWS – Code integrity determined that the image hash of a file is not valid
- [5039] EoP MS ME UWS – A registry key was virtualized.
- [5040] EoP MS ME UWS – A change has been made to IPsec settings. An Authentication Set was added.
- [5041] EoP MS ME UWS – A change has been made to IPsec settings. An Authentication Set was modified
- [5042] EoP MS ME UWS – A change has been made to IPsec settings. An Authentication Set was deleted
- [5043] EoP MS ME UWS – A change has been made to IPsec settings. A Connection Security Rule was added
- [5044] EoP MS ME UWS – A change has been made to IPsec settings. A Connection Security Rule was modified
- [5045] EoP MS ME UWS – A change has been made to IPsec settings. A Connection Security Rule was deleted
- [5046] EoP MS ME UWS – A change has been made to IPsec settings. A Crypto Set was added
- [5047] EoP MS ME UWS – A change has been made to IPsec settings. A Crypto Set was modified
- [5048] EoP MS ME UWS – A change has been made to IPsec settings. A Crypto Set was deleted
- [5049] EoP MS ME UWS – An IPsec Security Association was deleted
- [5050] EoP MS ME UWS – An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE
- [5051] EoP MS ME UWS – A file was virtualized
- [5056] EoP MS ME UWS – A cryptographic self test was performed
- [5057] EoP MS ME UWS – A cryptographic primitive operation failed
- [5058] EoP MS ME UWS – Key file operation
- [5059] EoP MS ME UWS – Key migration operation
- [5060] EoP MS ME UWS – Verification operation failed
- [5061] EoP MS ME UWS – Cryptographic operation
- [5062] EoP MS ME UWS – A kernel-mode cryptographic self test was performed
- [5063] EoP MS ME UWS – A cryptographic provider operation was attempted
- [5064] EoP MS ME UWS – A cryptographic context operation was attempted
- [5065] EoP MS ME UWS – A cryptographic context modification was attempted
- [5066] EoP MS ME UWS – A cryptographic function operation was attempted
- [5067] EoP MS ME UWS – A cryptographic function modification was attempted
- [5068] EoP MS ME UWS – A cryptographic function provider operation was attempted
- [5069] EoP MS ME UWS – A cryptographic function property operation was attempted
- [5070] EoP MS ME UWS – A cryptographic function property operation was attempted
- [5071] EoP MS ME UWS – Key access denied by Microsoft key distribution service
- [5120] EoP MS ME UWS – OCSP Responder Service Started
- [5121] EoP MS ME UWS – OCSP Responder Service Stopped
- [5122] EoP MS ME UWS – A Configuration entry changed in the OCSP Responder Service
- [5123] EoP MS ME UWS – A configuration entry changed in the OCSP Responder Service
- [5124] EoP MS ME UWS – A security setting was updated on OCSP Responder Service
- [5125] EoP MS ME UWS – A request was submitted to OCSP Responder Service
- [5126] EoP MS ME UWS – Signing Certificate was automatically updated by the OCSP Responder Service
- [5127] EoP MS ME UWS – The OCSP Revocation Provider successfully updated the revocation information
- [5136] EoP MS ME UWS – A directory service object was modified
- [5137] EoP MS ME UWS – A directory service object was created
- [5138] EoP MS ME UWS – A directory service object was undeleted
- [5139] EoP MS ME UWS – A directory service object was moved
- [5140] EoP MS ME UWS – A network share object was accessed
- [5141] EoP MS ME UWS – A directory service object was deleted
- [5142] EoP MS ME UWS – A network share object was added.
- [5143] EoP MS ME UWS – A network share object was modified
- [5144] EoP MS ME UWS – A network share object was deleted.
- [5145] EoP MS ME UWS – A network share object was checked to see whether client can be granted desired access
- [5146] EoP MS ME UWS – The Windows Filtering Platform has blocked a packet
- [5147] EoP MS ME UWS – A more restrictive Windows Filtering Platform filter has blocked a packet
- [5148] EoP MS ME UWS – The Windows Filtering Platform has detected a DoS attack and entered a defensive mode
- [5149] EoP MS ME UWS – The DoS attack has subsided and normal processing is being resumed.
- [5150] EoP MS ME UWS – The Windows Filtering Platform has blocked a packet.
- [5151] EoP MS ME UWS – A more restrictive Windows Filtering Platform filter has blocked a packet.
- [5152] EoP MS ME UWS – The Windows Filtering Platform blocked a packet
- [5153] EoP MS ME UWS – A more restrictive Windows Filtering Platform filter has blocked a packet
- [5154] EoP MS ME UWS – The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections
- [5155] EoP MS ME UWS – The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections
- [5156] EoP MS ME UWS – The Windows Filtering Platform has allowed a connection
- [5157] EoP MS ME UWS – The Windows Filtering Platform has blocked a connection
- [5158] EoP MS ME UWS – The Windows Filtering Platform has permitted a bind to a local port
- [5159] EoP MS ME UWS – The Windows Filtering Platform has blocked a bind to a local port
- [5168] EoP MS ME UWS – Spn check for SMB/SMB2 fails.
- [5169] EoP MS ME UWS – A directory service object was modified
- [5170] EoP MS ME UWS – A directory service object was modified during a background cleanup task
- [5376] EoP MS ME UWS – Credential Manager credentials were backed up
- [5377] EoP MS ME UWS – Credential Manager credentials were restored from a backup
- [5378] EoP MS ME UWS – The requested credentials delegation was disallowed by policy
- [5379] EoP MS ME UWS – Credential Manager credentials were read
- [5380] EoP MS ME UWS – Vault Find Credential
- [5381] EoP MS ME UWS – Vault credentials were read
- [5382] EoP MS ME UWS – Vault credentials were read
- [5440] EoP MS ME UWS – The following callout was present when the Windows Filtering Platform Base Filtering Engine started
- [5441] EoP MS ME UWS – The following filter was present when the Windows Filtering Platform Base Filtering Engine started
- [5442] EoP MS ME UWS – The following provider was present when the Windows Filtering Platform Base Filtering Engine started
- [5443] EoP MS ME UWS – The following provider context was present when the Windows Filtering Platform Base Filtering Engine started
- [5444] EoP MS ME UWS – The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started
- [5446] EoP MS ME UWS – A Windows Filtering Platform callout has been changed
- [5447] EoP MS ME UWS – A Windows Filtering Platform filter has been changed
- [5448] EoP MS ME UWS – A Windows Filtering Platform provider has been changed
- [5449] EoP MS ME UWS – A Windows Filtering Platform provider context has been changed
- [5450] EoP MS ME UWS – A Windows Filtering Platform sub-layer has been changed
- [5451] EoP MS ME UWS – An IPsec Quick Mode security association was established
- [5452] EoP MS ME UWS – An IPsec Quick Mode security association ended
- [5453] EoP MS ME UWS – An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started
- [5456] EoP MS ME UWS – PAStore Engine applied Active Directory storage IPsec policy on the computer
- [5457] EoP MS ME UWS – PAStore Engine failed to apply Active Directory storage IPsec policy on the computer
- [5458] EoP MS ME UWS – PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer
- [5459] EoP MS ME UWS – PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer
- [5460] EoP MS ME UWS – PAStore Engine applied local registry storage IPsec policy on the computer
- [5461] EoP MS ME UWS – PAStore Engine failed to apply local registry storage IPsec policy on the computer
- [5462] EoP MS ME UWS – PAStore Engine failed to apply some rules of the active IPsec policy on the computer
- [5463] EoP MS ME UWS – PAStore Engine polled for changes to the active IPsec policy and detected no changes
- [5464] EoP MS ME UWS – PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services
- [5465] EoP MS ME UWS – PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully
- [5466] EoP MS ME UWS – PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead
- [5467] EoP MS ME UWS – PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy
- [5468] EoP MS ME UWS – PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes
- [5471] EoP MS ME UWS – PAStore Engine loaded local storage IPsec policy on the computer
- [5472] EoP MS ME UWS – PAStore Engine failed to load local storage IPsec policy on the computer
- [5473] EoP MS ME UWS – PAStore Engine loaded directory storage IPsec policy on the computer
- [5474] EoP MS ME UWS – PAStore Engine failed to load directory storage IPsec policy on the computer
- [5477] EoP MS ME UWS – PAStore Engine failed to add quick mode filter
- [5478] EoP MS ME UWS – IPsec Services has started successfully
- [5479] EoP MS ME UWS – IPsec Services has been shut down successfully
- [5480] EoP MS ME UWS – IPsec Services failed to get the complete list of network interfaces on the computer
- [5483] EoP MS ME UWS – IPsec Services failed to initialize RPC server. IPsec Services could not be started
- [5484] EoP MS ME UWS – IPsec Services has experienced a critical failure and has been shut down
- [5485] EoP MS ME UWS – IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces
- [5632] EoP MS ME UWS – A request was made to authenticate to a wireless network
- [5633] EoP MS ME UWS – A request was made to authenticate to a wired network
- [5712] EoP MS ME UWS – A Remote Procedure Call (RPC) was attempted
- [5888] EoP MS ME UWS – An object in the COM+ Catalog was modified
- [5889] EoP MS ME UWS – An object was deleted from the COM+ Catalog
- [5890] EoP MS ME UWS – An object was added to the COM+ Catalog
- [6144] EoP MS ME UWS – Security policy in the group policy objects has been applied successfully
- [6145] EoP MS ME UWS – One or more errors occured while processing security policy in the group policy objects
- [6272] EoP MS ME UWS – Network Policy Server granted access to a user
- [6273] EoP MS ME UWS – Network Policy Server denied access to a user
- [6274] EoP MS ME UWS – Network Policy Server discarded the request for a user
- [6275] EoP MS ME UWS – Network Policy Server discarded the accounting request for a user
- [6276] EoP MS ME UWS – Network Policy Server quarantined a user
- [6277] EoP MS ME UWS – Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy
- [6278] EoP MS ME UWS – Network Policy Server granted full access to a user because the host met the defined health policy
- [6279] EoP MS ME UWS – Network Policy Server locked the user account due to repeated failed authentication attempts
- [6280] EoP MS ME UWS – Network Policy Server unlocked the user account
- [6281] EoP MS ME UWS – Code Integrity determined that the page hashes of an image file are not valid…
- [6400] EoP MS ME UWS – BranchCache: Received an incorrectly formatted response while discovering availability of content.
- [6401] EoP MS ME UWS – BranchCache: Received invalid data from a peer. Data discarded.
- [6402] EoP MS ME UWS – BranchCache: The message to the hosted cache offering it data is incorrectly formatted.
- [6403] EoP MS ME UWS – BranchCache: The hosted cache sent an incorrectly formatted response to the client’s message to offer it data.
- [6404] EoP MS ME UWS – BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.
- [6405] EoP MS ME UWS – BranchCache: %2 instance(s) of event id %1 occurred.
- [6406] EoP MS ME UWS – %1 registered to Windows Firewall to control filtering for the following:
- [6407] EoP MS ME UWS – %1
- [6408] EoP MS ME UWS – Registered product %1 failed and Windows Firewall is now controlling the filtering for %2.
- [6409] EoP MS ME UWS – BranchCache: A service connection point object could not be parsed
- [6410] EoP MS ME UWS – Code integrity determined that a file does not meet the security requirements to load into a process. This could be due to the use of shared sections or other issues
- [6416] EoP MS ME UWS – A new external device was recognized by the system.
- [6417] EoP MS ME UWS – The FIPS mode crypto selftests succeeded
- [6418] EoP MS ME UWS – The FIPS mode crypto selftests failed
- [6419] EoP MS ME UWS – A request was made to disable a device
- [6420] EoP MS ME UWS – A device was disabled
- [6421] EoP MS ME UWS – A request was made to enable a device
- [6422] EoP MS ME UWS – A device was enabled
- [6423] EoP MS ME UWS – The installation of this device is forbidden by system policy
- [6424] EoP MS ME UWS – The installation of this device was allowed, after having previously been forbidden by policy
- [8191] EoP MS ME UWS – Highest System-Defined Audit Message Value