AD FS

562 events across 2 channels

Event IDTitleChannel
100The Federation Service started successfully.Admin
100Unknown
102There was an error in enabling endpoints of Federation Service.Admin
102Unknown
103The Federation Service stopped successfully.Admin
103Unknown
104The artifact resolution service is not running.Admin
104Unknown
105An error occurred loading an authentication provider.Admin
105Unknown
106An authentication provider was successfully loaded: Identifier: …Admin
106Unknown
111The Federation Service encountered an error while processing the WS-Trust …Admin
111Unknown
131During processing of the Federation Service configuration, the element 'data1' …Admin
131Unknown
132During processing of the Federation Service configuration, the required element …Admin
132Unknown
133During processing of the Federation Service configuration, the element 'data1' …Admin
133Unknown
134During processing of the Federation Service configuration, the element 'data1' …Admin
134Unknown
135During processing of the Federation Service configuration, the element 'data1' …Admin
135Unknown
136During processing of the Federation Service configuration, the Federation …Admin
136Unknown
143The Federation Service was unable to create the federation metadata document as …Admin
143Unknown
144The Federation Service Proxy blocked an illegitimate request made by a client, …Admin
144Unknown
147A token was received from a claims provider identified by the key 'data1', but …Admin
147Unknown
149During processing of the Federation Service configuration, the attribute store …Admin
149Unknown
155The Federation Service was unable to listen at 'data1' for metadata document …Admin
155Unknown
156Trust monitoring cycle initiated.Admin
156Unknown
157Trust monitoring cycle completed.Admin
157Unknown
159The Federation Service encountered an error while writing to the following …Admin
159Unknown
163An error occurred during initialization of trust monitoring.Admin
163Unknown
164An error occurred during a read operation from the configuration database.Admin
164Unknown
165An error occurred during trust monitoring.Admin
165Unknown
166Trust monitoring service encountered an error while parsing the metadata …Admin
166Unknown
167Trust monitoring service encountered an error while applying the data in the …Admin
167Unknown
168The Federation Service encountered an error while retrieving the federation …Admin
168Unknown
171The trust monitoring service automatically updated the trust of 'data1' …Admin
171Unknown
173The trust monitoring service automatically updated the trust of 'data1' …Admin
173Unknown
174Trust monitoring service detected changes in policy of 'data1', but did not …Admin
174Unknown
180An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version …Admin
180Unknown
181AD FS could not enable the new KDFv2 feature automatically because of missing …Admin
181Unknown
182AD FS enabled the new KDFv2 feature successfully.Admin
182Unknown
183KDFv2 feature is disabled on AD FS farm.Admin
183Unknown
184A token request was received for a relying party identified by the key 'data1', …Admin
184Unknown
186The Federation Service could not fulfill the token-issuance request.Admin
186Unknown
187AD FS server received a JWT token without nonce in the assertion and it was …Admin
187Unknown
188AD FS server is not configured to reject JWT tokens that did not have nonce in …Admin
188Unknown
189AD FS server received an OAuth authorization request in the device code flow …Admin
189Unknown
193The Federation Service could not satisfy a token request because the relying …Admin
193Unknown
197The Federation Service could not satisfy a token request because the …Admin
197Unknown
198The federation server proxy started successfully.Admin
198Unknown
199The federation server proxy could not be started.Admin
199Unknown
200The federation server proxy stopped successfully.Admin
200Unknown
201The Federation Service data1 encountered an Access Denied error while trying to …Admin
201Unknown
202The Federation Service data1 could not be opened.Admin
202Unknown
203The Federation Service data1 could not be shut down properly.Admin
203Unknown
204The Federation Service data1 could not be closed.Admin
204Unknown
206The Federation Service could not fulfill the token-issuance request because the …Admin
206Unknown
207An attempt to write to the Security event log failed.Admin
207Unknown
208An error occurred during an attempt to register the event source for the …Admin
208Unknown
209The Security log event source for the Federation Service could not be …Admin
209Unknown
215The Federation Service at 'data1' did not return any WS-Trust endpoints to be …Admin
215Unknown
217A WS-Trust endpoint that was configured could not be opened.Admin
217Unknown
218The federation server proxy received error code 'data2' while making a request …Admin
218Unknown
220The Federation Service configuration could not be loaded correctly from the AD …Admin
220Unknown
221A change to the token service configuration was detected, but there was an error …Admin
221Unknown
222The federation server proxy was unable to complete a request to the Federation …Admin
222Unknown
223Claim description could not be loaded correctly from the database.Admin
223Unknown
224The federation server proxy configuration could not be updated with the latest …Admin
224Unknown
225A change to the service configuration was detected, but there was an error …Admin
225Unknown
230The federation server proxy has detected congestion, caused by high latency …Admin
230Unknown
238The Federation Service failed to find a domain controller for the domain data1.Admin
238Unknown
244The Federation Service was unable to listen at 'data1' for WS-MetadataExchange …Admin
244Unknown
245The federation server proxy successfully retrieved and updated its configuration …Admin
245Unknown
246The Federation Service encountered an error during an attempt to connect to a …Admin
246Unknown
247The Federation Service encountered an error while connecting to a global catalog …Admin
247Unknown
248The federation server proxy was not able to retrieve the list of endpoints from …Admin
248Unknown
249The certificate identified by thumbprint 'data1' could not be found in the …Admin
249Unknown
250Expiration of the artifact failed.Admin
250Unknown
251Attribute store 'Event.EventData' is loaded successfully.Admin
251Unknown
252The AD FS proxy service made changes to the endpoints it is listening on based …Admin
252Unknown
253AD FS proxy service failed to start a listener for the endpoint 'data1'.Admin
253Unknown
258The relying party 'data1' is not configured with SAML Assertion Consumer …Admin
258Unknown
259The request specified an Assertion Consumer Service index 'data1' that is not …Admin
259Unknown
260The request specified an Assertion Consumer Service protocol binding 'data1' …Admin
260Unknown
261The request specified an Assertion Consumer Service URL 'data1' that is not …Admin
261Unknown
262The artifact resolution request failed.Admin
262Unknown
273The request specified an assertion consumer service that is not configured or …Admin
273Unknown
274The federation server proxy encountered an error while trying to listen on one …Admin
274Unknown
275The federation server proxy could not establish a trust relationship for the SSL …Admin
275Unknown
276The federation server proxy was not able to authenticate to the Federation …Admin
276Unknown
277The Federation Service encountered an unexpected exception and has shut down.Admin
277Unknown
278The SAML artifact resolution endpoint is not configured or it is disabled.Admin
278Unknown
279Unable to find a claims provider trust for SAML artifact resolution in the AD FS …Admin
279Unknown
280Unable to resolve the SAML artifact from the claims provider because the claims …Admin
280Unknown
281Unable to resolve the SAML artifact from the claims provider because the claims …Admin
281Unknown
283Unable to resolve the SAML artifact.Admin
283Unknown
284Unable to resolve the SAML artifact.Admin
284Unknown
285The SAML artifact was resolved, but the response is empty or does not contain …Admin
285Unknown
286Cannot connect to the artifact database.Admin
286Unknown
287Cannot add the artifact to the artifact database.Admin
287Unknown
288Cannot get the artifact from storage.Admin
288Unknown
289Cannot remove the artifact from storage.Admin
289Unknown
290Cannot set expiration for the artifacts in storage.Admin
290Unknown
291The artifact resolution service could not be started.Admin
291Unknown
293A SAML request for the required artifact was rejected because the artifact …Admin
293Unknown
294The SAML artifact resolution request specified an issuer that is not configured …Admin
294Unknown
297The SAML artifact resolution request required an artifact resolution service …Admin
297Unknown
298The Windows Hello for Business key receipt certificate background task will not …Admin
298Unknown
302The Federation Service could not authorize token issuance for caller 'data2' as …Admin
302Unknown
303The Federation Service encountered an error while processing the SAML …Admin
303Unknown
305The Federation Service encountered an error while querying a LDAP server at …Admin
305Unknown
306The Federation Service encountered an error while querying a global catalog …Admin
306Unknown
311An attempt to update AD FS performance counters failed.Admin
311Unknown
315An error occurred during an attempt to build the certificate chain for the …Admin
315Unknown
316An error occurred during an attempt to build the certificate chain for the …Admin
316Unknown
317An error occurred during an attempt to build the certificate chain for the …Admin
317Unknown
319An error occurred while the certificate chain for the client certificate …Admin
319Unknown
320The verification of the SAML message signature failed.Admin
320Unknown
321The SAML authentication request had a NameID Policy that could not be satisfied.Admin
321Unknown
323The Federation Service could not authorize token issuance for the caller 'data2' …Admin
323Unknown
325The Federation Service could not authorize token issuance for caller 'data1'.Admin
325Unknown
326Failed to load the AD FS claims policy engine using policy type 'data1' User …Admin
326Unknown
327An error occurred during processing of the SAML logout request.Admin
327Unknown
328The SAML artifact resolution request was resolved, but the response does not …Admin
328Unknown
329The certificate that is identified by thumbprint 'data1' could not be decrypted …Admin
329Unknown
331The certificate management service encountered an error during decryption of the …Admin
331Unknown
332The certificate management service encountered an error during encryption of the …Admin
332Unknown
333The certificate management service encountered an error during database access.Admin
333Unknown
334Certificate rollover service needs to rollover data1 certificates urgently.Admin
334Unknown
335Admin
335Unknown
336The certificate management cycle was initiated.Admin
336Unknown
337The certificate management cycle was completed.Admin
337Unknown
338An error was encountered during certificate rollover.Admin
338Unknown
339An error occurred during initialization of certificate rollover.Admin
339Unknown
341The NotBefore attribute for the token has a value that is set to a future time.Admin
341Unknown
342Token validation failed.Admin
342Unknown
343There was an error during initialization of synchronization.Admin
343Unknown
344There was an error doing synchronization.Admin
344Unknown
345There was a communication error during AD FS configuration database …Admin
345Unknown
346There was an error during retrieving the configuration data for the secondary …Admin
346Unknown
348Synchronization of configuration data from the primary federation server 'data1' …Admin
348Unknown
349The administration service for the Federation Service started successfully.Admin
349Unknown
351There was an error getting synchronization properties.Admin
351Unknown
352A SQL operation in the AD FS configuration database with connection string …Admin
352Unknown
353Unable to resolve the SAML artifact.Admin
353Unknown
354The artifact resolution service could not verify the request signature.Admin
354Unknown
356Failed to register notification to the SQL database with the connection string …Admin
356Unknown
357Successfully registered notification to the SQL database with the connection …Admin
357Unknown
358Restarting Event.EventData.Admin
358Unknown
359An error occurred during an attempt to restart data1.Admin
359Unknown
360A request was made to a certificate transport endpoint, but the request did not …Admin
360Unknown
362Encountered error during federation passive sign-out.Admin
362Unknown
363A communication error occurred during an attempt to get a token from the …Admin
363Unknown
364Encountered error during federation passive request.Admin
364Unknown
365A token request was received for the relying party 'data1', but the request …Admin
365Unknown
366A token was received from claims provider 'data1', but the token could not be …Admin
366Unknown
367The audience restriction was not valid because the specified audience identifier …Admin
367Unknown
368The SAML Single Logout request does not correspond to the logged-in session …Admin
368Unknown
369Processing TTP request failed with the following exception.Admin
369Unknown
370Incoming TTP response is not valid.Admin
370Unknown
371Cannot find certificate to validate message/token signature obtained from claims …Admin
371Unknown
372Authentication Failed.Admin
372Unknown
373The artifact request from the replying party is signed with a weaker signature …Admin
373Unknown
374An error occurred while building the certificate chain for the claims provider …Admin
374Unknown
375Policy store synchronization initiated.Admin
375Unknown
376An Error occurred while executing a query in SQL attribute store.Admin
376Unknown
377A processing error occurred in an attribute store.Admin
377Unknown
378SAML request is not signed with expected signature algorithm.Admin
378Unknown
379A security token was rejected as the specified IssueInstant was before the …Admin
379Unknown
380During processing of the Federation Service configuration, the element 'data1' …Admin
380Unknown
381An error occurred during an attempt to build the certificate chain for …Admin
381Unknown
382AD FS detected that the Federation Service has more than data1 data2 trusts …Admin
382Unknown
383The Web request failed because the web.Admin
383Unknown
384The request to the Federation Service failed because the web.Admin
384Unknown
385AD FS detected that one or more certificates in AD FS configuration database …Admin
385Unknown
386AD FS detected that none of the service certificates that are configured to be …Admin
386Unknown
387AD FS detected that one or more of the certificates specified in the Federation …Admin
387Unknown
388AD FS detected that all the service certificates have appropriate access given …Admin
388Unknown
389AD FS detected that one or more of your trusts require their certificates to be …Admin
389Unknown
390AD FS detected that none of the partner certificates that are configured to be …Admin
390Unknown
392The federation server proxy was able to successfully renew its trust with the …Admin
392Unknown
393The federation server proxy could not establish a trust with the Federation …Admin
393Unknown
394The federation server proxy could not renew its trust with the Federation …Admin
394Unknown
395The trust between the federation server proxy and the Federation Service was …Admin
395Unknown
396The trust between the federation server proxy and the Federation Service was …Admin
396Unknown
397The federation server loaded the HTTP proxy configuration from WinHTTP settings.Admin
397Unknown
398AD FS detected that one or more certificates in the AD FS configuration database …Admin
398Unknown
399AD FS detected that none of the service certificates that are configured to be …Admin
399Unknown
400VSS writer permissions have been granted to user data1.Admin
400Unknown
401VSS writer permissions have been revoked from user data1.Admin
401Unknown
402Failed to add some of the certificate claims.Admin
402Unknown
407Password change failed for following user.Admin
407Unknown
414An error occurred during processing of a token request.Admin
414Unknown
415Admin
415Unknown
416Web configuration error: data1.Admin
416Unknown
417Unable to add the certificate claim data1.Admin
417Unknown
418The trust between the federation server proxy and the Federation Service was …Admin
418Unknown
419Unable to renew the trust between the federation server proxy and the Federation …Admin
419Unknown
420The trust between the federation server proxy and the Federation Service was …Admin
420Unknown
421The trust between the federation server proxy and the Federation Service could …Admin
421Unknown
432Error handling request from proxy at data1.Admin
432Unknown
433Error encountered while renewing trust with the federation server proxy.Admin
433Unknown
434The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) …Admin
434Unknown
435The primary AD FS token signing certificate ( thumbprint data1 ) will expire at …Admin
435Unknown
436The primary AD FS token decryption certificate ( thumbprint data1 ) will expire …Admin
436Unknown
437Error encountered while checking for pending certificate rollovers.Admin
437Unknown
438Error encountered while checking rollover status of the AD FS certificate …Admin
438Unknown
439Error encountered while attempting to read an enrollment certificate from a …Admin
439Unknown
440A Certificate Authority Enrollment Certificate was found.Admin
440Unknown
441A token with a bad token binding key was found.Admin
441Unknown
442The CA enrollment certificate management cycle was initiated.Admin
442Unknown
443The CA enrollment certificate management cycle was completed.Admin
443Unknown
444Error encountered while checking status of the AD FS enrollment certificate.Admin
444Unknown
445A token with no binding was received on a request which is …Admin
445Unknown
446An SSO token with no binding was received on a request which is …Admin
446Unknown
447Error encountered while attempting to update the configuration policy for the …Admin
447Unknown
448Error encountered while attempting to add a leased task to the database.Admin
448Unknown
449Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask …Admin
449Unknown
450Error encountered while removing the expired items from the usercode cache.Admin
450Unknown
451Following nodes have the reported heartbeat older than data1 UTC and will be …Admin
451Unknown
452Admin
452Unknown
500More information for the event entry with Instance ID data1.Admin
500Unknown
501More information for the event entry with Instance ID Event.EventData.Admin
501Unknown
502More information for the event entry with Instance ID data1.Admin
502Unknown
503More information for the event entry with Instance ID data1.Admin
503Unknown
504The following update was successful to the application proxy store on the …Admin
504Unknown
505The following update attempt to the application proxy store on the federation …Admin
505Unknown
506The following update attempt to the application proxy relying party trust on the …Admin
506Unknown
507The following update attempt to the application proxy relying party trust on the …Admin
507Unknown
508The following update attempt to the relying party trust on the federation server …Admin
508Unknown
509The following update attempt to the relying party trust on the federation server …Admin
509Unknown
510More information for the event entry with Instance ID data1.Admin
510Unknown
511The incoming sign-in request is not allowed due to an invalid Federation Service …Admin
511Unknown
517The incoming sign-in request is not allowed due to an invalid Federation Service …Admin
517Unknown
521The request for the relying party token resulted in a failure.Admin
521Unknown
530AD FS could not read the local claims provider trusts from the AD FS …Admin
530Unknown
531AD FS could not read the local claims provider trusts from the AD FS …Admin
531Unknown
540The Federation Service was was unable to return the OAuth discovery document as …Admin
540Unknown
541An invalid value was found during processing of the proxy configuration data …Admin
541Unknown
542There was an error during heartbeat.Admin
542Unknown
543There was an error during heartbeat communicating to primary federation server.Admin
543Unknown
544Heartbeat is not performed because primary server does not support heartbeat.Admin
544Unknown
545Heartbeat is performed at primary server.Admin
545Unknown
546A current tenant certificate for Azure MFA was not found.Admin
546Unknown
547The tenant certificate for Azure MFA has been renewed.Admin
547Unknown
548The tenant certificate for Azure MFA will expire soon.Admin
548Unknown
549The tenant certificate for Azure MFA has expired.Admin
549Unknown
550The data1 primary certificate cannot be used because the KeySpec must have a …Admin
550Unknown
551An error occurred during processing of an OAuth logout request.Admin
551Unknown
552The session cookies were successfully deleted using the OAuth logout path.Admin
552Unknown
553The specified redirect URL was validated successfully.Admin
553Unknown
554The specified redirect URL did not match any of the OAuth client's redirect …Admin
554Unknown
555The Windows Hello for Business key receipt could not be verified.Admin
555Unknown
556Error encountered while attempting to select a master node for the account …Admin
556Unknown
557An error occured while trying to communicate with the account store rest service …Admin
557Unknown
558Syncronization of the Account Activity data failed.Admin
558Unknown
559Device authentication using PKeyAuth failed.Admin
559Unknown
560User data1 could not be found in the account database.Admin
560Unknown
561Authorization failed when connecting to the account store endpoint on server …Admin
561Unknown
562An error occurred when communcating with the account store endpoint on server …Admin
562Unknown
563An error occurred while calculating extranet lockout status.Admin
563Unknown
564The banned IP list found in Microsoft.Admin
564Unknown
565An error occurred while attemtping to update the database schema for Adfs smart …Admin
565Unknown
566An error occurred during processing of an OAuth device code request.Admin
566Unknown
568An error occurred during processing of an OAuth device auth request with the …Admin
568Unknown
570Active Directory trust enumeration was unable to enumerate one of more domains …Admin
570Unknown
571Enumeration of the Active Directory domains failed.Admin
571Unknown
572The Active Directory suffix from this username is not trusted by this ADFS …Admin
572Unknown
573The following error was generated by a threat detection module.Admin
573Unknown
574A threat detection module failed to load.Admin
574Unknown
575The following threat detection module was successfully loaded.Admin
575Unknown
576An unexpected error was returned from a threat detection module.Admin
576Unknown
1000An error occurred during processing of a token request.Admin
1000Unknown
1020Encountered error during OAuth authorization request.Admin
1020Unknown
1021Encountered error during OAuth token request.Admin
1021Unknown
1080An error occurred while processing WebFinger request.Admin
1080Unknown
1100The Federation Service could not authorize a request to one of the REST …Admin
1100Unknown
1109The Federation Service failed to connect to the LDAP account store to …Admin
1109Unknown
1110The Federation Service failed to connect to the primary LDAP account store to …Admin
1110Unknown
1111The Federation Service failed to connect to all LDAP account stores to …Admin
1111Unknown
1112The Federation Service failed to connect to the Ldap server.Admin
1112Unknown
1113Client Json Web Key Set (JWKS) synchronization initiated.Admin
1113Unknown
1114Client Json Web Key Set (JWKS) synchronization completed.Admin
1114Unknown
1115The Federation Service encountered an error while retrieving the Json Web Key …Admin
1115Unknown
1116An error occurred during a read operation from the configuration database.Admin
1116Unknown
1117An error occurred during monitoring of the following client's Json Web Key Set …Admin
1117Unknown
1118An error occurred during monitoring of clients'Json Web Key Set (JWKS).Admin
1118Unknown
1130There was an error establishing or renewing the proxy trust.Admin
1130Unknown
1131There was an error establishing or renewing the trust between the proxy and STS.Admin
1131Unknown

Event ID 100 — The Federation Service started successfully.

Provider
AD FS
Channel
Admin
Level
Informational

Description

The Federation Service started successfully. The following service hosts have been added.

Message #

The Federation Service started successfully. The following service hosts have been added: 
%1

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:54.297871+00:00",
    "event_record_id": 34,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Federation Server Proxy ServiceHost\r\nhttps://adfs.ludus.domain:443/adfs/services/proxytrustpolicystoretransfer\r\n\r\nMSIS0014: AD FS 1.x Trust Information Service\r\nhttps://adfs.ludus.domain/adfs/fs/federationserverservice.asmx\r\n\r\nIssuance ServiceHost\r\nhttp://localhost:80/adfs/services/trust/mexsoap\r\nhttps://adfs.ludus.domain:443/adfs/services/trust/proxymex/\r\n\r\nIssuance ServiceHost\r\nhttp://localhost/adfs/services/trust/proxymexsoap\r\nhttps://adfs.ludus.domain:443/adfs/services/trust/proxymex/\r\n\r\nIssuance ServiceHost\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/windowstransport\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/certificatemixed\r\nhttps://certauth.adfs.ludus.domain/adfs/services/trust/2005/certificatetransport\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/usernamemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/kerberosmixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/issuedtokenmixedasymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/issuedtokenmixedsymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/kerberosmixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/certificatemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/usernamemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/issuedtokenmixedasymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/issuedtokenmixedsymmetricbasic256\r\nnet.tcp://localhost/adfs/services/trusttcp/windows\r\n\r\nSAML Metadata\r\nhttps://adfs.ludus.domain/FederationMetadata/2007-06/\r\n\r\nOther endpoints\r\n\r\nhttp://+:80/adfs/users/\r\nhttps://+:443/adfs/oauth2/authorize/\r\nhttps://+:443/adfs/ls/\r\nhttps://+:443/adfs/oauth2/logout/\r\nhttps://+:443/adfs/oauth2/token/\r\nhttps://+:443/adfs/certauth/oauth2/authorize/\r\nhttps://+:443/adfs/certauth/\r\nhttps://+:443/adfs/oauth2/\r\nhttps://+:443/adfs/oauth2/deviceauth/\r\nhttp://+:80/adfs/deviceflowresult/\r\nhttp://+:80/adfs/artifact/\r\nhttps://+:443/adfs/discovery/\r\nhttps://+:443/adfs/.well-known/\r\nhttps://+:443/.well-known/webfinger/\r\nhttps://+:443/adfs/userinfo/\r\nhttps://+:443/adfs/Proxy/EstablishTrust/\r\nhttps://+:443/adfs/backendproxytls/\r\nhttps://+:443/adfs/Proxy/\r\nhttp://+:80/adfs/Proxy/PrimaryWriter/\r\nhttps://+:443/adfs/portal/\r\nhttp://+:80/adfs/probe/\r\n"
      }
    }
  },
  "message": ""
}

Event ID 100 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service started successfully. The following service hosts have been added.

Fields #

NameDescription
data1 UnicodeString

Event ID 102 — There was an error in enabling endpoints of Federation Service.

Provider
AD FS
Channel
Admin
Level
Error

Description

There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Message #

There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service. 

Additional Data 
Exception details: 
%1

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 102,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:11:11.158613+00:00",
    "event_record_id": 292,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 11500
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "System.ServiceModel.FaultException`1[Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault]: ADMIN0012: OperationFault (Fault Detail is equal to Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault)."
      }
    }
  },
  "message": ""
}

Event ID 102 —

Provider
AD FS
Channel
Unknown

Description

There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 103 — The Federation Service stopped successfully.

Provider
AD FS
Channel
Admin
Level
Informational

Description

The Federation Service stopped successfully.

Message #

The Federation Service stopped successfully.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 103,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:04:06.374579+00:00",
    "event_record_id": 36,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 103 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service stopped successfully.

Event ID 104 — The artifact resolution service is not running.

Provider
AD FS
Channel
Admin

Description

The artifact resolution service is not running. The service must be running to perform token replay detection.

Message #

The artifact resolution service is not running. The service must be running to perform token replay detection. 

User Action 
Make sure that the artifact resolution service is configured properly. Or disable token replay detection by using the Set-ADFSProperties cmdlet with the PreventTokenReplays parameter in Windows PowerShell for AD FS.

Event ID 104 —

Provider
AD FS
Channel
Unknown

Description

The artifact resolution service is not running. The service must be running to perform token replay detection.

Event ID 105 — An error occurred loading an authentication provider.

Provider
AD FS
Channel
Admin

Description

An error occurred loading an authentication provider. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Message #

An error occurred loading an authentication provider. Fix configuration errors using PowerShell cmdlets and restart the Federation Service. 
Identifier: %1 
Context: %2 

Additional Data 
Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 105 —

Provider
AD FS
Channel
Unknown

Description

An error occurred loading an authentication provider. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 106 — An authentication provider was successfully loaded: Identifier: 'Event.EventData', Context: 'data1'.

Provider
AD FS
Channel
Admin
Level
Informational

Description

An authentication provider was successfully loaded: Identifier: 'Event.EventData', Context: 'data1'.

Message #

An authentication provider was successfully loaded: Identifier: '%1', Context: '%2'

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 106,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:54.076793+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "FormsAuthentication",
          "Passive protocol pipeline"
        ]
      }
    }
  },
  "message": ""
}

Event ID 106 —

Provider
AD FS
Channel
Unknown

Description

An authentication provider was successfully loaded: Identifier: 'data1', Context: 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 111 — The Federation Service encountered an error while processing the WS-Trust request.

Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while processing the WS-Trust request.

Message #

The Federation Service encountered an error while processing the WS-Trust request. 
Request type: %1 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 111 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while processing the WS-Trust request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 131 — During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

Provider
AD FS
Channel
Admin

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The configured value 'data2' could not be parsed as type 'data3'.

Message #

During processing of the Federation Service  configuration, the element '%1' was found to have invalid data. The configured value '%2' could not be parsed as type '%3'. 
Element: %1 
Value: %2 
Type: %3 

The Federation Service will not be able to start until this configuration element is corrected. 

User Action 
Correct the specified configuration element to conform to the given type.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 131 —

Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The configured value 'data2' could not be parsed as type 'data3'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 132 — During processing of the Federation Service configuration, the required element 'data1' was missing.

Provider
AD FS
Channel
Admin

Description

During processing of the Federation Service configuration, the required element 'data1' was missing.

Message #

During processing of the Federation Service configuration, the required element '%1' was missing. 
Element: %1 

The Federation Service will not be able to start until this configuration element is configured. 

User Action 
Configure the specified configuration element using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString

Event ID 132 —

Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the required element 'data1' was missing.

Fields #

NameDescription
data1 UnicodeString

Event ID 133 — During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

Provider
AD FS
Channel
Admin

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The private key for the certificate that was configured could not be accessed. The following are the values of the certificate: 
Element: %1 
Subject: %2 
Thumbprint: %3 
storeName: %4 
storeLocation: %5 
Federation Service identity: %6 

The Federation Service will not be able to start until this configuration element is corrected. 

This condition can occur when the certificate is found in the specified store but there is a problem accessing the certificate's private key. Common causes for this condition include the following: 
(1) The certificate was installed from a source that did not include the private key, such as a .cer or .p7b file. 
(2) The certificate's private key was imported (for example, from a .pfx file) into a store that is different from the store specified above. 
(3) The certificate was generated as part of a certificate request that did not specify the "Machine Key" option. 
(4) The Federation Service identity '%6' has not been granted read access to the certificate's private key. 

User Action 
If the certificate was imported from a source with no private key, choose a certificate that does have a private key, or import the certificate again from a source that includes the private key (for example, a .pfx file). 

If the certificate was imported in a user context, verify that the store specified above matches the store the certificate was imported into. 

If the certificate was generated by a certificate request that did not specify the "Machine Key" option and the key is marked as exportable, export the certificate with a private key from the user store to a .pfx file and import it again directly into the store specified in the configuration file. If the key is not marked as exportable, request a new certificate using the "Machine Key" option. 

If the Federation Service identity has not been granted read access to the certificate's private key, correct this condition using the Certificates  snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 133 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 134 — During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

Provider
AD FS
Channel
Admin

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' could not be found.

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The certificate that was identified by the findValue '%2' could not be found. 
Element: %1 
storeName: %3 
storeLocation: %4 
x509FindType: %5 
findValue: %2 

The Federation Service will not be able to start until this configuration element is corrected. 

This condition occurs when the findValue that is specified does not match any certificate in the specified store. Common causes for this condition include the following: 
(1) The certificate with the specified findValue is from a store that is different from the configured store. 
(2) The certificate was deleted from the store after configuration. 

User Action 
If the certificate exists in a different store, find the location using the certificates snap-in and correct the configuration appropriately. 

If the certificate has been deleted, configure a different certificate.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 134 —

Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' could not be found.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 135 — During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

Provider
AD FS
Channel
Admin

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' was not unique.

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The certificate that was identified by the findValue '%2' was not unique. 
Element: %1 
storeName: %3 
storeLocation: %4 
x509FindType: %5 
findValue: %2 

The Federation Service will not be able to start until this configuration element is corrected. 

This condition can occur when the certificate is found in the specified store but there is more than one certificate that matches the findValue. 

User Action 
If the certificate was identified by name and there are multiple certificates of the same name, configure the certificate using the certificate thumbprint.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 135 —

Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' was not unique.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 136 — During processing of the Federation Service configuration, the Federation Service encountered a configuration error.

Provider
AD FS
Channel
Admin

Description

During processing of the Federation Service configuration, the Federation Service encountered a configuration error.

Message #

During processing of the Federation Service configuration, the Federation Service encountered a configuration error. 

%1 

Additional Data 
%2 

The Federation Service will not be able to start until this error has been corrected. 

User Action 
Correct the specified configuration error using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 136 —

Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the Federation Service encountered a configuration error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 143 — The Federation Service was unable to create the federation metadata document as a result of an error.

Provider
AD FS
Channel
Admin

Description

The Federation Service was unable to create the federation metadata document as a result of an error.

Message #

The Federation Service was unable to create the federation metadata document as a result of an error. 
Document Path: %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 143 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service was unable to create the federation metadata document as a result of an error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 144 — The Federation Service Proxy blocked an illegitimate request made by a client, as there was no matching endpoint registered at the proxy.

Provider
AD FS
Channel
Admin

Message #

The Federation Service Proxy blocked an illegitimate request made by a client, as there was no matching  endpoint registered at the proxy. This could point to a DNS misconfiguration, a partially configured application  published through the proxy, or a malicious request. 
Url Path: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 144 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 147 — A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any ...

Provider
AD FS
Channel
Admin

Description

A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any known claims provider trust.

Message #

A token was received from a claims provider identified by the key '%1', but the token could not be validated because the key does not identify any known claims provider trust. 
Key: %1 

This request failed. 

User Action 
If this key represents the certificate thumbprint of a claims provider trust, verify that it  matches the signing certificate of the claims provider trust in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 147 —

Provider
AD FS
Channel
Unknown

Description

A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any known claims provider trust.

Fields #

NameDescription
data1 UnicodeString

Event ID 149 — During processing of the Federation Service configuration, the attribute store 'Event.EventData' could not be loaded.

Provider
AD FS
Channel
Admin
Level
Error

Description

During processing of the Federation Service configuration, the attribute store 'Event.EventData' could not be loaded.

Message #

During processing of the Federation Service configuration, the attribute store '%1' could not be loaded.  
Attribute store type: %2 

User Action 
If you are using a custom attribute store, verify that the custom attribute store is configured using AD FS Management snap-in. 

Additional Data 
%3

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 149,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:31.694542+00:00",
    "event_record_id": 90,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "TestLDAPStore",
          "Microsoft.IdentityServer.ClaimsPolicy.Engine.AttributeStore.Ldap.LdapAttributeStore, Microsoft.IdentityServer.ClaimsPolicy",
          "POLICY3820: The configured connection value 'LDAP://localhost:389' for the 'TestLDAPStore' attribute store is not valid. It must be a valid LDAP:// Uri. Ex:LDAP://fabrikam.com/DC=fabrikam,DC=com"
        ]
      }
    }
  },
  "message": ""
}

Event ID 149 —

Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the attribute store 'data1' could not be loaded.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 155 — The Federation Service was unable to listen at 'data1' for metadata document requests due to an unexpected error.

Provider
AD FS
Channel
Admin

Description

The Federation Service was unable to listen at 'data1' for metadata document requests due to an unexpected error.

Message #

The Federation Service was unable to listen at '%1' for metadata document requests due to an unexpected error. 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 155 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service was unable to listen at 'data1' for metadata document requests due to an unexpected error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 156 — Trust monitoring cycle initiated.

Provider
AD FS
Channel
Admin
Level
Informational

Description

Trust monitoring cycle initiated.

Message #

Trust monitoring cycle initiated.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 156,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.122193+00:00",
    "event_record_id": 75,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 11600
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 156 —

Provider
AD FS
Channel
Unknown

Description

Trust monitoring cycle initiated.

Event ID 157 — Trust monitoring cycle completed.

Provider
AD FS
Channel
Admin
Level
Informational

Description

Trust monitoring cycle completed.

Message #

Trust monitoring cycle completed.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 157,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.147700+00:00",
    "event_record_id": 78,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 11600
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 157 —

Provider
AD FS
Channel
Unknown

Description

Trust monitoring cycle completed.

Event ID 159 — The Federation Service encountered an error while writing to the following object in the configuration database.

Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while writing to the following object in the configuration database.

Message #

The Federation Service encountered an error while writing to the following object in the configuration database. 

Object Type: 
%1 

Name: 
%2 

Metadata document URL: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 159 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while writing to the following object in the configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 163 — An error occurred during initialization of trust monitoring.

Provider
AD FS
Channel
Admin

Description

An error occurred during initialization of trust monitoring. Trust monitoring against the published partner configuration will be disabled for the lifetime of this service.

Message #

An error occurred during initialization of trust monitoring. Trust monitoring against the published partner configuration will be disabled for the lifetime of this service. 

Additional Data 

Exception details: 
%1 

User Action 
If you want to try to start the trust monitoring service again, restart the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 163 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during initialization of trust monitoring. Trust monitoring against the published partner configuration will be disabled for the lifetime of this service.

Fields #

NameDescription
data1 UnicodeString

Event ID 164 — An error occurred during a read operation from the configuration database.

Provider
AD FS
Channel
Admin

Message #

An error occurred during a read operation from the configuration database. Trust monitoring was shut down and will be tried again after an amount of time that corresponds to the trust monitoring interval. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 164 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 165 — An error occurred during trust monitoring.

Provider
AD FS
Channel
Admin

Description

An error occurred during trust monitoring. The trust monitoring cycle was shut down.

Message #

An error occurred during trust monitoring. The trust monitoring cycle was shut down. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 165 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during trust monitoring. The trust monitoring cycle was shut down.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 166 — Trust monitoring service encountered an error while parsing the metadata document from 'data1'.

Provider
AD FS
Channel
Admin

Description

Trust monitoring service encountered an error while parsing the metadata document from 'data1'. Trust monitoring failed for.

Message #

Trust monitoring service encountered an error while parsing the metadata document from '%1'. Trust monitoring failed for: 

Object Type: 
%2 

Name: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 166 —

Provider
AD FS
Channel
Unknown

Description

Trust monitoring service encountered an error while parsing the metadata document from 'data1'. Trust monitoring failed for.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 167 — Trust monitoring service encountered an error while applying the data in the metadata document from 'data1'.

Provider
AD FS
Channel
Admin

Description

Trust monitoring service encountered an error while applying the data in the metadata document from 'data1'. Trust monitoring failed for.

Message #

Trust monitoring service encountered an error while applying the data in the metadata document from '%1'. Trust monitoring failed for: 

Object Type: 
%2 

Name: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 167 —

Provider
AD FS
Channel
Unknown

Description

Trust monitoring service encountered an error while applying the data in the metadata document from 'data1'. Trust monitoring failed for.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 168 — The Federation Service encountered an error while retrieving the federation metadata document from 'data1'.

Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while retrieving the federation metadata document from 'data1'. The monitoring for the following trusts failed.

Message #

The Federation Service encountered an error while retrieving the federation metadata document from '%1'. The monitoring for the following trusts failed: 

Claims providers: 
%2 

Relying parties: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5 

User Action 
Make sure federation metadata URL is accessible. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 168 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while retrieving the federation metadata document from 'data1'. The monitoring for the following trusts failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 171 — The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

Provider
AD FS
Channel
Admin

Description

The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

Message #

The trust monitoring service automatically updated the trust of '%1' successfully with the partner's published changes.

Fields #

NameDescription
data1 UnicodeString

Event ID 171 —

Provider
AD FS
Channel
Unknown

Description

The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

Fields #

NameDescription
data1 UnicodeString

Event ID 173 — The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

Provider
AD FS
Channel
Admin

Description

The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

Message #

The trust monitoring service automatically updated the trust of '%1' successfully with the partner's published changes. 

Additional Data 
Warnings: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 173 —

Provider
AD FS
Channel
Unknown

Description

The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 174 — Trust monitoring service detected changes in policy of 'data1', but did not automatically apply the changes on the trust partner.

Provider
AD FS
Channel
Admin

Description

Trust monitoring service detected changes in policy of 'data1', but did not automatically apply the changes on the trust partner.

Message #

Trust monitoring service detected changes in policy of '%1', but did not automatically apply the changes on the trust partner. 

Additional Data 
Warnings: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 174 —

Provider
AD FS
Channel
Unknown

Description

Trust monitoring service detected changes in policy of 'data1', but did not automatically apply the changes on the trust partner.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 180 — An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version 'data2' to Minor Version 'data3'.

Provider
AD FS
Channel
Admin

Description

An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version 'data2' to Minor Version 'data3'.

Message #

An error occurred while upgrading FarmBehaviorLevel '%1' from Minor Version '%2' to Minor Version '%3'. 

Additional Data 
Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 180 —

Provider
AD FS
Channel
Unknown

Description

An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version 'data2' to Minor Version 'data3'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 181 — AD FS could not enable the new KDFv2 feature automatically because of missing Windows Updates on one or more nodes of the farm.

Provider
AD FS
Channel
Admin

Message #

AD FS could not enable the new KDFv2 feature automatically because of missing Windows Updates on one or more nodes of the farm. Please make sure that all the farm nodes are patched with the latest Windows Updates. AD FS checks regularly for the required updates to enable the new KDFv2 feature. An event 182 will be logged when a check is successful. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 181 —

Provider
AD FS
Channel
Unknown

Event ID 182 — AD FS enabled the new KDFv2 feature successfully.

Provider
AD FS
Channel
Admin

Description

AD FS enabled the new KDFv2 feature successfully. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Message #

AD FS enabled the new KDFv2 feature successfully. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 182 —

Provider
AD FS
Channel
Unknown

Description

AD FS enabled the new KDFv2 feature successfully. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 183 — KDFv2 feature is disabled on AD FS farm.

Provider
AD FS
Channel
Admin

Message #

KDFv2 feature is disabled on AD FS farm. Please make sure that all the farm nodes are patched with latest Windows Updates and the KDFv2 feature is enabled to enhance the security of the farm. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 183 —

Provider
AD FS
Channel
Unknown

Event ID 184 — A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identi...

Provider
AD FS
Channel
Admin

Description

A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identify any known relying party trust.

Message #

A token request was received for a relying party identified by the key '%1', but the request could not be fulfilled because the key does not identify any known relying party trust. 
Key: %1 

This request failed. 

User Action 
If this key represents a URI for which a token should be issued, verify that its prefix matches the relying party trust that is configured in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 184 —

Provider
AD FS
Channel
Unknown

Description

A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identify any known relying party trust.

Fields #

NameDescription
data1 UnicodeString

Event ID 186 — The Federation Service could not fulfill the token-issuance request.

Provider
AD FS
Channel
Admin

Message #

The Federation Service could not fulfill the token-issuance request. More than  one claim based on SamlNameIdentifierClaimResource was produced after the issuance  transform rules were applies for relying party '%2'. See event 500 with the same Instance ID for claims after application of issuance transform rules. 

Additional Data 
Instance ID: %1 

User Action 
Ensure that the issuance transform rules that are configured for the relying party do not result in multiple claims based on SamlNameIdentifierClaimResource.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 186 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 187 — AD FS server received a JWT token without nonce in the assertion and it was accepted based on the current configuration setting of EnforceNonceInJWT.

Provider
AD FS
Channel
Admin

Message #

AD FS server received a JWT token without nonce in the assertion and it was accepted based on the current configuration setting of EnforceNonceInJWT. However, it indicates a potential replay of the JWT token by a malicious client or the possibility that the client is not patched with latest Windows Updates. Please make sure to update the EnforceNonceInJWT setting to reject all such JWT tokens after patching the clients with latest Windows Updates. 
For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2238156. 

Additional Data 
    Client IP: %1 
    User Agent: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 187 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 188 — AD FS server is not configured to reject JWT tokens that did not have nonce in the assertion.

Provider
AD FS
Channel
Admin

Message #

AD FS server is not configured to reject JWT tokens that did not have nonce in the assertion. The corresponding setting (EnforceNonceInJWT) should be enabled for security reasons after making sure that all the clients are patched with the latest Windows Updates. 
The event 187 indicates the instances where AD FS received such tokens and accepted due to the current setting of EnforceNonceInJWT. 
For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2238156.

Event ID 188 —

Provider
AD FS
Channel
Unknown

Event ID 189 — AD FS server received an OAuth authorization request in the device code flow without a Cross Site Request Forgery (CSRF) protection code in the Use...

Provider
AD FS
Channel
Admin

Message #

AD FS server received an OAuth authorization request in the device code flow without a Cross Site Request Forgery (CSRF) protection code in the UserCode cookie. This indicates that the AD FS server that issued the UserCode cookie has not  been patched with the latest Windows security updates. It is recommended to install the latest Windows security updates  on all the AD FS servers of the farm in order to be protected from CSRF attacks. Your environment is currently vulnerable  to the CSRF attacks in OAuth device code flow due to one or more unpatched AD FS servers. 

Additional Data 
    Usercode: %1 
    Client IP: %2 
    User Agent: %3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 189 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 193 — The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type.

Provider
AD FS
Channel
Admin

Description

The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type.

Message #

The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type. 
Comparison type: %1 
Desired authentication type(s): %2 
Relying party: %3 

This request failed. 

User Action 
Use the AD FS PowerShell commands to configure the authentication context order property. 
Ensure that the relying party is configured to request the correct authentication type.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 193 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 197 — The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of '%...

Provider
AD FS
Channel
Admin

Description

The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'data2' for the relying party 'data3'.

Message #

The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of '%2' for the relying party '%3'. 
Authentication type: %1 
Desired authentication type(s): %2 
Relying party: %3 

This request failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 197 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'data2' for the relying party 'data3'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 198 — The federation server proxy started successfully.

Provider
AD FS
Channel
Admin

Description

The federation server proxy started successfully.

Message #

The federation server proxy started successfully.

Event ID 198 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy started successfully.

Event ID 199 — The federation server proxy could not be started.

Provider
AD FS
Channel
Admin

Description

The federation server proxy could not be started.

Message #

The federation server proxy could not be started. 
Reason: %1 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 199 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy could not be started.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 200 — The federation server proxy stopped successfully.

Provider
AD FS
Channel
Admin

Description

The federation server proxy stopped successfully.

Message #

The federation server proxy stopped successfully.

Event ID 200 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy stopped successfully.

Event ID 201 — The Federation Service data1 encountered an Access Denied error while trying to register one or more endpoint URLs.

Provider
AD FS
Channel
Admin

Message #

The Federation Service %1 encountered an Access Denied error while trying to register one or more endpoint URLs. This condition typically occurs when the ACL for the endpoint URL is missing or the HTTP namespace in the ACL is not a prefix match of the endpoint URL. 

 The %1 could not be opened. 

User Action 
Ensure that a valid ACL for each of the URLs has been configured on this computer. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 201 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 202 — The Federation Service data1 could not be opened.

Provider
AD FS
Channel
Admin

Description

The Federation Service data1 could not be opened.

Message #

The Federation Service %1 could not be opened. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 202 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service could not be opened.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 203 — The Federation Service data1 could not be shut down properly.

Provider
AD FS
Channel
Admin

Description

The Federation Service data1 could not be shut down properly.

Message #

The Federation Service %1 could not be shut down properly. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 203 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service could not be shut down properly.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 204 — The Federation Service data1 could not be closed.

Provider
AD FS
Channel
Admin

Description

The Federation Service data1 could not be closed.

Message #

The Federation Service %1 could not be closed. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 204 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service could not be closed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 206 — The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint addr...

Provider
AD FS
Channel
Admin

Description

The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint address.

Message #

The Federation Service could not fulfill the token-issuance request because the relying party '%1' is missing a WS-Federation Passive endpoint address. 
Relying party: %1 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure a WS-Federation Passive endpoint on this relying party.

Fields #

NameDescription
data1 UnicodeString

Event ID 206 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint address.

Fields #

NameDescription
data1 UnicodeString

Event ID 207 — An attempt to write to the Security event log failed.

Provider
AD FS
Channel
Admin

Description

An attempt to write to the Security event log failed.

Message #

An attempt to write to the Security event log failed. 

Additional Data 
Windows error code: %1 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 207 —

Provider
AD FS
Channel
Unknown

Description

An attempt to write to the Security event log failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 208 — An error occurred during an attempt to register the event source for the Security log.

Provider
AD FS
Channel
Admin

Description

An error occurred during an attempt to register the event source for the Security log.

Message #

An error occurred during an attempt to register the event source for the Security log.  

User Action 
Ensure that the Federation Service has the correct permissions to write to the Security log.

Event ID 208 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during an attempt to register the event source for the Security log.

Event ID 209 — The Security log event source for the Federation Service could not be registered.

Provider
AD FS
Channel
Admin

Description

The Security log event source for the Federation Service could not be registered.

Message #

The Security log event source for the Federation Service could not be registered. 

Additional Data 
Windows error code: %1 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 209 —

Provider
AD FS
Channel
Unknown

Description

The Security log event source for the Federation Service could not be registered.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 215 — The Federation Service at 'data1' did not return any WS-Trust endpoints to be published by the federation server proxy.

Provider
AD FS
Channel
Admin

Description

The Federation Service at 'data1' did not return any WS-Trust endpoints to be published by the federation server proxy.

Message #

The Federation Service at '%1' did not return any WS-Trust endpoints to be published by the federation server proxy. 

User Action 
If you want to publish WS-Trust endpoints to the federation server proxy, make sure that the endpoints are enabled for proxy use on the federation server.

Fields #

NameDescription
data1 UnicodeString

Event ID 215 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service at 'data1' did not return any WS-Trust endpoints to be published by the federation server proxy.

Fields #

NameDescription
data1 UnicodeString

Event ID 217 — A WS-Trust endpoint that was configured could not be opened.

Provider
AD FS
Channel
Admin

Description

A WS-Trust endpoint that was configured could not be opened.

Message #

A WS-Trust endpoint that was configured could not be opened. 

Additional Data 
Address: %1 
Mode: %2 

Error: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 217 —

Provider
AD FS
Channel
Unknown

Description

A WS-Trust endpoint that was configured could not be opened.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 218 — The federation server proxy received error code 'data2' while making a request to the Federation Service at 'data1'.

Provider
AD FS
Channel
Admin

Description

The federation server proxy received error code 'data2' while making a request to the Federation Service at 'data1'. This could mean that the Federation Service is not started on the remote host.

Message #

The federation server proxy received error code '%2' while making a request to the Federation Service at '%1'. This could mean that the Federation Service is not started on the remote host. 

User Action 
Verify that the Federation Service is running on the remote host.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 218 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy received error code 'data2' while making a request to the Federation Service at 'data1'. This could mean that the Federation Service is not started on the remote host.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 220 — The Federation Service configuration could not be loaded correctly from the AD FS configuration database.

Provider
AD FS
Channel
Admin
Level
Error

Description

The Federation Service configuration could not be loaded correctly from the AD FS configuration database.

Message #

The Federation Service configuration could not be loaded correctly from the AD FS configuration database. 

Additional Data 
Error:  
%1

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 220,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:11:11.159207+00:00",
    "event_record_id": 297,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 11500
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "ADMIN0012: OperationFault"
      }
    }
  },
  "message": ""
}

Event ID 220 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service configuration could not be loaded correctly from the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 221 — A change to the token service configuration was detected, but there was an error reloading the changes to configuration.

Provider
AD FS
Channel
Admin
Level
Error

Description

A change to the token service configuration was detected, but there was an error reloading the changes to configuration.

Message #

A change to the token service configuration was detected, but there was an error reloading the changes to configuration. 

Additional Data 
Error:  
%1

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 221,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:10:50.898809+00:00",
    "event_record_id": 229,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 8536
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "ADMIN0012: OperationFault"
      }
    }
  },
  "message": ""
}

Event ID 221 —

Provider
AD FS
Channel
Unknown

Description

A change to the token service configuration was detected, but there was an error reloading the changes to configuration.

Fields #

NameDescription
data1 UnicodeString

Event ID 222 — The federation server proxy was unable to complete a request to the Federation Service at address 'data1' because of a time-out.

Provider
AD FS
Channel
Admin

Description

The federation server proxy was unable to complete a request to the Federation Service at address 'data1' because of a time-out. This might mean that the Federation Service is currently unavailable.

Message #

The federation server proxy was unable to complete a request to the Federation Service at address '%1' because of a time-out. This might mean that the Federation Service is currently unavailable. 

User Action 
Verify that the Federation Service is running.

Fields #

NameDescription
data1 UnicodeString

Event ID 222 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy was unable to complete a request to the Federation Service at address 'data1' because of a time-out. This might mean that the Federation Service is currently unavailable.

Fields #

NameDescription
data1 UnicodeString

Event ID 223 — Claim description could not be loaded correctly from the database.

Provider
AD FS
Channel
Admin

Description

Claim description could not be loaded correctly from the database.

Message #

Claim description could not be loaded correctly from the database. 

Additional Data 
Error:  
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 223 —

Provider
AD FS
Channel
Unknown

Description

Claim description could not be loaded correctly from the database.

Fields #

NameDescription
data1 UnicodeString

Event ID 224 — The federation server proxy configuration could not be updated with the latest configuration on the federation service.

Provider
AD FS
Channel
Admin

Description

The federation server proxy configuration could not be updated with the latest configuration on the federation service.

Message #

The federation server proxy configuration could not be updated with the latest configuration on the federation service. 

Additional Data 
Error:  
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 224 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy configuration could not be updated with the latest configuration on the federation service.

Fields #

NameDescription
data1 UnicodeString

Event ID 225 — A change to the service configuration was detected, but there was an error reloading the changes to data1.

Provider
AD FS
Channel
Admin

Description

A change to the service configuration was detected, but there was an error reloading the changes to data1.

Message #

A change to the service configuration was detected, but there was an error reloading the changes to %1. 

Additional Data 
Error:  
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 225 —

Provider
AD FS
Channel
Unknown

Description

A change to the service configuration was detected, but there was an error reloading the changes to .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 230 — The federation server proxy has detected congestion, caused by high latency response times, on the Federation Service.

Provider
AD FS
Channel
Admin

Message #

The federation server proxy has detected congestion, caused by high latency response times, on the Federation Service. The load might be above the Federation Service operating capacity, or there might be network connectivity issues. Request throttling has been enforced to limit the number of concurrent requests to the following size: %1. 

User Action 
Verify that the Federation Service is operating within its operating capacity. 
Verify that the Federation Service is not experiencing network outages.

Fields #

NameDescription
data1 UnicodeString

Event ID 230 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 238 — The Federation Service failed to find a domain controller for the domain data1.

Provider
AD FS
Channel
Admin

Description

The Federation Service failed to find a domain controller for the domain data1.

Message #

The Federation Service failed to find a domain controller for the domain %1. 

Additional Data 
Domain Name: %1 
Error: %2 

User Action 
Use Nltest to determine why DC locator is failing. Nltest is part of the Windows Support Tools.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 238 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service failed to find a domain controller for the domain .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 244 — The Federation Service was unable to listen at 'data1' for WS-MetadataExchange requests due to an unexpected error.

Provider
AD FS
Channel
Admin

Description

The Federation Service was unable to listen at 'data1' for WS-MetadataExchange requests due to an unexpected error.

Message #

The Federation Service was unable to listen at '%1' for WS-MetadataExchange requests due to an unexpected error. 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 244 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service was unable to listen at 'data1' for WS-MetadataExchange requests due to an unexpected error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 245 — The federation server proxy successfully retrieved and updated its configuration from the Federation Service 'data1'.

Provider
AD FS
Channel
Admin

Description

The federation server proxy successfully retrieved and updated its configuration from the Federation Service 'data1'.

Message #

The federation server proxy successfully retrieved and updated its configuration from the Federation Service '%1'.

Fields #

NameDescription
data1 UnicodeString

Event ID 245 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy successfully retrieved and updated its configuration from the Federation Service 'data1'.

Fields #

NameDescription
data1 UnicodeString

Event ID 246 — The Federation Service encountered an error during an attempt to connect to a LDAP server at data1.

Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error during an attempt to connect to a LDAP server at data1.

Message #

The Federation Service encountered an error during an attempt to connect to a LDAP server at %1. 

Additional Data 
Domain Name: %1 
LDAP server hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from LDAP server (if available): %7 
Exception Details: 
 %8 

User Action 
 Check the network connectivity to the LDAP server. Also, check whether the LDAP server is configured properly.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 246 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error during an attempt to connect to a LDAP server at .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 247 — The Federation Service encountered an error while connecting to a global catalog server at data1.

Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while connecting to a global catalog server at data1.

Message #

The Federation Service encountered an error while connecting to a global catalog server at %1. 

Additional Data 
Domain Name: %1 
Global Catalog hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from server (if available): %7 
Exception Details: 
 
 %8 

User Action 
Troubleshoot the network connectivity to the global catalog server. Also, verify that the global catalog server is configured properly.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 247 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while connecting to a global catalog server at .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 248 — The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1.

Provider
AD FS
Channel
Admin

Description

The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1. The error message is 'data2'.

Message #

The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at %1. The error message is '%2'. 

User Action 
Make sure that the Federation Service is running. Troubleshoot network connectivity. If the trust between the federation server proxy and the Federation Service is lost, run the Federation Server Proxy Configuration Wizard again.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 248 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1. The error message is 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 249 — The certificate identified by thumbprint 'data1' could not be found in the certificate store.

Provider
AD FS
Channel
Admin

Message #

The certificate identified by thumbprint '%1' could not be found in the certificate store.  In certificate rollover scenarios, this can potentially cause a failure when the Federation Service is signing or decrypting using this certificate. 

User Action 
Ensure that the certificate that is identified by thumbprint '%1' has been added to the Localmachine "My" store and that it is accessible by the service account of the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 249 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 250 — Expiration of the artifact failed.

Provider
AD FS
Channel
Admin

Description

Expiration of the artifact failed.

Message #

Expiration of the artifact failed. 

Additional Data 
Exception message: 
%1 

User Action 
Ensure that the artifact storage server is configured properly. Troubleshoot network connectivity to the artifact storage server.

Fields #

NameDescription
data1 UnicodeString

Event ID 250 —

Provider
AD FS
Channel
Unknown

Description

Expiration of the artifact failed.

Fields #

NameDescription
data1 UnicodeString

Event ID 251 — Attribute store 'Event.EventData' is loaded successfully.

Provider
AD FS
Channel
Admin
Level
Informational

Description

Attribute store 'Event.EventData' is loaded successfully.

Message #

Attribute store '%1' is loaded successfully.

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 251,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:52.787344+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Active Directory"
      }
    }
  },
  "message": ""
}

Event ID 251 —

Provider
AD FS
Channel
Unknown

Description

Attribute store 'data1' is loaded successfully.

Fields #

NameDescription
data1 UnicodeString

Event ID 252 — The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service.

Provider
AD FS
Channel
Admin

Description

The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service.

Message #

The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service. 

Endpoints added: 
%1 

Endpoints removed: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 252 —

Provider
AD FS
Channel
Unknown

Description

The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 253 — AD FS proxy service failed to start a listener for the endpoint 'data1'.

Provider
AD FS
Channel
Admin

Description

AD FS proxy service failed to start a listener for the endpoint 'data1'.

Message #

AD FS proxy service failed to start a listener for the endpoint '%1' 
Exceptiondetails: 
%2 

User action: Ensure that no conflicting SSL bindings are configured for the specified endpoint.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 253 —

Provider
AD FS
Channel
Unknown

Description

AD FS proxy service failed to start a listener for the endpoint 'data1'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 258 — The relying party 'data1' is not configured with SAML Assertion Consumer Services.

Provider
AD FS
Channel
Admin

Description

The relying party 'data1' is not configured with SAML Assertion Consumer Services.

Message #

The relying party '%1' is not configured with SAML Assertion Consumer Services. 
Relying party: %1 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure one or more Assertion Consumer Services for this relying party.

Fields #

NameDescription
data1 UnicodeString

Event ID 258 —

Provider
AD FS
Channel
Unknown

Description

The relying party 'data1' is not configured with SAML Assertion Consumer Services.

Fields #

NameDescription
data1 UnicodeString

Event ID 259 — The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'.

Provider
AD FS
Channel
Admin

Description

The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'.

Message #

The request specified an Assertion Consumer Service index '%1' that is not  configured on the relying party '%2'. 
Assertion Consumer Service index: %1 
Relying party: %2 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an Assertion Consumer Service with the specified index for this relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 259 —

Provider
AD FS
Channel
Unknown

Description

The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 260 — The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'.

Provider
AD FS
Channel
Admin

Description

The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'.

Message #

The request specified an Assertion Consumer Service protocol binding '%1' that is not  configured on the relying party '%2'. 
Assertion Consumer Service protocol binding: %1 
Relying party: %2 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an Assertion Consumer Service with the specified protocol binding for this relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 260 —

Provider
AD FS
Channel
Unknown

Description

The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 261 — The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'.

Provider
AD FS
Channel
Admin

Description

The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'.

Message #

The request specified an Assertion Consumer Service URL '%1' that is not  configured on the relying party '%2'. 
Assertion Consumer Service URL: %1 
Relying party: %2 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an Assertion Consumer Service with the specified URL for this relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 261 —

Provider
AD FS
Channel
Unknown

Description

The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 262 — The artifact resolution request failed.

Provider
AD FS
Channel
Admin

Description

The artifact resolution request failed.

Message #

The artifact resolution request failed. 

Additional Data 
Exception message: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 262 —

Provider
AD FS
Channel
Unknown

Description

The artifact resolution request failed.

Fields #

NameDescription
data1 UnicodeString

Event ID 273 — The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'.

Provider
AD FS
Channel
Admin

Description

The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'.

Message #

The request specified an assertion consumer service  that is not  configured or not supported on the relying party '%4'. 
Request parameters: '%1', '%2', '%3' 
Relying party: %4 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an assertion consumer service with the specified parameters for this relying party. Also, check whether the artifact resolution service is enabled if the SAML artifact is requested.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 273 —

Provider
AD FS
Channel
Unknown

Description

The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 274 — The federation server proxy encountered an error while trying to listen on one of the proxy endpoints.

Provider
AD FS
Channel
Admin

Message #

The federation server proxy encountered an error while trying to listen on one of the proxy endpoints.  The federation server proxy will not be able to start until it can listen on all required proxy endpoints. 
Proxy Endpoints: 
 
%1 

User Action 
Ensure that the permissions on the URLs of the proxy endpoints allow the federation server proxy security account (the default is Network Service) to listen on them.

Fields #

NameDescription
data1 UnicodeString

Event ID 274 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 275 — The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service data1.

Provider
AD FS
Channel
Admin

Description

The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service data1.

Message #

The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service %1. 
Error Message: 
%2 

User Action 
Ensure that the SSL certificate for Federation Service '%1' is valid and trusted by the federation server proxy.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 275 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 276 — The federation server proxy was not able to authenticate to the Federation Service.

Provider
AD FS
Channel
Admin

Description

The federation server proxy was not able to authenticate to the Federation Service.

Message #

The federation server proxy was not able to authenticate to the Federation Service. 

User Action 
Ensure that the proxy is trusted by the Federation Service. To do this, log on to the proxy computer with the host name that is identified in the certificate subject name and re-establish trust between the proxy and the Federation Service using the Install-WebApplicationProxy cmdlet. 

Additional Data 

Certificate details: 

Subject Name: 
%1 

Thumbprint: 
%2 

NotBefore Time: 
%3 

NotAfter Time: 
%4 

Client endpoint: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 276 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy was not able to authenticate to the Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 277 — The Federation Service encountered an unexpected exception and has shut down.

Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an unexpected exception and has shut down.

Message #

The Federation Service encountered an unexpected exception and has shut down. 

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 277 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an unexpected exception and has shut down.

Fields #

NameDescription
data1 UnicodeString

Event ID 278 — The SAML artifact resolution endpoint is not configured or it is disabled.

Provider
AD FS
Channel
Admin
Level
Warning

Description

The SAML artifact resolution endpoint is not configured or it is disabled.

Message #

The SAML artifact resolution endpoint is not configured or it is disabled. 

User Action 
If SAML artifact resolution is required, use the AD FS Management snap-in to configure or enable the SAML artifact resolution endpoint.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 278,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:53.726364+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 278 —

Provider
AD FS
Channel
Unknown

Description

The SAML artifact resolution endpoint is not configured or it is disabled.

Event ID 279 — Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database.

Provider
AD FS
Channel
Admin

Description

Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database.

Message #

Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database.  
SAML artifact: %1 

This request failed. 

User Action 
Verify that a claims provider trust exists in the AD FS configuration database. 
Make sure that the data for the claims provider trust is up to date.

Fields #

NameDescription
data1 UnicodeString

Event ID 279 —

Provider
AD FS
Channel
Unknown

Description

Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 280 — Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service config...

Provider
AD FS
Channel
Admin

Description

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured.

Message #

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured.  
Claims provider trust: %1 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Add the artifact resolution service endpoint to the claims provider trust.

Fields #

NameDescription
data1 UnicodeString

Event ID 280 —

Provider
AD FS
Channel
Unknown

Description

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured.

Fields #

NameDescription
data1 UnicodeString

Event ID 281 — Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpo...

Provider
AD FS
Channel
Admin

Description

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured.

Message #

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured.  
Claims provider trust: %1 
Required endpoint index: %2 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Use the AD FS Management snap-in to configure the artifact resolution endpoint with the  specified index.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 281 —

Provider
AD FS
Channel
Unknown

Description

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 283 — Unable to resolve the SAML artifact.

Provider
AD FS
Channel
Admin

Description

Unable to resolve the SAML artifact. The artifact resolution request to the claims provider failed. See inner exception for more details.

Message #

Unable to resolve the SAML artifact. The artifact resolution request to the claims provider failed. See inner exception for more details. 
SAML Artifact: %1 
Claims provider: %2 
Inner exception: 
%3 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Verify network connectivity. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 283 —

Provider
AD FS
Channel
Unknown

Description

Unable to resolve the SAML artifact. The artifact resolution request to the claims provider failed. See inner exception for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 284 — Unable to resolve the SAML artifact.

Provider
AD FS
Channel
Admin

Description

Unable to resolve the SAML artifact. A malformed response was received from the claims provider. See inner exception for more details.

Message #

Unable to resolve the SAML artifact. A malformed response was received from the claims provider. See inner exception for more details. 
SAML artifact: %1 
Claims provider: %2 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 284 —

Provider
AD FS
Channel
Unknown

Description

Unable to resolve the SAML artifact. A malformed response was received from the claims provider. See inner exception for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 285 — The SAML artifact was resolved, but the response is empty or does not contain expected assertions.

Provider
AD FS
Channel
Admin

Description

The SAML artifact was resolved, but the response is empty or does not contain expected assertions.

Message #

The SAML artifact was resolved, but the response is empty or does not contain expected assertions. 
SAML artifact: %1 
Claims provider: %2 

This request failed. 

User Action 
For more information, contact the claims provider.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 285 —

Provider
AD FS
Channel
Unknown

Description

The SAML artifact was resolved, but the response is empty or does not contain expected assertions.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 286 — Cannot connect to the artifact database.

Provider
AD FS
Channel
Admin

Description

Cannot connect to the artifact database.

Message #

Cannot connect to the artifact database. 
Connection string: %1 
Error message: 

%2 

User Action 
Ensure that the artifact database is configured properly. Use the Set-ADFSProperties cmdlet with the ArtifactDbConnection parameter in the Windows PowerShell for AD FS to modify the connection string, if necessary. 
Troubleshoot the connectivity to the artifact storage .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 286 —

Provider
AD FS
Channel
Unknown

Description

Cannot connect to the artifact database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 287 — Cannot add the artifact to the artifact database.

Provider
AD FS
Channel
Admin

Description

Cannot add the artifact to the artifact database. See exception message for more details.

Message #

Cannot add the artifact to the artifact database. See exception message for more details. 
Artifact ID: %1 
Inner exception details: 
%2 

User Action 
Ensure that the artifact database is configured properly.  
Troubleshoot the connectivity to the artifact database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 287 —

Provider
AD FS
Channel
Unknown

Description

Cannot add the artifact to the artifact database. See exception message for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 288 — Cannot get the artifact from storage.

Provider
AD FS
Channel
Admin

Description

Cannot get the artifact from storage. See exception message for more details.

Message #

Cannot get the artifact from storage. See exception message for more details. 
ArtifactId: %1 
Inner exception details: 
%2 

User Action 
Ensure that the artifact storage in the AD FS configuration database is configured properly.  
Troubleshoot connectivity to the artifact storage in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 288 —

Provider
AD FS
Channel
Unknown

Description

Cannot get the artifact from storage. See exception message for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 289 — Cannot remove the artifact from storage.

Provider
AD FS
Channel
Admin

Description

Cannot remove the artifact from storage. See inner exception message for more details.

Message #

Cannot remove the artifact from storage. See inner exception message for more details. 
ArtifactId: %1 
Inner exception details: 
%2 

User Action 
Ensure that the artifact storage in the AD FS configuration database is configured properly.  
Troubleshoot connectivity to the artifact storage in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 289 —

Provider
AD FS
Channel
Unknown

Description

Cannot remove the artifact from storage. See inner exception message for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 290 — Cannot set expiration for the artifacts in storage.

Provider
AD FS
Channel
Admin

Description

Cannot set expiration for the artifacts in storage. See inner exception message for more details.

Message #

Cannot set expiration for the artifacts in storage. See inner exception message for more details. 
Inner exception details: 
%1 

User Action 
Ensure that the artifact storage in the AD FS configuration database is configured properly.  
Troubleshoot connectivity to the artifact storage in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 290 —

Provider
AD FS
Channel
Unknown

Description

Cannot set expiration for the artifacts in storage. See inner exception message for more details.

Fields #

NameDescription
data1 UnicodeString

Event ID 291 — The artifact resolution service could not be started.

Provider
AD FS
Channel
Admin

Description

The artifact resolution service could not be started.

Message #

The artifact resolution service could not be started. 

Additional Data 
Exception details: 
%1 

User Action 
Make sure artifact resolution service is properly configured.

Fields #

NameDescription
data1 UnicodeString

Event ID 291 —

Provider
AD FS
Channel
Unknown

Description

The artifact resolution service could not be started.

Fields #

NameDescription
data1 UnicodeString

Event ID 293 — A SAML request for the required artifact was rejected because the artifact resolution service is not enabled.

Provider
AD FS
Channel
Admin

Description

A SAML request for the required artifact was rejected because the artifact resolution service is not enabled.

Message #

A SAML request for the required artifact was rejected because the artifact resolution service is not enabled. 
Relying party: %1 

This request failed. 

User Action 
Enable the artifact resolution service. 
Use the AD FS Management snap-in to configure or enable the SAML artifact resolution endpoint.

Fields #

NameDescription
data1 UnicodeString

Event ID 293 —

Provider
AD FS
Channel
Unknown

Description

A SAML request for the required artifact was rejected because the artifact resolution service is not enabled.

Fields #

NameDescription
data1 UnicodeString

Event ID 294 — The SAML artifact resolution request specified an issuer that is not configured for the relying party.

Provider
AD FS
Channel
Admin

Description

The SAML artifact resolution request specified an issuer that is not configured for the relying party.

Message #

The SAML artifact resolution request specified an issuer that is not configured for the relying party. 
Relying party: %1 
Artifact resolution request issuer: %2 

This artifact resolution request failed. 

User Action 
Ensure that the relying party is configured properly using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 294 —

Provider
AD FS
Channel
Unknown

Description

The SAML artifact resolution request specified an issuer that is not configured for the relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 297 — The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured.

Provider
AD FS
Channel
Admin

Description

The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured.

Message #

The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured. 
Endpoint index: %1 
Configured endpoint index: %2 

This artifact resolution request failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 297 —

Provider
AD FS
Channel
Unknown

Description

The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 298 — The Windows Hello for Business key receipt certificate background task will not run.

Provider
AD FS
Channel
Admin
Level
Informational

Description

The Windows Hello for Business key receipt certificate background task will not run.

Message #

The Windows Hello for Business key receipt certificate background task will not run. 

Additional Information: %1

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 298,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.107600+00:00",
    "event_record_id": 71,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13100
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "ServiceState.IsDrsInitialized is false."
      }
    }
  },
  "message": ""
}

Event ID 298 —

Provider
AD FS
Channel
Unknown

Description

The Windows Hello for Business key receipt certificate background task will not run.

Fields #

NameDescription
data1 UnicodeString

Event ID 302 — The Federation Service could not authorize token issuance for caller 'data2' as subject 'data3' to the relying party 'data4'.

Provider
AD FS
Channel
Admin

Message #

The Federation Service could  not authorize token issuance for caller '%2' as subject '%3' to the relying party '%4'. See event 501 with the same Instance ID for caller identity. See event 503 with the same Instance ID for ActAs identity, if any. 

Additional Data 
Instance ID: %1 
Relying party: %4 
Exception details: 
%5 
User Action 
Use the AD FS Management snap-in to ensure that the caller is authorized to act as the subject to the relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 302 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 303 — The Federation Service encountered an error while processing the SAML authentication request.

Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while processing the SAML authentication request.

Message #

The Federation Service encountered an error while processing the SAML authentication request. 

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 303 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while processing the SAML authentication request.

Fields #

NameDescription
data1 UnicodeString

Event ID 305 — The Federation Service encountered an error while querying a LDAP server at data1.

Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while querying a LDAP server at data1.

Message #

The Federation Service encountered an error while querying a LDAP server at %1. 

Additional Data 
Domain name: %1 
LDAP server hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from LDAP server (if available): %7 
Exception Details: 
 %8

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 305 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while querying a LDAP server at .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 306 — The Federation Service encountered an error while querying a global catalog server at data1.

Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while querying a global catalog server at data1.

Message #

The Federation Service encountered an error while querying a global catalog server at %1. 

Additional Data 
Domain name: %1 
Global catalog server hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from server (if available): %7 
Exception Details: 
 
 %8

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 306 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while querying a global catalog server at .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 311 — An attempt to update AD FS performance counters failed.

Provider
AD FS
Channel
Admin

Description

An attempt to update AD FS performance counters failed.

Message #

An attempt to update AD FS performance counters failed.  

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 311 —

Provider
AD FS
Channel
Unknown

Description

An attempt to update AD FS performance counters failed.

Fields #

NameDescription
data1 UnicodeString

Event ID 315 — An error occurred during an attempt to build the certificate chain for the claims provider trust 'data1' certificate identified by thumbprint 'data2'.

Provider
AD FS
Channel
Admin

Message #

An error occurred during an attempt to build the certificate chain for the claims provider trust '%1' certificate identified by thumbprint '%2'. Possible causes are that the certificate has been revoked, the certificate chain could not be verified as specified by the claims provider trust's signing certificate revocation settings or certificate is not within its validity period. 

You can use Windows PowerShell commands for AD FS to configure the revocation settings for the claims provider trust's signing certificate. 
Claims provider trust's signing certificate revocation settings: %3 
The following errors occurred while building the certificate chain:  
%4 

User Action: 
Ensure that the claims provider trust's signing certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 315 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 316 — An error occurred during an attempt to build the certificate chain for the relying party trust 'data1' certificate identified by thumbprint 'data2'.

Provider
AD FS
Channel
Admin

Message #

An error occurred during an attempt to build the certificate chain for the relying party trust '%1' certificate identified by thumbprint '%2'. Possible causes are that the certificate has been revoked, the certificate chain could not be verified as specified by the relying party trust's signing certificate revocation settings or certificate is not within its validity period. 

You can use Windows PowerShell commands for AD FS to configure the revocation settings for the relying party signing certificate. 
Relying party trust's signing certificate revocation settings: %3 
The following errors occurred while building the certificate chain:  
%4 

User Action: 
Ensure that the relying party trust's signing certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 316 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 317 — An error occurred during an attempt to build the certificate chain for the relying party trust 'Event.EventData' certificate identified by thumbprint 'data1'.

Provider
AD FS
Channel
Admin
Level
Error

Message #

An error occurred during an attempt to build the certificate chain for the relying party trust '%1' certificate identified by thumbprint '%2'. Possible causes are that the certificate has been revoked, the certificate chain could not be verified as specified by the relying party trust's encryption certificate revocation settings or certificate is not within its validity period. 

You can use Windows PowerShell commands for AD FS to configure the revocation settings for the relying party encryption certificate. 
Relying party trust's encryption certificate revocation settings: %3 
The following errors occurred while building the certificate chain:  
%4 

User Action: 
Ensure that the relying party trust's encryption certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 317,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:09:23.681803+00:00",
    "event_record_id": 208,
    "correlation": {
      "ActivityID": "88CEECE0-7882-41D3-9B05-08A1D8CE3B05"
    },
    "execution": {
      "process_id": 13608,
      "thread_id": 14296
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "https://testrp3.example.com/oauth",
          "DB0FEA9B641F3814FC5168AE83EF7839AF1BB012",
          "CheckChainExcludeRoot",
          "The certificate is revoked.\r\n\r\n"
        ]
      }
    }
  },
  "message": ""
}

Event ID 317 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 319 — An error occurred while the certificate chain for the client certificate identified by thumbprint 'data1' was being built.

Provider
AD FS
Channel
Admin

Message #

An error occurred while the certificate chain for the client certificate identified by thumbprint '%1' was being built. The certificate chain could not be built. The certificate has been revoked, the certificate chain could not be verified as specified by the encryption certificate revocation settings or certificate is not within its validity period. 

You can use the Set-ADFSProperties cmdlet with the ProxyCertRevocationCheck parameter in Windows PowerShell for AD FS to configure the client certificate revocation settings. 
Client Certificate Revocation Settings: %2 
The following errors occurred while building the certificate chain:  
%3 

User Action: 
Ensure that the client certificate is valid and has not been revoked. 
Ensure that the Federation Service can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 319 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 320 — The verification of the SAML message signature failed.

Provider
AD FS
Channel
Admin

Description

The verification of the SAML message signature failed.

Message #

The verification of the SAML message signature failed. 
Message issuer: %1 
Exception details: 
%2 

This request failed. 

User Action 
Verify that the message issuer configuration in the AD FS configuration database is up to date. 
Configure the signing certificate for the specified issuer. 
Verify that the issuer's certificate is up to date. 
Verify the issuer and server message signing requirements.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 320 —

Provider
AD FS
Channel
Unknown

Description

The verification of the SAML message signature failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 321 — The SAML authentication request had a NameID Policy that could not be satisfied.

Provider
AD FS
Channel
Admin

Description

The SAML authentication request had a NameID Policy that could not be satisfied.

Message #

The SAML authentication request had a NameID Policy that could not be satisfied. 
Requestor: %1 
Name identifier format: %2 
SPNameQualifier: %3 
Exception details: 
%4 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure the configuration that emits the required name identifier.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 321 —

Provider
AD FS
Channel
Unknown

Description

The SAML authentication request had a NameID Policy that could not be satisfied.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 323 — The Federation Service could not authorize token issuance for the caller 'data2' on behalf of the subject 'data3' to the relying party 'data4'.

Provider
AD FS
Channel
Admin

Message #

The Federation Service could  not authorize token issuance for the caller '%2' on behalf of the subject '%3' to the relying party '%4'. See event 501 with the same Instance ID for caller identity. See event 502 with the same Instance ID for OnBehalfOf identity, if any. 

Additional Data 
Instance ID: %1 
Exception details: 
%5 
User Action 
Use the Windows PowerShell Get-ADFSClaimsProviderTrust or Get-ADFSRelyingPartyTrust cmdlet to ensure the caller is authorized on behalf of the subject to the relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 323 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 325 — The Federation Service could not authorize token issuance for caller 'data1'.

Provider
AD FS
Channel
Admin
Level
Error

Message #

The Federation Service could not authorize token issuance for caller '%2'. The caller is not authorized to request a token for the relying party '%3'. See event 501 with the same Instance ID for caller identity. 

Additional Data 
Instance ID: %1 
Relying party: %3 
Exception details: 
%4 
User Action 
Use the AD FS Management snap-in to ensure that the caller is authorized to request a token for the relying party.

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 325,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:37.248466+00:00",
    "event_record_id": 96,
    "correlation": {
      "ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "a6f4ff0b-8776-43a4-9be1-6b9bf86e338f",
          "ludus\\domainadmin\r\n",
          "https://testrp1.example.com/saml",
          "Microsoft.IdentityServer.Service.IssuancePipeline.CallerAuthorizationException: MSIS5007: The caller authorization failed for caller identity ludus\\domainadmin for relying party trust https://testrp1.example.com/saml.\r\n   at Microsoft.IdentityModel.Threading.AsyncResult.End(IAsyncResult result)\r\n   at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.ProcessCoreAsyncResult.End(IAsyncResult ar)\r\n   at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.EndProcessCore(IAsyncResult ar, String requestAction, String responseAction, String trustNamespace)"
        ]
      }
    }
  },
  "message": ""
}

Event ID 325 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 326 — Failed to load the AD FS claims policy engine using policy type 'data1' User Action Make sure AD FS is installed correctly.

Provider
AD FS
Channel
Admin

Description

Failed to load the AD FS claims policy engine using policy type 'data1'.

Message #

Failed to load the AD FS claims policy engine using policy type '%1' 

User Action 
Make sure AD FS is installed correctly.

Fields #

NameDescription
data1 UnicodeString

Event ID 326 —

Provider
AD FS
Channel
Unknown

Description

Failed to load the AD FS claims policy engine using policy type 'data1'.

Fields #

NameDescription
data1 UnicodeString

Event ID 327 — An error occurred during processing of the SAML logout request.

Provider
AD FS
Channel
Admin

Description

An error occurred during processing of the SAML logout request.

Message #

An error occurred during processing of the SAML logout request. 

Additional Data 
Caller identity: %1 
Logout initiator identity: %2 
Error message: %3 
Exception details: %4 
User Action 
Ensure that the single logout service is configured properly for this relying party trust or claims provider trust in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 327 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during processing of the SAML logout request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 328 — The SAML artifact resolution request was resolved, but the response does not contain the expected assertions.

Provider
AD FS
Channel
Admin

Description

The SAML artifact resolution request was resolved, but the response does not contain the expected assertions.

Message #

The SAML artifact resolution request was resolved, but the response does not contain the expected assertions. 

Additional Data: 
SAML artifact: %1 
Status code: %2 
SubStatus code: %3 
Status message: %4 

This request failed. 

User Action 
Contact the claims provider for more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 328 —

Provider
AD FS
Channel
Unknown

Description

The SAML artifact resolution request was resolved, but the response does not contain the expected assertions.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 329 — The certificate that is identified by thumbprint 'data1' could not be decrypted using the keys for X.

Provider
AD FS
Channel
Admin

Description

The certificate that is identified by thumbprint 'data1' could not be decrypted using the keys for X.509 certificate private key sharing.

Message #

The certificate that is identified by thumbprint '%1' could not be decrypted using the keys for X.509 certificate private key sharing. 

Additional Data: 
X.509 certificate private key sharing diagnosis: %2 

User Action 
You may have to restore all Active Directory objects underneath the specified distinguished name in the diagnostic information above for X.509 certificate private key sharing.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 329 —

Provider
AD FS
Channel
Unknown

Description

The certificate that is identified by thumbprint 'data1' could not be decrypted using the keys for X.509 certificate private key sharing.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 331 — The certificate management service encountered an error during decryption of the keys.

Provider
AD FS
Channel
Admin

Description

The certificate management service encountered an error during decryption of the keys.

Message #

The certificate management service encountered an error during decryption of the keys. 
storeName: %2 
storeLocation: %1 
x509FindType: %4 
findValue: %3 

Additional Data: 
X.509 certificate private key sharing diagnosis: %5  

User Action 
You may have to restore all Active Directory objects underneath the distinguished name that is specified in the diagnosis for X.509 certificate private key sharing above.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 331 —

Provider
AD FS
Channel
Unknown

Description

The certificate management service encountered an error during decryption of the keys.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 332 — The certificate management service encountered an error during encryption of the keys.

Provider
AD FS
Channel
Admin

Description

The certificate management service encountered an error during encryption of the keys.

Message #

The certificate management service encountered an error during encryption of the keys. 
Subject: %1 
Diagnosis: %2 

User Action 
You may have to restore all Active Directory objects underneath the distinguished name that is specified in the diagnosis above for X.509 certificate private key sharing.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 332 —

Provider
AD FS
Channel
Unknown

Description

The certificate management service encountered an error during encryption of the keys.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 333 — The certificate management service encountered an error during database access.

Provider
AD FS
Channel
Admin

Description

The certificate management service encountered an error during database access.

Message #

The certificate management service encountered an error during database access. 

Additional Data: 
Diagnosis: %1 

User Action 
Confirm that the SQL store is online.

Fields #

NameDescription
data1 UnicodeString

Event ID 333 —

Provider
AD FS
Channel
Unknown

Description

The certificate management service encountered an error during database access.

Fields #

NameDescription
data1 UnicodeString

Event ID 334 — Certificate rollover service needs to rollover data1 certificates urgently.

Provider
AD FS
Channel
Admin

Description

Certificate rollover service needs to rollover data1 certificates urgently. Partners will not be able to apply the update in time.

Message #

Certificate rollover service needs to rollover %1 certificates urgently. Partners will not be able to apply the update in time.

Fields #

NameDescription
data1 UnicodeString

Event ID 334 —

Provider
AD FS
Channel
Unknown

Description

Certificate rollover service needs to rollover certificates urgently. Partners will not be able to apply the update in time.

Fields #

NameDescription
data1 UnicodeString

Event ID 335 —

Provider
AD FS
Channel
Admin
Level
Warning

Message #

%1

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 335,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:06:25.397047+00:00",
    "event_record_id": 83,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13020
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "MSIS10005: Certificate rollover service has added certificate with thumbprint '7D951E82355227B06C62677CAA93C92BCC9FD7BC' to 'Signing' certificate collection. See https://go.microsoft.com/fwlink/?linkid=861845 for more information."
      }
    }
  },
  "message": ""
}

Event ID 335 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 336 — The certificate management cycle was initiated.

Provider
AD FS
Channel
Admin
Level
Informational

Description

The certificate management cycle was initiated.

Message #

The certificate management cycle was initiated.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 336,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.117752+00:00",
    "event_record_id": 72,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13136
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 336 —

Provider
AD FS
Channel
Unknown

Description

The certificate management cycle was initiated.

Event ID 337 — The certificate management cycle was completed.

Provider
AD FS
Channel
Admin
Level
Informational

Description

The certificate management cycle was completed.

Message #

The certificate management cycle was completed.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 337,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.300723+00:00",
    "event_record_id": 81,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13136
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 337 —

Provider
AD FS
Channel
Unknown

Description

The certificate management cycle was completed.

Event ID 338 — An error was encountered during certificate rollover.

Provider
AD FS
Channel
Admin

Description

An error was encountered during certificate rollover. The monitoring cycle was shut down.

Message #

An error was encountered during certificate rollover. The monitoring cycle was shut down. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 338 —

Provider
AD FS
Channel
Unknown

Description

An error was encountered during certificate rollover. The monitoring cycle was shut down.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 339 — An error occurred during initialization of certificate rollover.

Provider
AD FS
Channel
Admin

Description

An error occurred during initialization of certificate rollover. Certificates will not be rolled over.

Message #

An error occurred during initialization of certificate rollover. Certificates will not be rolled over. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 339 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during initialization of certificate rollover. Certificates will not be rolled over.

Fields #

NameDescription
data1 UnicodeString

Event ID 341 — The NotBefore attribute for the token has a value that is set to a future time.

Provider
AD FS
Channel
Admin

Description

The NotBefore attribute for the token has a value that is set to a future time. See inner exception for more details.

Message #

The NotBefore attribute for the token has a value that is set to a future time. See inner exception for more details. 

Additional Data 

Token Type: 
%1 

Exception details: 
%2 

This request failed. 

User Action 
Verify that system clock is synchronized.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 341 —

Provider
AD FS
Channel
Unknown

Description

The NotBefore attribute for the token has a value that is set to a future time. See inner exception for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 342 — Token validation failed.

Provider
AD FS
Channel
Admin
Level
Error

Description

Token validation failed.

Message #

Token validation failed.  

Additional Data 

Token Type: 
%1 
%Error message: 
%2 

Exception details: 
%3

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 342,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:36.815386+00:00",
    "event_record_id": 95,
    "correlation": {
      "ActivityID": "FCDC6F25-76F3-4BC2-B0EB-7EFEBD19BD6C"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 11496
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "http://schemas.microsoft.com/ws/2006/05/identitymodel/tokens/UserName",
          "fakeuser-The user name or password is incorrect",
          "System.IdentityModel.Tokens.SecurityTokenValidationException: fakeuser ---> System.ComponentModel.Win32Exception: The user name or password is incorrect\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserInfo(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String authenticationType, String issuerName)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUser(String domain, String username, String password, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String issuerName)\r\n   at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)\r\n   --- End of inner exception stack trace ---\r\n   at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)\r\n   at Microsoft.IdentityServer.Service.Tokens.MsisLocalCpUserNameSecurityTokenHandler.ValidateTokenInternal(UsernameAuthenticationContext usernameAuthenticationContext, SecurityToken token)\r\n   at Microsoft.IdentityServer.Service.Tokens.MsisLocalCpUserNameSecurityTokenHandler.ValidateToken(SecurityToken token)\r\n\r\nSystem.ComponentModel.Win32Exception (0x80004005): The user name or password is incorrect\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserInfo(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String authenticationType, String issuerName)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUser(String domain, String username, String password, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String issuerName)\r\n   at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)"
        ]
      }
    }
  },
  "message": ""
}

Event ID 342 —

Provider
AD FS
Channel
Unknown

Description

Token validation failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 343 — There was an error during initialization of synchronization.

Provider
AD FS
Channel
Admin

Description

There was an error during initialization of synchronization. Synchronization of data from the primary federation server to the secondary federation server will not occur.

Message #

There was an error during initialization of synchronization. Synchronization of data from the primary federation server to the secondary federation server will not occur. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 343 —

Provider
AD FS
Channel
Unknown

Description

There was an error during initialization of synchronization. Synchronization of data from the primary federation server to the secondary federation server will not occur.

Fields #

NameDescription
data1 UnicodeString

Event ID 344 — There was an error doing synchronization.

Provider
AD FS
Channel
Admin

Description

There was an error doing synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.

Message #

There was an error doing synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur. 

Additional data 

Exception details: 
%1 

User Action 
 Make sure the primary federation server is available or the service account identity of this machine matches the service account identity of the primary federation server.

Fields #

NameDescription
data1 UnicodeString

Event ID 344 —

Provider
AD FS
Channel
Unknown

Description

There was an error doing synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.

Fields #

NameDescription
data1 UnicodeString

Event ID 345 — There was a communication error during AD FS configuration database synchronization.

Provider
AD FS
Channel
Admin

Description

There was a communication error during AD FS configuration database synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.

Message #

There was a communication error during AD FS configuration database synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur. 

Additional Data 

Master Name : %1 
Endpoint Uri : %2 
Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 345 —

Provider
AD FS
Channel
Unknown

Description

There was a communication error during AD FS configuration database synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 346 — There was an error during retrieving the configuration data for the secondary federation server.

Provider
AD FS
Channel
Admin

Description

There was an error during retrieving the configuration data for the secondary federation server.

Message #

There was an error during retrieving the configuration data for the secondary federation server. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 346 —

Provider
AD FS
Channel
Unknown

Description

There was an error during retrieving the configuration data for the secondary federation server.

Fields #

NameDescription
data1 UnicodeString

Event ID 348 — Synchronization of configuration data from the primary federation server 'data1' is completed.

Provider
AD FS
Channel
Admin

Description

Synchronization of configuration data from the primary federation server 'data1' is completed. data2 objects were added. data3 objects were deleted.

Message #

Synchronization of configuration data from the primary federation server '%1' is completed. %2 objects were added. %3 objects were deleted.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 348 —

Provider
AD FS
Channel
Unknown

Description

Synchronization of configuration data from the primary federation server 'data1' is completed. data2 objects were added. data3 objects were deleted.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 349 — The administration service for the Federation Service started successfully.

Provider
AD FS
Channel
Admin
Level
Informational

Message #

The administration service for the Federation Service started successfully. You can now use the Windows Powershell commands for AD FS to modify the Federation Service configuration. The following service hosts have been added: 
%1

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 349,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:51.927998+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Policy Administration ServiceHost\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nhttp://adfs.ludus.domain:80/adfs/services/policystoretransfer\r\nnet.tcp://localhost:1501/adfs/services/policystoretransfer\r\n\r\n"
      }
    }
  },
  "message": ""
}

Event ID 349 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 351 — There was an error getting synchronization properties.

Provider
AD FS
Channel
Admin

Description

There was an error getting synchronization properties.

Message #

There was an error getting synchronization properties. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 351 —

Provider
AD FS
Channel
Unknown

Description

There was an error getting synchronization properties.

Fields #

NameDescription
data1 UnicodeString

Event ID 352 — A SQL operation in the AD FS configuration database with connection string Event.EventData failed.

Provider
AD FS
Channel
Admin
Level
Error

Description

A SQL operation in the AD FS configuration database with connection string Event.EventData failed.

Message #

A SQL operation in the AD FS configuration database with connection string %1 failed.  

Additional Data 

Exception details: 
%2

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 352,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:10:50.887915+00:00",
    "event_record_id": 228,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 8536
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "Data Source=np:\\\\.\\pipe\\microsoft##wid\\tsql\\query;Initial Catalog=AdfsConfigurationV4;Integrated Security=True",
          "Login failed for user 'ludus\\svc_adfs'."
        ]
      }
    }
  },
  "message": ""
}

Event ID 352 —

Provider
AD FS
Channel
Unknown

Description

A SQL operation in the AD FS configuration database with connection string failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 353 — Unable to resolve the SAML artifact.

Provider
AD FS
Channel
Admin

Description

Unable to resolve the SAML artifact. Verification of the artifact response signature failed.

Message #

Unable to resolve the SAML artifact. Verification of the artifact response signature failed. 
Claims provider: %1 
Exception details: 
%2 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Verify that the claims provider trust's signing certificate is up to date.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 353 —

Provider
AD FS
Channel
Unknown

Description

Unable to resolve the SAML artifact. Verification of the artifact response signature failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 354 — The artifact resolution service could not verify the request signature.

Provider
AD FS
Channel
Admin

Description

The artifact resolution service could not verify the request signature.

Message #

The artifact resolution service could not verify the request signature. 

Additional Data 
Exception details: 
%1 

User action: 
Verify that the relying party trust in the AD FS configuration database is up to date. 
Configure the relying party certificate for request signing. 
Verify that relying party certificate is up to date.

Fields #

NameDescription
data1 UnicodeString

Event ID 354 —

Provider
AD FS
Channel
Unknown

Description

The artifact resolution service could not verify the request signature.

Fields #

NameDescription
data1 UnicodeString

Event ID 356 — Failed to register notification to the SQL database with the connection string data1 for cache type 'data2'.

Provider
AD FS
Channel
Admin

Description

Failed to register notification to the SQL database with the connection string data1 for cache type 'data2'. Changes to settings may not take effect until the Federation Service restarts.

Message #

Failed to register notification to the SQL database with the connection string %1 for cache type '%2'. Changes to settings may not take effect until the Federation Service restarts. 

Additional Data 

Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 356 —

Provider
AD FS
Channel
Unknown

Description

Failed to register notification to the SQL database with the connection string data1 for cache type 'data2'. Changes to settings may not take effect until the Federation Service restarts.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 357 — Successfully registered notification to the SQL database with the connection string data1.

Provider
AD FS
Channel
Admin

Description

Successfully registered notification to the SQL database with the connection string data1.

Message #

Successfully registered notification to the SQL database with the connection string %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 357 —

Provider
AD FS
Channel
Unknown

Description

Successfully registered notification to the SQL database with the connection string .

Fields #

NameDescription
data1 UnicodeString

Event ID 358 — Restarting Event.EventData.

Provider
AD FS
Channel
Admin
Level
Warning

Message #

Restarting %1. This restart is necessary because a change was detected in the certificates that this service host uses. Requests that are served by endpoints of this service host may fail during restart.

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 358,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:06:25.236927+00:00",
    "event_record_id": 82,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13020
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Issuance ServiceHost"
      }
    }
  },
  "message": ""
}

Event ID 358 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 359 — An error occurred during an attempt to restart data1.

Provider
AD FS
Channel
Admin

Description

An error occurred during an attempt to restart data1.

Message #

An error occurred during an attempt to restart %1. 

Additional Data 

Exception details: 
%2 

User Action 
 Restart the Federation Service to recover from the error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 359 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during an attempt to restart .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 360 — A request was made to a certificate transport endpoint, but the request did not include a client certificate.

Provider
AD FS
Channel
Admin

Message #

A request was made to a certificate transport endpoint, but the request did not include a client certificate. This could be because the root CA certificate that issued the client certificate is not in the Trust CA certificate store or because the client certificate is expired. 

User Action: 
Ensure that the CA that issued the client certificate in this request has its certificate in the Trusted Root Certificate Authority store on the Local Computer. 
Ensure that the client certificate is not expired.

Event ID 360 —

Provider
AD FS
Channel
Unknown

Event ID 362 — Encountered error during federation passive sign-out.

Provider
AD FS
Channel
Admin

Description

Encountered error during federation passive sign-out.

Message #

Encountered error during federation passive sign-out. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 362 —

Provider
AD FS
Channel
Unknown

Description

Encountered error during federation passive sign-out.

Fields #

NameDescription
data1 UnicodeString

Event ID 363 — A communication error occurred during an attempt to get a token from the Federation Service.

Provider
AD FS
Channel
Admin

Description

A communication error occurred during an attempt to get a token from the Federation Service. Make sure that the Federation Service is running.

Message #

A communication error occurred during an attempt to get a token from the Federation Service. Make sure that the Federation Service is running. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 363 —

Provider
AD FS
Channel
Unknown

Description

A communication error occurred during an attempt to get a token from the Federation Service. Make sure that the Federation Service is running.

Fields #

NameDescription
data1 UnicodeString

Event ID 364 — Encountered error during federation passive request.

Provider
AD FS
Channel
Admin
Level
Error

Description

Encountered error during federation passive request.

Message #

Encountered error during federation passive request. 

Additional Data 

Protocol Name: 
%1 

Relying Party: 
%2 

Exception details: 
%3

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 364,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:52.936421+00:00",
    "event_record_id": 109,
    "correlation": {
      "ActivityID": "E915B92E-2E46-4CB5-0900-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "OAuthAuthorizationProtocol",
          "",
          "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\r\n   at Microsoft.IdentityServer.Web.Protocols.ProtocolContext.Validate()\r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationProtocolHandler.GetRequiredPipelineBehaviors(ProtocolContext pContext)\r\n   at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context)\r\n\r\n"
        ]
      }
    }
  },
  "message": ""
}

Event ID 364 —

Provider
AD FS
Channel
Unknown

Description

Encountered error during federation passive request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 365 — A token request was received for the relying party 'data1', but the request could not be fulfilled because the relying party trust is not enabled.

Provider
AD FS
Channel
Admin

Description

A token request was received for the relying party 'data1', but the request could not be fulfilled because the relying party trust is not enabled.

Message #

A token request was received for the relying party '%1', but the request could not be fulfilled because the relying party trust is not enabled. 
Relying party: %1 

This request failed. 

User Action 
If this relying party trust should be enabled, enable it by using the AD FS Management snap-in or Windows PowerShell for AD FS.

Fields #

NameDescription
data1 UnicodeString

Event ID 365 —

Provider
AD FS
Channel
Unknown

Description

A token request was received for the relying party 'data1', but the request could not be fulfilled because the relying party trust is not enabled.

Fields #

NameDescription
data1 UnicodeString

Event ID 366 — A token was received from claims provider 'data1', but the token could not be validated because the claims provider trust is not enabled.

Provider
AD FS
Channel
Admin

Description

A token was received from claims provider 'data1', but the token could not be validated because the claims provider trust is not enabled.

Message #

A token was received from claims provider '%1', but the token could not be validated because the claims provider trust is not enabled. 
Claims provider: %1 

This request failed. 

User Action 
If this claims provider trust should be enabled, enable it by using the AD FS Management snap-in or Windows PowerShell for AD FS.

Fields #

NameDescription
data1 UnicodeString

Event ID 366 —

Provider
AD FS
Channel
Unknown

Description

A token was received from claims provider 'data1', but the token could not be validated because the claims provider trust is not enabled.

Fields #

NameDescription
data1 UnicodeString

Event ID 367 — The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federati...

Provider
AD FS
Channel
Admin

Description

The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federation Service.

Message #

The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federation Service. 

User Action 
See the exception details for the audience identifier that failed validation. If the audience identifier identifies this Federation Service, add the audience identifier to the acceptable identifiers list by using Windows PowerShell for AD FS.  Note that the audience identifier is used to verify whether the token was sent to this Federation Service. If you think that the audience identifier does not identify your Federation Service, adding it to the acceptable identifiers list may open a security vulnerability in your system. 

Additional Data 

Token Type: 
%1 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 367 —

Provider
AD FS
Channel
Unknown

Description

The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 368 — The SAML Single Logout request does not correspond to the logged-in session participant.

Provider
AD FS
Channel
Admin

Description

The SAML Single Logout request does not correspond to the logged-in session participant.

Message #

The SAML Single Logout request does not correspond to the logged-in session participant. 
Requestor: %1 
Request name identifier: %2 
Logged-in session participants: 
%3  

This request failed. 

User Action 
Verify that the claim provider trust or the relying party trust configuration is up to date. If the name identifier in the request is different from the name identifier in the session only by NameQualifier or SPNameQualifier, check and correct the name identifier policy issuance rule using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 368 —

Provider
AD FS
Channel
Unknown

Description

The SAML Single Logout request does not correspond to the logged-in session participant.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 369 — Processing TTP request failed with the following exception.

Provider
AD FS
Channel
Admin

Description

Processing TTP request failed with the following exception.

Message #

Processing TTP request failed with the following exception. 

Additional Data 

Exception details: 
%1 

User Action 
Ensure that user has enabled cookies in browser settings.

Fields #

NameDescription
data1 UnicodeString

Event ID 369 —

Provider
AD FS
Channel
Unknown

Description

Processing TTP request failed with the following exception.

Fields #

NameDescription
data1 UnicodeString

Event ID 370 — Incoming TTP response is not valid.

Provider
AD FS
Channel
Admin

Description

Incoming TTP response is not valid. Processing response failed with following exception.

Message #

Incoming TTP response is not valid. Processing response failed with following exception. 

Additional Data 

Exception details: 
%1 

User Action 
Ensure that partner federation provider is configured properly to send valid TTP response.

Fields #

NameDescription
data1 UnicodeString

Event ID 370 —

Provider
AD FS
Channel
Unknown

Description

Incoming TTP response is not valid. Processing response failed with following exception.

Fields #

NameDescription
data1 UnicodeString

Event ID 371 — Cannot find certificate to validate message/token signature obtained from claims provider.

Provider
AD FS
Channel
Admin

Description

Cannot find certificate to validate message/token signature obtained from claims provider.

Message #

Cannot find certificate to validate message/token signature obtained from claims provider. 
Claims provider: %1 

This request failed. 

User Action 
Check that Claim Provider Trust configuration is up to date.

Fields #

NameDescription
data1 UnicodeString

Event ID 371 —

Provider
AD FS
Channel
Unknown

Description

Cannot find certificate to validate message/token signature obtained from claims provider.

Fields #

NameDescription
data1 UnicodeString

Event ID 372 — Authentication Failed.

Provider
AD FS
Channel
Admin

Description

Authentication Failed. The token used to authenticate the user is signed using a weaker signature algorithm than expected.

Message #

Authentication Failed. The token used to authenticate the user is signed using a weaker signature algorithm than expected. 

Additional Data 
 Token Type: %1 
 Issuer: %2 
 Actual token signature algorithm: %3 
 Expected token signature algorithm: %4  

User Action 
Check that Claim Provider is configured to accept tokens with expected signature algorithm.  
Use the AD FS PowerShell commands to configure the signature algorithm property.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 372 —

Provider
AD FS
Channel
Unknown

Description

Authentication Failed. The token used to authenticate the user is signed using a weaker signature algorithm than expected.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 373 — The artifact request from the replying party is signed with a weaker signature algorithm.

Provider
AD FS
Channel
Admin

Description

The artifact request from the replying party is signed with a weaker signature algorithm.

Message #

The artifact request from the replying party is signed with a weaker signature algorithm. 

Additional Data 
Relying party identity: %1 
Actual message signature algorithm: %2 
Expected message signature algorithm: %3 

User action: 
Check that relying party is configured to accept artifact resolution request with expected signature algorithm. 
Use the AD FS PowerShell commands to configure the signature algorithm property.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 373 —

Provider
AD FS
Channel
Unknown

Description

The artifact request from the replying party is signed with a weaker signature algorithm.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 374 — An error occurred while building the certificate chain for the claims provider trust 'data1' certificate identified by thumbprint 'data2'.

Provider
AD FS
Channel
Admin

Message #

An error occurred while building the certificate chain for the claims provider trust '%1' certificate identified by thumbprint '%2'.  The certificate chain could not be built, the certificate has been revoked, or the certificate chain could not be verified as specified by the claims provider trust's encryption certificate revocation settings. 

AD FS powershell commands can be used to configure the claims provider trust encryption certificate revocation settings. 
Claims Provider Trust Encryption Certificate Revocation Settings: %3 
The following errors occurred while building the certificate chain:  
%4 
User Action: 
Ensure that the claims provider trust's encryption certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 374 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 375 — Policy store synchronization initiated.

Provider
AD FS
Channel
Admin

Description

Policy store synchronization initiated.

Message #

Policy store synchronization initiated.

Event ID 375 —

Provider
AD FS
Channel
Unknown

Description

Policy store synchronization initiated.

Event ID 376 — An Error occurred while executing a query in SQL attribute store.

Provider
AD FS
Channel
Admin

Description

An Error occurred while executing a query in SQL attribute store.

Message #

An Error occurred while executing a query in SQL attribute store. 

Additional Data 
 Connection information: %1 
 Query: %2 
 Parameters: %3 

User Action 
Examine the exception details to take one or more of the following actions if applicable. 
  Verify that the connection string to the SQL attribute store is valid. 
  Make sure that the SQL attribute store can be reached by the connection string and the SQL attribute store exists. 
  Verify that the SQL query and parameters are valid. 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 376 —

Provider
AD FS
Channel
Unknown

Description

An Error occurred while executing a query in SQL attribute store.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 377 — A processing error occurred in an attribute store.

Provider
AD FS
Channel
Admin

Description

A processing error occurred in an attribute store.

Message #

A processing error occurred in an attribute store. 

User Action 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 377 —

Provider
AD FS
Channel
Unknown

Description

A processing error occurred in an attribute store.

Fields #

NameDescription
data1 UnicodeString

Event ID 378 — SAML request is not signed with expected signature algorithm.

Provider
AD FS
Channel
Admin

Description

SAML request is not signed with expected signature algorithm. SAML request is signed with signature algorithm data1 . Expected signature algorithm is data2.

Message #

SAML request is not signed with expected signature algorithm. SAML request is signed with signature algorithm %1 . Expected signature algorithm is %2 

User Action: 
Verify that signature algorithm for the partner is configured as expected.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 378 —

Provider
AD FS
Channel
Unknown

Description

SAML request is not signed with expected signature algorithm. SAML request is signed with signature algorithm . Expected signature algorithm is.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 379 — A security token was rejected as the specified IssueInstant was before the allowed time frame.

Provider
AD FS
Channel
Admin

Description

A security token was rejected as the specified IssueInstant was before the allowed time frame.

Message #

A security token was rejected as the specified IssueInstant was before the allowed time frame. 

Token Type: 
%1 

User Action: 
 To allow tokens for a larger timeframe, use the AD FS PowerShell commands to adjust the value of the ReplayCacheExpirationInterval.

Fields #

NameDescription
data1 UnicodeString

Event ID 379 —

Provider
AD FS
Channel
Unknown

Description

A security token was rejected as the specified IssueInstant was before the allowed time frame.

Fields #

NameDescription
data1 UnicodeString

Event ID 380 — During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

Provider
AD FS
Channel
Admin

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The certificate that was configured could not be used. The certificate has been revoked, the certificate chain could not be verified or certificate is not within its validity period. The following are the values of the certificate: 
Element: %1 
Subject: %2 
Thumbprint: %3 

The Federation Service will not be able to start until this configuration element is corrected. 

User Action 
Verify whether the certificate chain for the certificate configured has been revoked by its certificate authority. 
If the certificate has been revoked or expired, the AD FS service must be issued a new certificate.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 380 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 381 — An error occurred during an attempt to build the certificate chain for configuration certificate identified by thumbprint 'data1'.

Provider
AD FS
Channel
Admin

Message #

An error occurred during an attempt to build the certificate chain for configuration certificate identified by thumbprint '%1'. Possible causes are that the certificate has been revoked or certificate is not within its validity period. 
The following errors occurred while building the certificate chain:  
%2 

User Action: 
Ensure that the certificate is valid and has not been revoked or expired.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 381 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 382 — AD FS detected that the Federation Service has more than data1 data2 trusts configured and that the data in the AD FS configuration database for this Fed...

Provider
AD FS
Channel
Admin

Message #

AD FS detected that the Federation Service has more than %1 %2 trusts configured and that the data in the AD FS configuration database for this Federation Service is stored and synchronized using Windows Internal Database technology. The overall performance of data synchronization between configuration databases that are stored locally on federation servers across the farm will degrade as you add more than %1 trusts when you use the Windows Internal Database to store the AD FS configuration database. 

User Action: 
To improve synchronization performance across your federation server farm, we recommend that you migrate the data in the AD FS configuration database to SQL server. For more information about how to do this, see AD FS Operations Guide (http://go.microsoft.com/fwlink/?LinkId=181189).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 382 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 383 — The Web request failed because the web.

Provider
AD FS
Channel
Admin

Description

The Web request failed because the web.config file is malformed.

Message #

The Web request failed because the web.config file is malformed. 

User Action: 
Fix the malformed data in the web.config file. 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 383 —

Provider
AD FS
Channel
Unknown

Description

The Web request failed because the web.config file is malformed.

Fields #

NameDescription
data1 UnicodeString

Event ID 384 — The request to the Federation Service failed because the web.

Provider
AD FS
Channel
Admin

Description

The request to the Federation Service failed because the web.config file has an invalid configuration for 'data1' that the Federation Service does not support.

Message #

The request to the Federation Service failed because the web.config file has an invalid  configuration for '%1' that the Federation Service does not support. 

User Action: Ensure that the configuration of the property '%1' is supported by the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 384 —

Provider
AD FS
Channel
Unknown

Description

The request to the Federation Service failed because the web.config file has an invalid configuration for 'data1' that the Federation Service does not support.

Fields #

NameDescription
data1 UnicodeString

Event ID 385 — AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire s...

Provider
AD FS
Channel
Admin

Description

AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon. See additional details for more information.

Message #

AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon. See additional details for more information 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 385 —

Provider
AD FS
Channel
Unknown

Description

AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon. See additional details for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 386 — AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire.

Provider
AD FS
Channel
Admin
Level
Informational

Description

AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire.

Message #

AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 386,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.125743+00:00",
    "event_record_id": 76,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 9156
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 386 —

Provider
AD FS
Channel
Unknown

Description

AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire.

Event ID 387 — AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD F...

Provider
AD FS
Channel
Admin

Description

AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service.

Message #

AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service. 

User Action: Ensure that the AD FS service account has read permissions on the certificate private keys. 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 387 —

Provider
AD FS
Channel
Unknown

Description

AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 388 — AD FS detected that all the service certificates have appropriate access given to the AD FS service account.

Provider
AD FS
Channel
Admin
Level
Informational

Description

AD FS detected that all the service certificates have appropriate access given to the AD FS service account.

Message #

AD FS detected that all the service certificates have appropriate access given to the AD FS service account.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 388,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.126174+00:00",
    "event_record_id": 77,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 11756
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 388 —

Provider
AD FS
Channel
Unknown

Description

AD FS detected that all the service certificates have appropriate access given to the AD FS service account.

Event ID 389 — AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon.

Provider
AD FS
Channel
Admin

Description

AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon. See additional details for more information.

Message #

AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon. See additional details for more information 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 389 —

Provider
AD FS
Channel
Unknown

Description

AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon. See additional details for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 390 — AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire.

Provider
AD FS
Channel
Admin
Level
Informational

Description

AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire.

Message #

AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 390,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.154591+00:00",
    "event_record_id": 79,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 9156
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 390 —

Provider
AD FS
Channel
Unknown

Description

AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire.

Event ID 392 — The federation server proxy was able to successfully renew its trust with the Federation Service.

Provider
AD FS
Channel
Admin

Description

The federation server proxy was able to successfully renew its trust with the Federation Service.

Message #

The federation server proxy was able to successfully renew its trust with the Federation Service.  

Proxy trust certificate subject: %1. 
Proxy trust certificate old thumbprint: %2. 
Proxy trust certificate new thumbprint: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 392 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy was able to successfully renew its trust with the Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 393 — The federation server proxy could not establish a trust with the Federation Service.

Provider
AD FS
Channel
Admin

Description

The federation server proxy could not establish a trust with the Federation Service.

Message #

The federation server proxy could not establish a trust with the Federation Service. 

Additional Data 
Exception details: 
%1 

User Action 
Ensure that the credentials being used to establish a trust between the federation server proxy and the Federation Service are valid and that the Federation Service can be reached.

Fields #

NameDescription
data1 UnicodeString

Event ID 393 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy could not establish a trust with the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 394 — The federation server proxy could not renew its trust with the Federation Service.

Provider
AD FS
Channel
Admin

Description

The federation server proxy could not renew its trust with the Federation Service.

Message #

The federation server proxy could not renew its trust with the Federation Service.  

Additional Data 
Exception details: 
%1 

User Action 
Ensure that the federation server proxy is trusted by the Federation Service. If the trust does not exist or has been revoked, establish a trust between the proxy and the Federation Service using the Federation Service Proxy Configuration Wizard by logging on to the proxy computer.

Fields #

NameDescription
data1 UnicodeString

Event ID 394 —

Provider
AD FS
Channel
Unknown

Description

The federation server proxy could not renew its trust with the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 395 — The trust between the federation server proxy and the Federation Service was established successfully using the account 'data1'.

Provider
AD FS
Channel
Admin

Description

The trust between the federation server proxy and the Federation Service was established successfully using the account 'data1'.

Message #

The trust between the federation server proxy and the Federation Service was established successfully using the account '%1'. 

Proxy trust certificate subject: %2. 
Proxy trust certificate thumbprint: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 395 —

Provider
AD FS
Channel
Unknown

Description

The trust between the federation server proxy and the Federation Service was established successfully using the account 'data1'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 396 — The trust between the federation server proxy and the Federation Service was renewed successfully.

Provider
AD FS
Channel
Admin

Description

The trust between the federation server proxy and the Federation Service was renewed successfully.

Message #

The trust between the federation server proxy and the Federation Service was renewed successfully. 

Proxy trust certificate subject: %1. 
Proxy trust certificate old thumbprint: %2. 
Proxy trust certificate new thumbprint: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 396 —

Provider
AD FS
Channel
Unknown

Description

The trust between the federation server proxy and the Federation Service was renewed successfully.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 397 — The federation server loaded the HTTP proxy configuration from WinHTTP settings.

Provider
AD FS
Channel
Admin
Level
Informational

Description

The federation server loaded the HTTP proxy configuration from WinHTTP settings.

Message #

The federation server loaded the HTTP proxy configuration from WinHTTP settings. 

HTTP Proxy: %1 
HTTPS Proxy: %2 
Bypass proxy for local addresses: %3 
Bypass proxy for addresses: %4 

To learn more about how to set the HTTP proxy settings for the federation server, see http://go.microsoft.com/fwlink/?LinkId=182180.

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 397,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:50.877782+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 12484
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "",
          "",
          "",
          "\r\n"
        ]
      }
    }
  },
  "message": ""
}

Event ID 397 —

Provider
AD FS
Channel
Unknown

Description

The federation server loaded the HTTP proxy configuration from WinHTTP settings.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 398 — AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived.

Provider
AD FS
Channel
Admin

Description

AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived.

Message #

AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived. 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 398 —

Provider
AD FS
Channel
Unknown

Description

AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived.

Fields #

NameDescription
data1 UnicodeString

Event ID 399 — AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived.

Provider
AD FS
Channel
Admin
Level
Informational

Description

AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived.

Message #

AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 399,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.121989+00:00",
    "event_record_id": 74,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 9156
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 399 —

Provider
AD FS
Channel
Unknown

Description

AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived.

Event ID 400 — VSS writer permissions have been granted to user data1.

Provider
AD FS
Channel
Admin

Description

VSS writer permissions have been granted to user data1.

Message #

VSS writer permissions have been granted to user %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 400 —

Provider
AD FS
Channel
Unknown

Description

VSS writer permissions have been granted to user .

Fields #

NameDescription
data1 UnicodeString

Event ID 401 — VSS writer permissions have been revoked from user data1.

Provider
AD FS
Channel
Admin

Description

VSS writer permissions have been revoked from user data1.

Message #

VSS writer permissions have been revoked from user %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 401 —

Provider
AD FS
Channel
Unknown

Description

VSS writer permissions have been revoked from user .

Fields #

NameDescription
data1 UnicodeString

Event ID 402 — Failed to add some of the certificate claims.

Provider
AD FS
Channel
Admin

Description

Failed to add some of the certificate claims.

Message #

Failed to add some of the certificate claims.

Event ID 402 —

Provider
AD FS
Channel
Unknown

Description

Failed to add some of the certificate claims.

Event ID 407 — Password change failed for following user.

Provider
AD FS
Channel
Admin

Description

Password change failed for following user.

Message #

Password change failed for following user: 

Additional Data 

User: 
%1 

Server on which password change was attempted: 
%2 
Error details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 407 —

Provider
AD FS
Channel
Unknown

Description

Password change failed for following user.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 414 — An error occurred during processing of a token request.

Provider
AD FS
Channel
Admin

Description

An error occurred during processing of a token request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.

Message #

An error occurred during processing of a token request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.  

Additional Data 

Activity ID:
 %1 

Target Relying Party:
 %2 

Is Application Proxy Configured:
 %3 

Is Request From the Extranet:
 %4 

User action: 
Use the Activity ID data in this message to search and correlate the data to events in the Event log using Event Viewer. This Activity ID will also be shown as additional information in the error page when an error occurs in the federation passive Web application.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 414 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during processing of a token request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 415 —

Provider
AD FS
Channel
Admin

Message #

%1

Fields #

NameDescription
data1 UnicodeString

Event ID 415 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 416 — Web configuration error: data1.

Provider
AD FS
Channel
Admin

Description

Web configuration error: data1.

Message #

Web configuration error: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 416 —

Provider
AD FS
Channel
Unknown

Description

Web configuration error.

Fields #

NameDescription
data1 UnicodeString

Event ID 417 — Unable to add the certificate claim data1.

Provider
AD FS
Channel
Admin

Description

Unable to add the certificate claim data1.

Message #

Unable to add the certificate claim %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 417 —

Provider
AD FS
Channel
Unknown

Description

Unable to add the certificate claim .

Fields #

NameDescription
data1 UnicodeString

Event ID 418 — The trust between the federation server proxy and the Federation Service was successfully renewed.

Provider
AD FS
Channel
Admin

Description

The trust between the federation server proxy and the Federation Service was successfully renewed.

Message #

The trust between the federation server proxy and the Federation Service was successfully renewed. 

Additional Data 

Server from which request was made: 
%1 
Certificate Subject: 
%2 
Old Certificate Thumbprint: 
%3 
New Certificate Thumbprint: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 418 —

Provider
AD FS
Channel
Unknown

Description

The trust between the federation server proxy and the Federation Service was successfully renewed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 419 — Unable to renew the trust between the federation server proxy and the Federation Service.

Provider
AD FS
Channel
Admin

Description

Unable to renew the trust between the federation server proxy and the Federation Service.

Message #

Unable to renew the trust between the federation server proxy and the Federation Service. 

Additional Data 

Server from which request was made: 
%1 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 419 —

Provider
AD FS
Channel
Unknown

Description

Unable to renew the trust between the federation server proxy and the Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 420 — The trust between the federation server proxy and the Federation Service was successfully established.

Provider
AD FS
Channel
Admin

Description

The trust between the federation server proxy and the Federation Service was successfully established.

Message #

The trust between the federation server proxy and the Federation Service was successfully established. 

Additional Data 

User: 
%1 

Server from which request was made: 
%2 
Certificate Subject: 
%3 
Certificate Thumbprint: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 420 —

Provider
AD FS
Channel
Unknown

Description

The trust between the federation server proxy and the Federation Service was successfully established.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 421 — The trust between the federation server proxy and the Federation Service could not be established.

Provider
AD FS
Channel
Admin

Description

The trust between the federation server proxy and the Federation Service could not be established.

Message #

The trust between the federation server proxy and the Federation Service could not be established. 

Additional Data 

User: 
%1 

Server from which request was made: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 421 —

Provider
AD FS
Channel
Unknown

Description

The trust between the federation server proxy and the Federation Service could not be established.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 432 — Error handling request from proxy at data1.

Provider
AD FS
Channel
Admin

Description

Error handling request from proxy at data1.

Message #

Error handling request from proxy at %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 432 —

Provider
AD FS
Channel
Unknown

Description

Error handling request from proxy at.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 433 — Error encountered while renewing trust with the federation server proxy.

Provider
AD FS
Channel
Admin

Description

Error encountered while renewing trust with the federation server proxy.

Message #

Error encountered while renewing trust with the federation server proxy.  

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 433 —

Provider
AD FS
Channel
Unknown

Description

Error encountered while renewing trust with the federation server proxy.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 434 — The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) will expire at data2 UTC.

Provider
AD FS
Channel
Admin

Description

The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) will expire at data2 UTC.

Message #

The primary AD FS certificate authority issuer certificate ( thumbprint %1 ) will expire at %2 UTC. 
The certificate rollover service will roll over to the current secondary ( thumbprint %3 ) at %4 UTC. 
To avoid certificate issuance service interruption, ensure that the current secondary certificate ( thumbprint %3 ) is installed in Active Directory before the rollover occurs at %4 UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 434 —

Provider
AD FS
Channel
Unknown

Description

The primary AD FS certificate authority issuer certificate ( thumbprint ) will expire at UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 435 — The primary AD FS token signing certificate ( thumbprint data1 ) will expire at data2 UTC.

Provider
AD FS
Channel
Admin

Description

The primary AD FS token signing certificate ( thumbprint data1 ) will expire at data2 UTC.

Message #

The primary AD FS token signing certificate ( thumbprint %1 ) will expire at %2 UTC. 
The certificate rollover service will roll over to the current secondary ( thumbprint %3 ) at %4 UTC. 
Relying parties that rely on federation metadata will be notified automatically; any relying parties that do not rely on federation metadata must be informed of the new certificate before the rollover at %4 UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 435 —

Provider
AD FS
Channel
Unknown

Description

The primary AD FS token signing certificate ( thumbprint ) will expire at UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 436 — The primary AD FS token decryption certificate ( thumbprint data1 ) will expire at data2 UTC.

Provider
AD FS
Channel
Admin

Description

The primary AD FS token decryption certificate ( thumbprint data1 ) will expire at data2 UTC.

Message #

The primary AD FS token decryption certificate ( thumbprint %1 ) will expire at %2 UTC. 
The certificate rollover service will roll over to the current secondary ( thumbprint %3 ) at %4 UTC. 
Identity providers that rely on federation metadata will be notified automatically; any identity providers that send encrypted tokens to AD FS and do not rely on federation metadata must be informed of the new certificate before the expiration at %2 UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 436 —

Provider
AD FS
Channel
Unknown

Description

The primary AD FS token decryption certificate ( thumbprint ) will expire at UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 437 — Error encountered while checking for pending certificate rollovers.

Provider
AD FS
Channel
Admin

Description

Error encountered while checking for pending certificate rollovers.

Message #

Error encountered while checking for pending certificate rollovers. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC. 
If this issue persists, AD FS will not be able to advise of pending certificate rollover events. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 437 —

Provider
AD FS
Channel
Unknown

Description

Error encountered while checking for pending certificate rollovers.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 438 — Error encountered while checking rollover status of the AD FS certificate authority issuer certificate.

Provider
AD FS
Channel
Admin

Description

Error encountered while checking rollover status of the AD FS certificate authority issuer certificate.

Message #

Error encountered while checking rollover status of the AD FS certificate authority issuer certificate. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC.  Future runs may occur on other farm nodes if AD FS is running in a farm configuration. 
If this issue persists, the AD FS certificate authority issuer certificate cannot be rolled over successfully when it nears expiry. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 438 —

Provider
AD FS
Channel
Unknown

Description

Error encountered while checking rollover status of the AD FS certificate authority issuer certificate.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 439 — Error encountered while attempting to read an enrollment certificate from a template.

Provider
AD FS
Channel
Admin

Description

Error encountered while attempting to read an enrollment certificate from a template.

Message #

Error encountered while attempting to read an enrollment certificate from a template. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 439 —

Provider
AD FS
Channel
Unknown

Description

Error encountered while attempting to read an enrollment certificate from a template.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 440 — A Certificate Authority Enrollment Certificate was found.

Provider
AD FS
Channel
Admin

Description

A Certificate Authority Enrollment Certificate was found.

Message #

A Certificate Authority Enrollment Certificate was found. 

Additional Data 

Certificate Thumbprint: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 440 —

Provider
AD FS
Channel
Unknown

Description

A Certificate Authority Enrollment Certificate was found.

Fields #

NameDescription
data1 UnicodeString

Event ID 441 — A token with a bad token binding key was found.

Provider
AD FS
Channel
Admin

Description

A token with a bad token binding key was found.

Message #

A token with a bad token binding key was found. 

Additional Data 

User: %1 
Target RP: %2 
Client IP: %3 
Token Binding ID: %4 
Request Provided ID: %5 
Request Referred ID: %6

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 441 —

Provider
AD FS
Channel
Unknown

Description

A token with a bad token binding key was found.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 442 — The CA enrollment certificate management cycle was initiated.

Provider
AD FS
Channel
Admin

Description

The CA enrollment certificate management cycle was initiated.

Message #

The CA enrollment certificate management cycle was initiated.

Event ID 442 —

Provider
AD FS
Channel
Unknown

Description

The CA enrollment certificate management cycle was initiated.

Event ID 443 — The CA enrollment certificate management cycle was completed.

Provider
AD FS
Channel
Admin

Description

The CA enrollment certificate management cycle was completed.

Message #

The CA enrollment certificate management cycle was completed.

Event ID 443 —

Provider
AD FS
Channel
Unknown

Description

The CA enrollment certificate management cycle was completed.

Event ID 444 — Error encountered while checking status of the AD FS enrollment certificate.

Provider
AD FS
Channel
Admin

Description

Error encountered while checking status of the AD FS enrollment certificate.

Message #

Error encountered while checking status of the AD FS enrollment certificate. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC. 
If this issue persists, the AD FS will not be able to enroll certificate. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 444 —

Provider
AD FS
Channel
Unknown

Description

Error encountered while checking status of the AD FS enrollment certificate.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 445 — A token with no binding was received on a request which is token-binding-capable.

Provider
AD FS
Channel
Admin

Description

A token with no binding was received on a request which is token-binding-capable.

Message #

A token with no binding was received on a request which is token-binding-capable.  
This could be evidence of a possible downgrade attack, or it could mean the token originally came from a server that doesn't support token binding. 

Additional Data 

User: %1 
Target RP: %2 
Client IP: %3 
Request Provided ID: %4 
Request Referred ID: %5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 445 —

Provider
AD FS
Channel
Unknown

Description

A token with no binding was received on a request which is token-binding-capable.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 446 — An SSO token with no binding was received on a request which is token-binding-capable.

Provider
AD FS
Channel
Admin

Description

An SSO token with no binding was received on a request which is token-binding-capable. This is evidence of a possible downgrade attack.

Message #

An SSO token with no binding was received on a request which is token-binding-capable. This is evidence of a possible downgrade attack.  

Additional Data 

User: %1 
Target RP: %2 
Client IP: %3 
Request Provided ID: %4 
Request Referred ID: %5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 446 —

Provider
AD FS
Channel
Unknown

Description

An SSO token with no binding was received on a request which is token-binding-capable. This is evidence of a possible downgrade attack.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 447 — Error encountered while attempting to update the configuration policy for the template data1.

Provider
AD FS
Channel
Admin

Description

Error encountered while attempting to update the configuration policy for the template data1. If the template is published under machine policy, service might not be able to read it.

Message #

Error encountered while attempting to update the configuration policy for the template %1. If the template is published under machine policy, service might not be able to read it. 
See https://go.microsoft.com/fwlink/?linkid=852318 for more information. 

Exception details: UpdateMachinePolicyConfigurationForTemplate returned error: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 447 —

Provider
AD FS
Channel
Unknown

Description

Error encountered while attempting to update the configuration policy for the template . If the template is published under machine policy, service might not be able to read it.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 448 — Error encountered while attempting to add a leased task to the database.

Provider
AD FS
Channel
Admin

Description

Error encountered while attempting to add a leased task to the database.

Message #

Error encountered while attempting to add a leased task to the database. 

Additional Data: 

Task name: %1 
Error: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 448 —

Provider
AD FS
Channel
Unknown

Description

Error encountered while attempting to add a leased task to the database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 449 — Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task.

Provider
AD FS
Channel
Admin

Description

Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task.

Message #

Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task. 

Additional Data: 

Error: %1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 449 —

Provider
AD FS
Channel
Unknown

Description

Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 450 — Error encountered while removing the expired items from the usercode cache.

Provider
AD FS
Channel
Admin

Description

Error encountered while removing the expired items from the usercode cache.

Message #

Error encountered while removing the expired items from the usercode cache. 

Additional Data: 

Error: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 450 —

Provider
AD FS
Channel
Unknown

Description

Error encountered while removing the expired items from the usercode cache.

Fields #

NameDescription
data1 UnicodeString

Event ID 451 — Following nodes have the reported heartbeat older than data1 UTC and will be deleted.

Provider
AD FS
Channel
Admin

Description

Following nodes have the reported heartbeat older than data1 UTC and will be deleted.

Message #

Following nodes have the reported heartbeat older than %1 UTC and will be deleted. 

%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 451 —

Provider
AD FS
Channel
Unknown

Description

Following nodes have the reported heartbeat older than UTC and will be deleted.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 452 —

Provider
AD FS
Channel
Admin

Message #

%1

Fields #

NameDescription
data1 UnicodeString

Event ID 452 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 500 — More information for the event entry with Instance ID data1.

Provider
AD FS
Channel
Admin

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID:  
%1 
 

Issued identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 500 —

Provider
AD FS
Channel
Unknown

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 501 — More information for the event entry with Instance ID Event.EventData.

Provider
AD FS
Channel
Admin
Level
Informational

Description

More information for the event entry with Instance ID Event.EventData. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID: 
%1 
 
Caller identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 501,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:37.250884+00:00",
    "event_record_id": 97,
    "correlation": {
      "ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "a6f4ff0b-8776-43a4-9be1-6b9bf86e338f",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname",
          "ludus\\domainadmin",
          "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name",
          "ludus\\domainadmin",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid",
          "S-1-5-21-1006758700-2167138679-1475694448-1105",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-572",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-1149",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-18-1",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-519",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-518",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-512",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-520"
        ]
      }
    }
  },
  "message": ""
}

Event ID 501 —

Provider
AD FS
Channel
Unknown

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 502 — More information for the event entry with Instance ID data1.

Provider
AD FS
Channel
Admin

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID: 
%1 
 
OnBehalfOf identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 502 —

Provider
AD FS
Channel
Unknown

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 503 — More information for the event entry with Instance ID data1.

Provider
AD FS
Channel
Admin

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID: 
%1 
 
ActAs identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 503 —

Provider
AD FS
Channel
Unknown

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 504 — The following update was successful to the application proxy store on the federation server.

Provider
AD FS
Channel
Admin

Description

The following update was successful to the application proxy store on the federation server.

Message #

The following update was successful to the application proxy store on the federation server. 

Authentication information:  
%1 

HTTP method:  
%2 

Key: 
%3 

Value: 
%4 

Version: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 504 —

Provider
AD FS
Channel
Unknown

Description

The following update was successful to the application proxy store on the federation server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 505 — The following update attempt to the application proxy store on the federation server failed.

Provider
AD FS
Channel
Admin

Description

The following update attempt to the application proxy store on the federation server failed.

Message #

The following update attempt to the application proxy store on the federation server failed. 

Authentication information:  
%1 

HTTP method:  
%2 

Key: 
%3 

Value: 
%4 

Version: 
%5 

Error information: 
%6

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 505 —

Provider
AD FS
Channel
Unknown

Description

The following update attempt to the application proxy store on the federation server failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 506 — The following update attempt to the application proxy relying party trust on the federation server succeeded.

Provider
AD FS
Channel
Admin

Description

The following update attempt to the application proxy relying party trust on the federation server succeeded.

Message #

The following update attempt to the application proxy relying party trust on the federation server succeeded. 

Authentication information:  
%1 

HTTP method:  
%2 

Identifier: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 506 —

Provider
AD FS
Channel
Unknown

Description

The following update attempt to the application proxy relying party trust on the federation server succeeded.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 507 — The following update attempt to the application proxy relying party trust on the federation server failed.

Provider
AD FS
Channel
Admin

Description

The following update attempt to the application proxy relying party trust on the federation server failed.

Message #

The following update attempt to the application proxy relying party trust on the federation server failed. 

Authentication information:  
%1 

HTTP method:  
%2 

Identifier: 
%3 

Error information: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 507 —

Provider
AD FS
Channel
Unknown

Description

The following update attempt to the application proxy relying party trust on the federation server failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 508 — The following update attempt to the relying party trust on the federation server succeeded.

Provider
AD FS
Channel
Admin

Description

The following update attempt to the relying party trust on the federation server succeeded.

Message #

The following update attempt to the relying party trust on the federation server succeeded. 

Authentication information:  
%1 

HTTP method:  
%2 

Relying party trust identifier: 
%3 

Internal Url: 
%4 

External Url: 
%5 

Published identifier: 
%6

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 508 —

Provider
AD FS
Channel
Unknown

Description

The following update attempt to the relying party trust on the federation server succeeded.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 509 — The following update attempt to the relying party trust on the federation server failed.

Provider
AD FS
Channel
Admin

Description

The following update attempt to the relying party trust on the federation server failed.

Message #

The following update attempt to the relying party trust on the federation server failed. 

Authentication information:  
%1 

HTTP method:  
%2 

Relying party trust identifier: 
%3 

Internal url: 
%4 

External url: 
%5 

Published identifier: 
%6 

Error information: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 509 —

Provider
AD FS
Channel
Unknown

Description

The following update attempt to the relying party trust on the federation server failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 510 — More information for the event entry with Instance ID data1.

Provider
AD FS
Channel
Admin
Collection Priority
Recommended (ASD)

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 
 
Instance ID:  
%1 
 
Details: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 510 —

Provider
AD FS
Channel
Unknown
Collection Priority
Recommended (ASD)

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 511 — The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

Provider
AD FS
Channel
Admin

Description

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

Message #

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.  

Request url: 
 %1 

User Action:
 Examine the Federation Service configuration and take the following actions: 
  Verify that the sign-in request has all the required parameters and is formatted correctly. 
  Verify that a web application proxy relying party trust exists, is enabled, and has identifiers which match the sign-in request parameters. 
  Verify that the target relying party trust object exists, is published through the web application proxy, and has identifiers which match the sign-in request parameters.

Fields #

NameDescription
data1 UnicodeString

Event ID 511 —

Provider
AD FS
Channel
Unknown

Description

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

Fields #

NameDescription
data1 UnicodeString

Event ID 517 — The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

Provider
AD FS
Channel
Admin

Description

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

Message #

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.  

Request url: 
 %1 

User Action:
 Verify that either an enabled web application proxy relying party trust exists in your Federation Service configuration or that the target relying party trust object is not published through a web application proxy.

Fields #

NameDescription
data1 UnicodeString

Event ID 517 —

Provider
AD FS
Channel
Unknown

Description

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

Fields #

NameDescription
data1 UnicodeString

Event ID 521 — The request for the relying party token resulted in a failure.

Provider
AD FS
Channel
Admin

Description

The request for the relying party token resulted in a failure.

Message #

The request for the relying party token resulted in a failure. 

Authentication information:  
%1 

HTTP method: 
%2 

Username:  
%3 

Password presented:  
%4 

Realm: 
%5 

Application realm:  
%6 

Device registration certificate thumbprint:  
%7 

User certificate thumbprint:  
%8 

Error information: 
%9 

User action: 
Examine the request and verify that at least one of the following parameter sets are present. 
  Username and password 
  Username, password, and device registration certificate 
  User certificate

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString

Event ID 521 —

Provider
AD FS
Channel
Unknown

Description

The request for the relying party token resulted in a failure.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString

Event ID 530 — AD FS could not read the local claims provider trusts from the AD FS configuration.

Provider
AD FS
Channel
Admin

Description

AD FS could not read the local claims provider trusts from the AD FS configuration. AD FS will continue to operating from cached configuration.

Message #

AD FS could not read the local claims provider trusts from the AD FS configuration.  AD FS will continue to operating from cached configuration. 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 530 —

Provider
AD FS
Channel
Unknown

Description

AD FS could not read the local claims provider trusts from the AD FS configuration. AD FS will continue to operating from cached configuration.

Fields #

NameDescription
data1 UnicodeString

Event ID 531 — AD FS could not read the local claims provider trusts from the AD FS configuration.

Provider
AD FS
Channel
Admin

Description

AD FS could not read the local claims provider trusts from the AD FS configuration. AD FS will not function until this configuration can be read for the first time.

Message #

AD FS could not read the local claims provider trusts from the AD FS configuration.  AD FS will not function until this configuration can be read for the first time. 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 531 —

Provider
AD FS
Channel
Unknown

Description

AD FS could not read the local claims provider trusts from the AD FS configuration. AD FS will not function until this configuration can be read for the first time.

Fields #

NameDescription
data1 UnicodeString

Event ID 540 — The Federation Service was was unable to return the OAuth discovery document as a result of an error.

Provider
AD FS
Channel
Admin

Description

The Federation Service was was unable to return the OAuth discovery document as a result of an error.

Message #

The Federation Service was was unable to return the OAuth discovery document as a result of an error. 
Document Path: %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 540 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service was was unable to return the OAuth discovery document as a result of an error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 541 — An invalid value was found during processing of the proxy configuration data from the AD FS server.

Provider
AD FS
Channel
Admin

Description

An invalid value was found during processing of the proxy configuration data from the AD FS server. The value will be ignored, and the rest of the proxy configuration data will be processed.

Message #

An invalid value was found during processing of the proxy configuration data from the AD FS server. The value will be ignored, and the rest of the proxy configuration data will be processed.  

Additional Data 

FarmBehavior: '%1' 

User action: 
This may point to an interoperability issue between the proxy and the AD FS server. Contact the vendor for your AD FS server.

Fields #

NameDescription
data1 UnicodeString

Event ID 541 —

Provider
AD FS
Channel
Unknown

Description

An invalid value was found during processing of the proxy configuration data from the AD FS server. The value will be ignored, and the rest of the proxy configuration data will be processed.

Fields #

NameDescription
data1 UnicodeString

Event ID 542 — There was an error during heartbeat.

Provider
AD FS
Channel
Admin

Description

There was an error during heartbeat.

Message #

There was an error during heartbeat. 

Additional data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 542 —

Provider
AD FS
Channel
Unknown

Description

There was an error during heartbeat.

Fields #

NameDescription
data1 UnicodeString

Event ID 543 — There was an error during heartbeat communicating to primary federation server.

Provider
AD FS
Channel
Admin

Description

There was an error during heartbeat communicating to primary federation server.

Message #

There was an error during heartbeat communicating to primary federation server. 

Primary server: '%1' 

Endpoint: '%2' 

Additional data 

Exception details: 
%3 

User Action 
 Make sure the primary federation server is available or the service account identity of this machine matches the service account identity of the primary federation server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 543 —

Provider
AD FS
Channel
Unknown

Description

There was an error during heartbeat communicating to primary federation server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 544 — Heartbeat is not performed because primary server does not support heartbeat.

Provider
AD FS
Channel
Admin

Description

Heartbeat is not performed because primary server does not support heartbeat.

Message #

Heartbeat is not performed because primary server does not support heartbeat. 

Primary server: '%1'

Fields #

NameDescription
data1 UnicodeString

Event ID 544 —

Provider
AD FS
Channel
Unknown

Description

Heartbeat is not performed because primary server does not support heartbeat.

Fields #

NameDescription
data1 UnicodeString

Event ID 545 — Heartbeat is performed at primary server.

Provider
AD FS
Channel
Admin
Level
Informational

Description

Heartbeat is performed at primary server.

Message #

Heartbeat is performed at primary server. 

Primary server: '%1'

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 545,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:56.798717+00:00",
    "event_record_id": 35,
    "correlation": {
      "ActivityID": "0D26E79C-B333-000D-9A2E-270D33B3DC01"
    },
    "execution": {
      "process_id": 8080,
      "thread_id": 11896
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "localhost"
      }
    }
  },
  "message": ""
}

Event ID 545 —

Provider
AD FS
Channel
Unknown

Description

Heartbeat is performed at primary server.

Fields #

NameDescription
data1 UnicodeString

Event ID 546 — A current tenant certificate for Azure MFA was not found.

Provider
AD FS
Channel
Admin

Description

A current tenant certificate for Azure MFA was not found.

Message #

A current tenant certificate for Azure MFA was not found.  

TenantId: %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 546 —

Provider
AD FS
Channel
Unknown

Description

A current tenant certificate for Azure MFA was not found.

Fields #

NameDescription
data1 UnicodeString

Event ID 547 — The tenant certificate for Azure MFA has been renewed.

Provider
AD FS
Channel
Admin

Description

The tenant certificate for Azure MFA has been renewed.

Message #

The tenant certificate for Azure MFA has been renewed.  

TenantId: %1. 
Old thumbprint: %2. 
Old expiration date: %3. 
New thumbprint: %4. 
New expiration date: %5.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 547 —

Provider
AD FS
Channel
Unknown

Description

The tenant certificate for Azure MFA has been renewed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 548 — The tenant certificate for Azure MFA will expire soon.

Provider
AD FS
Channel
Admin

Description

The tenant certificate for Azure MFA will expire soon.

Message #

The tenant certificate for Azure MFA will expire soon.  

TenantId: %1. 
Thumbprint: %2. 
Expiration date: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 548 —

Provider
AD FS
Channel
Unknown

Description

The tenant certificate for Azure MFA will expire soon.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 549 — The tenant certificate for Azure MFA has expired.

Provider
AD FS
Channel
Admin

Description

The tenant certificate for Azure MFA has expired.

Message #

The tenant certificate for Azure MFA has expired.  

TenantId: %1. 
Thumbprint: %2. 
Expiration date: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 549 —

Provider
AD FS
Channel
Unknown

Description

The tenant certificate for Azure MFA has expired.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 550 — The data1 primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1).

Provider
AD FS
Channel
Admin

Description

The data1 primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1).

Message #

The %1 primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1). 

User Action: This value can be changed by reimporting the certificate from a pfx file.  From an elevated command prompt, use the command "certutil -importpfx filename.pfx AT_KEYEXCHANGE". For more information, see http://go.microsoft.com/fwlink/?LinkId=798501

Fields #

NameDescription
data1 UnicodeString

Event ID 550 —

Provider
AD FS
Channel
Unknown

Description

The primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1).

Fields #

NameDescription
data1 UnicodeString

Event ID 551 — An error occurred during processing of an OAuth logout request.

Provider
AD FS
Channel
Admin

Description

An error occurred during processing of an OAuth logout request.

Message #

An error occurred during processing of an OAuth logout request. 
Path: %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 551 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during processing of an OAuth logout request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 552 — The session cookies were successfully deleted using the OAuth logout path.

Provider
AD FS
Channel
Admin
Level
Informational

Description

The session cookies were successfully deleted using the OAuth logout path.

Message #

The session cookies were successfully deleted using the OAuth logout path.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 552,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:53.219831+00:00",
    "event_record_id": 114,
    "correlation": {
      "ActivityID": "26B7203E-F387-4B80-0E00-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 552 —

Provider
AD FS
Channel
Unknown

Description

The session cookies were successfully deleted using the OAuth logout path.

Event ID 553 — The specified redirect URL was validated successfully.

Provider
AD FS
Channel
Admin

Description

The specified redirect URL was validated successfully.

Message #

The specified redirect URL was validated successfully. 

URL: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 553 —

Provider
AD FS
Channel
Unknown

Description

The specified redirect URL was validated successfully.

Fields #

NameDescription
data1 UnicodeString

Event ID 554 — The specified redirect URL did not match any of the OAuth client's redirect URIs.

Provider
AD FS
Channel
Admin
Level
Error

Description

The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected.

Message #

The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected. 

URL: %1

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 554,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:53.228256+00:00",
    "event_record_id": 115,
    "correlation": {
      "ActivityID": "26B7203E-F387-4B80-0E00-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "https://localhost"
      }
    }
  },
  "message": ""
}

Event ID 554 —

Provider
AD FS
Channel
Unknown

Description

The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected.

Fields #

NameDescription
data1 UnicodeString

Event ID 555 — The Windows Hello for Business key receipt could not be verified.

Provider
AD FS
Channel
Admin

Description

The Windows Hello for Business key receipt could not be verified.

Message #

The Windows Hello for Business key receipt could not be verified. 

Additional Information: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 555 —

Provider
AD FS
Channel
Unknown

Description

The Windows Hello for Business key receipt could not be verified.

Fields #

NameDescription
data1 UnicodeString

Event ID 556 — Error encountered while attempting to select a master node for the account store.

Provider
AD FS
Channel
Admin

Description

Error encountered while attempting to select a master node for the account store.

Message #

Error encountered while attempting to select a master node for the account store. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC.  Future runs may occur on other farm nodes if AD FS is running in a farm configuration. 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 556 —

Provider
AD FS
Channel
Unknown

Description

Error encountered while attempting to select a master node for the account store.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 557 — An error occured while trying to communicate with the account store rest service on node data1.

Provider
AD FS
Channel
Admin

Description

An error occured while trying to communicate with the account store rest service on node data1.

Message #

An error occured while trying to communicate with the account store rest service on node %1.   
If this is a WID farm the primary node may be offline. 
If this is a SQL farm ADFS will automatically select a new node to host the User store master role. 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 557 —

Provider
AD FS
Channel
Unknown

Description

An error occured while trying to communicate with the account store rest service on node .

Fields #

NameDescription
data1 UnicodeString

Event ID 558 — Syncronization of the Account Activity data failed.

Provider
AD FS
Channel
Admin

Description

Syncronization of the Account Activity data failed.

Message #

Syncronization of the Account Activity data failed. 

Additional Data 
Exception message: 
%1 

User Action 
Ensure that the artifact storage server is configured properly. Troubleshoot network connectivity to the artifact storage server.  
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 558 —

Provider
AD FS
Channel
Unknown

Description

Syncronization of the Account Activity data failed.

Fields #

NameDescription
data1 UnicodeString

Event ID 559 — Device authentication using PKeyAuth failed.

Provider
AD FS
Channel
Admin

Description

Device authentication using PKeyAuth failed. Request might continue without device authentication.

Message #

Device authentication using PKeyAuth failed. Request might continue without device authentication. 

Additional Information: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 559 —

Provider
AD FS
Channel
Unknown

Description

Device authentication using PKeyAuth failed. Request might continue without device authentication.

Fields #

NameDescription
data1 UnicodeString

Event ID 560 — User data1 could not be found in the account database.

Provider
AD FS
Channel
Admin

Description

User data1 could not be found in the account database.

Message #

User %1 could not be found in the account database.

Fields #

NameDescription
data1 UnicodeString

Event ID 560 —

Provider
AD FS
Channel
Unknown

Description

User could not be found in the account database.

Fields #

NameDescription
data1 UnicodeString

Event ID 561 — Authorization failed when connecting to the account store endpoint on server data1.

Provider
AD FS
Channel
Admin

Description

Authorization failed when connecting to the account store endpoint on server data1.

Message #

Authorization failed when connecting to the account store endpoint on server %1 

Additional Data 

Exception Message: 
%2 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 561 —

Provider
AD FS
Channel
Unknown

Description

Authorization failed when connecting to the account store endpoint on server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 562 — An error occurred when communcating with the account store endpoint on server data1.

Provider
AD FS
Channel
Admin

Description

An error occurred when communcating with the account store endpoint on server data1.

Message #

An error occurred when communcating with the account store endpoint on server %1. 

Additional Data 

Exception Message: 
%2 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 562 —

Provider
AD FS
Channel
Unknown

Description

An error occurred when communcating with the account store endpoint on server .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 563 — An error occurred while calculating extranet lockout status.

Provider
AD FS
Channel
Admin

Description

An error occurred while calculating extranet lockout status. Due to the value of the data1 setting authentication will be allowed for this user and token issuance will continue.

Message #

An error occurred while calculating extranet lockout status. Due to the value of the %1 setting authentication will be allowed for this user and token issuance will continue. 
If this is a WID farm the primary node may be offline. 
If this is a SQL farm ADFS will automatically select a new node to host the User store master role. 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information. 

Additional Data 
Account store server name: 
%2 
User Id: 
%3 

Exception Message: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 563 —

Provider
AD FS
Channel
Unknown

Description

An error occurred while calculating extranet lockout status. Due to the value of the setting authentication will be allowed for this user and token issuance will continue.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 564 — The banned IP list found in Microsoft.

Provider
AD FS
Channel
Admin

Message #

The banned IP list found in Microsoft.IdentityServer.Servicehost.exe.config is being used instead of the banned IP list found in the ADFS configuration database.  Verify that the configuration file contains the correct list.  Clearing the banned IPs from the database using Set-ADFSProperties -RemoveBannedIPs will silence this warning.

Event ID 564 —

Provider
AD FS
Channel
Unknown

Event ID 565 — An error occurred while attemtping to update the database schema for Adfs smart lockout.

Provider
AD FS
Channel
Admin

Description

An error occurred while attemtping to update the database schema for Adfs smart lockout. See https://go.microsoft.com/fwlink/?linkid=864556 for more information.

Message #

An error occurred while attemtping to update the database schema for Adfs smart lockout. See https://go.microsoft.com/fwlink/?linkid=864556 for more information. 

Additional Data 

Exception Message: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 565 —

Provider
AD FS
Channel
Unknown

Description

An error occurred while attemtping to update the database schema for Adfs smart lockout. See https://go.microsoft.com/fwlink/?linkid=864556 for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 566 — An error occurred during processing of an OAuth device code request.

Provider
AD FS
Channel
Admin

Description

An error occurred during processing of an OAuth device code request.

Message #

An error occurred during processing of an OAuth device code request. 
Error: %1 

Additional Data 

Client identifier: %2 

Full request: %3 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 566 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during processing of an OAuth device code request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 568 — An error occurred during processing of an OAuth device auth request with the provided usercode: data1.

Provider
AD FS
Channel
Admin

Description

An error occurred during processing of an OAuth device auth request with the provided usercode: data1.

Message #

An error occurred during processing of an OAuth device auth request with the provided usercode: %1. 
Error: %2 

Additional Data 

User Code Data (if available): %3 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 568 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during processing of an OAuth device auth request with the provided usercode: .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 570 — Active Directory trust enumeration was unable to enumerate one of more domains due to the following error.

Provider
AD FS
Channel
Admin

Message #

Active Directory trust enumeration was unable to enumerate one of more domains due to the following error.  Enumeration will continue but the Active Directory identifier list may not be correct. Validate that all expected Active Directory identifiers are present by running Get-ADFSDirectoryProperties: 

Error string: %1 

Exception Details: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 570 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 571 — Enumeration of the Active Directory domains failed.

Provider
AD FS
Channel
Admin

Description

Enumeration of the Active Directory domains failed.

Message #

Enumeration of the Active Directory domains failed. 

Exception Details: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 571 —

Provider
AD FS
Channel
Unknown

Description

Enumeration of the Active Directory domains failed.

Fields #

NameDescription
data1 UnicodeString

Event ID 572 — The Active Directory suffix from this username is not trusted by this ADFS server.

Provider
AD FS
Channel
Admin

Description

The Active Directory suffix from this username is not trusted by this ADFS server. If this identifier is expected it can be added to the trusted identier list by using Set-ADFSDirectoryProperties.

Message #

The Active Directory suffix from this username is not trusted by this ADFS server.  If this identifier is expected it can be added to the trusted identier list by using Set-ADFSDirectoryProperties. 

Username: %1 

Suffix: %2 

Client IP: %3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 572 —

Provider
AD FS
Channel
Unknown

Description

The Active Directory suffix from this username is not trusted by this ADFS server. If this identifier is expected it can be added to the trusted identier list by using Set-ADFSDirectoryProperties.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 573 — The following error was generated by a threat detection module.

Provider
AD FS
Channel
Admin

Description

The following error was generated by a threat detection module.

Message #

The following error was generated by a threat detection module. 

Module Identifier: %1 

Message: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 573 —

Provider
AD FS
Channel
Unknown

Description

The following error was generated by a threat detection module.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 574 — A threat detection module failed to load.

Provider
AD FS
Channel
Admin

Description

A threat detection module failed to load. Verify the module binary is correctly installed on this node.

Message #

A threat detection module failed to load.  Verify the module binary is correctly installed on this node. 

Module Name: %1 

Module Identifier: %2 

Type: %3 

Failure Message: %4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 574 —

Provider
AD FS
Channel
Unknown

Description

A threat detection module failed to load. Verify the module binary is correctly installed on this node.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 575 — The following threat detection module was successfully loaded.

Provider
AD FS
Channel
Admin
Level
Informational

Description

The following threat detection module was successfully loaded.

Message #

The following threat detection module was successfully loaded 

Module Name: %1 

Module Identifier: %2 

Type: %3

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 575,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:53.739665+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "BannedIpProvider",
          "",
          "Microsoft.IdentityServer.Service.AccountPolicy.BannedIpProvider, Microsoft.IdentityServer.Service, Version=10.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"
        ]
      }
    }
  },
  "message": ""
}

Event ID 575 —

Provider
AD FS
Channel
Unknown

Description

The following threat detection module was successfully loaded.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 576 — An unexpected error was returned from a threat detection module.

Provider
AD FS
Channel
Admin

Description

An unexpected error was returned from a threat detection module.

Message #

An unexpected error was returned from a threat detection module. 

Module Name: %1 

Module Identifier: %2 

Type: %3 

Exception Type: %4 

Error Message: %5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 576 —

Provider
AD FS
Channel
Unknown

Description

An unexpected error was returned from a threat detection module.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 1000 — An error occurred during processing of a token request.

Provider
AD FS
Channel
Admin
Level
Warning

Message #

An error occurred during processing of a token request. The data in this event may have the identity of the caller (application) that made this request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.  

Additional Data 

Caller:
 %1 

OnBehalfOf user:
 %2 

ActAs user:
 %3 

Target Relying Party:
 %4 

Device identity:
 %5 

User action: 
Use the Activity ID data in this message to search and correlate the data to events in the Event log using Event Viewer. This Activity ID will also be shown as additional information in the error page when an error occurs in the federation passive Web application.

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1000,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:37.253680+00:00",
    "event_record_id": 101,
    "correlation": {
      "ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "ludus\\domainadmin\r\n",
          "",
          "",
          "https://testrp1.example.com/saml",
          ""
        ]
      }
    }
  },
  "message": ""
}

Event ID 1000 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 1020 — Encountered error during OAuth authorization request.

Provider
AD FS
Channel
Admin
Level
Error

Description

Encountered error during OAuth authorization request.

Message #

Encountered error during OAuth authorization request. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1020,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:52.935997+00:00",
    "event_record_id": 108,
    "correlation": {
      "ActivityID": "E915B92E-2E46-4CB5-0900-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\r\n\r\n"
      }
    }
  },
  "message": ""
}

Event ID 1020 —

Provider
AD FS
Channel
Unknown

Description

Encountered error during OAuth authorization request.

Fields #

NameDescription
data1 UnicodeString

Event ID 1021 — Encountered error during OAuth token request.

Provider
AD FS
Channel
Admin
Level
Error

Description

Encountered error during OAuth token request.

Message #

Encountered error during OAuth token request. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
Event.EventData
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1021,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:36.668080+00:00",
    "event_record_id": 94,
    "correlation": {
      "ActivityID": "43EBE48F-E201-482C-1500-00400A0000FF"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9241: Received invalid OAuth access token request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'nonexistent'. \r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthTokenRequestContext.ValidateCore()\r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthClientCredentialsContext.ValidateCore()\r\n\r\n"
      }
    }
  },
  "message": ""
}

Event ID 1021 —

Provider
AD FS
Channel
Unknown

Description

Encountered error during OAuth token request.

Fields #

NameDescription
data1 UnicodeString

Event ID 1080 — An error occurred while processing WebFinger request.

Provider
AD FS
Channel
Admin

Description

An error occurred while processing WebFinger request.

Message #

An error occurred while processing WebFinger request. 

Additional Data 
Request url: %1 

User Action 
Examine the exception details to take one or more of the following actions if applicable. 
  Verify that the resource query parameter exists and is valid representing an authorization server's URL. 
  Verify that all federation partners (RP-STSs) that this ADFS issues tokens to (including any chains) have been configured using powershell cmdlet Add-ADFSTrustedFederationPartner. 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1080 —

Provider
AD FS
Channel
Unknown

Description

An error occurred while processing WebFinger request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1100 — The Federation Service could not authorize a request to one of the REST endpoints.

Provider
AD FS
Channel
Admin

Description

The Federation Service could not authorize a request to one of the REST endpoints.

Message #

The Federation Service could not authorize a request to one of the REST endpoints. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 1100 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service could not authorize a request to one of the REST endpoints.

Fields #

NameDescription
data1 UnicodeString

Event ID 1109 — The Federation Service failed to connect to the LDAP account store to authenticate user data2.

Provider
AD FS
Channel
Admin

Description

The Federation Service failed to connect to the LDAP account store to authenticate user data2.

Message #

The Federation Service failed to connect to the LDAP account store to authenticate user %2. 

Activity ID: %1 

Request Details: 
    User DN: %2 
    Local CP trust identifier: %3 
    LDAP server: %4 
    SSL: %5 
    Authentication method: %6 

Exception details: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1109 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service failed to connect to the LDAP account store to authenticate user .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1110 — The Federation Service failed to connect to the primary LDAP account store to authenticate user data2.

Provider
AD FS
Channel
Admin

Description

The Federation Service failed to connect to the primary LDAP account store to authenticate user data2.

Message #

The Federation Service failed to connect to the primary LDAP account store to authenticate user %2. 

Activity ID: %1 

Request Details: 
    User DN: %2 
    Local CP trust identifier: %3 
    Ldap server: %4 
    SSL: %5 
    Authentication method: %6 

Exception details: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1110 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service failed to connect to the primary LDAP account store to authenticate user .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1111 — The Federation Service failed to connect to all LDAP account stores to authenticate user data2.

Provider
AD FS
Channel
Admin

Description

The Federation Service failed to connect to all LDAP account stores to authenticate user data2.

Message #

The Federation Service failed to connect to all LDAP account stores to authenticate user %2. 

Activity ID: %1 

Request Details: 
    User DN: %2 
    Local CP trust identifier: %3 
    Ldap server: %4 
    SSL: %5 
    Authentication method: %6 

Exception details: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1111 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service failed to connect to all LDAP account stores to authenticate user .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1112 — The Federation Service failed to connect to the Ldap server.

Provider
AD FS
Channel
Admin

Description

The Federation Service failed to connect to the Ldap server.

Message #

The Federation Service failed to connect to the Ldap server. 

Activity ID: %1 

Request Details: 
    Local CP trust identifier: %2 
    Ldap ErrorCode: %3 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 1112 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service failed to connect to the Ldap server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 1113 — Client Json Web Key Set (JWKS) synchronization initiated.

Provider
AD FS
Channel
Admin
Level
Informational

Description

Client Json Web Key Set (JWKS) synchronization initiated.

Message #

Client Json Web Key Set (JWKS) synchronization initiated.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1113,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.121414+00:00",
    "event_record_id": 73,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 10760
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 1113 —

Provider
AD FS
Channel
Unknown

Description

Client Json Web Key Set (JWKS) synchronization initiated.

Event ID 1114 — Client Json Web Key Set (JWKS) synchronization completed.

Provider
AD FS
Channel
Admin
Level
Informational

Description

Client Json Web Key Set (JWKS) synchronization completed.

Message #

Client Json Web Key Set (JWKS) synchronization completed.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1114,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.154935+00:00",
    "event_record_id": 80,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 10760
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 1114 —

Provider
AD FS
Channel
Unknown

Description

Client Json Web Key Set (JWKS) synchronization completed.

Event ID 1115 — The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from 'data1'.

Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from 'data1'. The key synchronization for the following client failed.

Message #

The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from '%1'. The key synchronization for the following client failed: 

Client: 
%2 

Additional Data 

Exception details: 
%3 

Additional details: 
%4 

User Action 
Make sure the JWKS URI '%1' is accessible.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 1115 —

Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from 'data1'. The key synchronization for the following client failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 1116 — An error occurred during a read operation from the configuration database.

Provider
AD FS
Channel
Admin

Message #

An error occurred during a read operation from the configuration database. Monitoring of clients' Json Web Key Set (JWKS) was shut down and will be tried again after an amount of time that corresponds to the monitoring interval. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1116 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1117 — An error occurred during monitoring of the following client's Json Web Key Set (JWKS).

Provider
AD FS
Channel
Admin

Description

An error occurred during monitoring of the following client's Json Web Key Set (JWKS).

Message #

An error occurred during monitoring of the following client's Json Web Key Set (JWKS). 

Client: 
%1 

Additional Data 

Exception details: 
%2 

Additional details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 1117 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during monitoring of the following client's Json Web Key Set (JWKS).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 1118 — An error occurred during monitoring of clients'Json Web Key Set (JWKS).

Provider
AD FS
Channel
Admin

Description

An error occurred during monitoring of clients'Json Web Key Set (JWKS). The monitoring cycle was shut down.

Message #

An error occurred during monitoring of clients'Json Web Key Set (JWKS). The monitoring cycle was shut down. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1118 —

Provider
AD FS
Channel
Unknown

Description

An error occurred during monitoring of clients'Json Web Key Set (JWKS). The monitoring cycle was shut down.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1130 — There was an error establishing or renewing the proxy trust.

Provider
AD FS
Channel
Admin

Description

There was an error establishing or renewing the proxy trust. Ensure the STS and proxy servers have the same TLS version enabled.

Message #

There was an error establishing or renewing the proxy trust. Ensure the STS and proxy servers have the same TLS version enabled. 
Consult the following links for additional details: 
https://go.microsoft.com/fwlink/?linkid=875038  
https://go.microsoft.com/fwlink/?linkid=875039  

Additional Data 

Exception Details: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 1130 —

Provider
AD FS
Channel
Unknown

Description

There was an error establishing or renewing the proxy trust. Ensure the STS and proxy servers have the same TLS version enabled.

Fields #

NameDescription
data1 UnicodeString

Event ID 1131 — There was an error establishing or renewing the trust between the proxy and STS.

Provider
AD FS
Channel
Admin

Message #

There was an error establishing or renewing the trust between the proxy and STS. Ensure the Network Service Account has Read/Write permissions on C:\Program Data\Microsoft\Crypto\RSA\Machine Keys on the proxy server. 
Consult the following link for additional details: 
https://go.microsoft.com/fwlink/?linkid=875037  

Additional Data 

Exception Details: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 1131 —

Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString