Microsoft-Windows-AAD
204 events across 2 channels
Event ID 1001 — AadCloudAPPlugin Initialize Start
Message
Event ID 1002 — AadCloudAPPlugin Initialize Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1003 — AadCloudAPPlugin Uninitialize Start
Message
Event ID 1004 — AadCloudAPPlugin ValidateUserInfo Start
Message
Event ID 1005 — AadCloudAPPlugin ValidateUserInfo Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1006 — AadCloudAPPlugin GetToken Start
Message
Event ID 1007 — AadCloudAPPlugin GetToken Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1008 — AadCloudAPPlugin GetKeys Start
Message
Event ID 1009 — AadCloudAPPlugin GetKeys Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1010 — AadCloudAPPlugin GetUnlockKey Start
Message
Event ID 1011 — AadCloudAPPlugin GetUnlockKey Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1012 — AadCloudAPPlugin PersistSSOTokens Start
Message
Event ID 1013 — AadCloudAPPlugin PersistSSOTokens Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1015 — AadCloudAPPlugin Realm discovery response.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_Realm_discovery_response | — |
Request_status | — |
Response | — |
Status | — |
Event ID 1016 — AadCloudAPPlugin device is cloud domain joined
Message
Event ID 1017 — AadCloudAPPlugin device is domain joined
Message
Event ID 1018 — AadCloudAPPlugin GetToken Correlation ID.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_GetToken_Correlation_ID | — |
value | — |
Event ID 1019 — AadCloudAPPlugin GetKeys Correlation ID.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_GetKeys_Correlation_ID | — |
value | — |
Event ID 1020 — AadCloudAPPlugin loaded as surrogate
Message
Event ID 1021 — AadCloudAPPlugin MEX request status.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_MEX_request_status | — |
Status | — |
Event ID 1022 — Endpoint Uri.
Message
Fields
| Name | Description |
|---|---|
Endpoint_Uri | — |
value | — |
Event ID 1023 — NGC UserID Key.
Message
Fields
| Name | Description |
|---|---|
NGC_UserID_Key | — |
value | — |
Event ID 1024 — Http request status.
Message
Fields
| Name | Description |
|---|---|
Http_request_status | — |
value | — |
Event ID 1025 — Http request status.
Message
Fields
| Name | Description |
|---|---|
Http_request_status | — |
Method | — |
Endpoint_Uri | — |
Correlation_ID | — |
value | — |
EndpointUri | — |
CorrelationID | — |
Event ID 1026 — Credential type: %1 Correlation ID: %2.
Message
Fields
| Name | Description |
|---|---|
Credential_type | — |
Correlation_ID | — |
value | — |
CorrelationID | — |
Event ID 1027 — AadCloudAPPlugin managed logon flow for federated NGC user.
Message
Event ID 1028 — AadCloudAPPlugin RefreshToken Start
Message
Event ID 1029 — AadCloudAPPlugin RefreshToken Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1030 — AadCloudAPPlugin RefreshToken Correlation ID.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_RefreshToken_Correlation_ID | — |
value | — |
Event ID 1031 — AadCloudAPPlugin encrypted OAuth response received
Message
Event ID 1032 — Number of groups received.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1033 — Validation needed.
Message
Fields
| Name | Description |
|---|---|
Validation_needed | — |
value | — |
Event ID 1034 — AadCloudAPPlugin GenericCallPkg Start
Message
Event ID 1035 — AadCloudAPPlugin GenericCallPkg Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1081 — OAuth response error: %1 Error description: %2 CorrelationID: %3.
Message
Fields
| Name | Description |
|---|---|
OAuth_response_error | — |
Error_description | — |
CorrelationID | — |
Error | — |
ErrorDescription | — |
Event ID 1082 — Key error: %1 Error description: %2 CorrelationID: %3.
Message
Fields
| Name | Description |
|---|---|
Key_error | — |
Error_description | — |
CorrelationID | — |
Error | — |
ErrorDescription | — |
Event ID 1083 — Protected key error: %1 Error description: %2 CorrelationID: %3.
Message
Fields
| Name | Description |
|---|---|
Protected_key_error | — |
Error_description | — |
CorrelationID | — |
Error | — |
ErrorDescription | — |
References
Event ID 1084 — Http transport error.
Message
Fields
| Name | Description |
|---|---|
Http_transport_error_Status | Http transport error. Status. |
Correlation_ID | — |
Result | — |
Target | — |
References
Event ID 1085 — Logon failure.
Message
Fields
| Name | Description |
|---|---|
Logon_failure_Status | Logon failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1086 — Get user realm failure.
Message
Fields
| Name | Description |
|---|---|
Get_user_realm_failure_Status | Get user realm failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1087 — Get credential keys failure.
Message
Fields
| Name | Description |
|---|---|
Get_credential_keys_failure_Status | Get credential keys failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1088 — WSTrust response error: %1 Error description: %2.
Message
Fields
| Name | Description |
|---|---|
WSTrust_response_error | — |
Error_description | — |
Error | — |
ErrorDescription | — |
Event ID 1089 — Device is not cloud domain joined.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1090 — NGC nonce response error: %1 Error description: %2 CorrelationID: %3.
Message
Fields
| Name | Description |
|---|---|
NGC_nonce_response_error | — |
Error_description | — |
CorrelationID | — |
Error | — |
ErrorDescription | — |
Event ID 1091 — NGC auth ticket is not defined.
Message
Fields
| Name | Description |
|---|---|
Result | — |
Event ID 1092 — OAuth request retry.
Message
Fields
| Name | Description |
|---|---|
OAuth_request_retry_Correlation_ID | OAuth request retry. Correlation ID. |
Retry | — |
CorrelationID | — |
RetryNumber | — |
Event ID 1093 — NGC call %1 returned error: %2.
Message
Fields
| Name | Description |
|---|---|
API | — |
Result | — |
References
Event ID 1094 — Refresh token failure.
Message
Fields
| Name | Description |
|---|---|
Refresh_token_failure_Status | Refresh token failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1095 — Refresh token user SIDs don't match.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1096 — Refresh token is expired.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1097 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Example Event
system:
provider: Microsoft-Windows-AAD
guid: 4DE9BC9C-B27A-43C9-8994-0915F1A5E24F
event_source_name: ''
event_id: 1097
version: 0
level: 3
task: 103
opcode: 0
keywords: 4611686018427387952
time_created: '2023-11-05T22:29:32.897824+00:00'
event_record_id: 8
correlation:
ActivityID: 59A0D65F-1037-0002-97FA-A0593710DA01
execution:
process_id: 7788
thread_id: 7496
channel: Microsoft-Windows-AAD/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
Error: 2325807322
ErrorMessage: Upgrade default pawn task complete.
AdditionalInformation: 'Logged at UpdateDefaultPawn.cpp, line: 43, method: UpdateDefaultPawn::Apply.'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1098 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1099 — Code: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Code | — |
OperationCode | — |
OperationMessage | — |
AdditionalInformation | — |
Event ID 1100 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1101 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1102 — Code: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Code | — |
OperationCode | — |
OperationMessage | — |
AdditionalInformation | — |
Event ID 1103 — Can't decrypt OAuth response.
Message
Fields
| Name | Description |
|---|---|
Cant_decrypt_OAuth_response_Error | Can't decrypt OAuth response. Error. |
Result | — |
Event ID 1104 — AAD Cloud AP plugin call %1 returned error: %2.
Message
Fields
| Name | Description |
|---|---|
API | — |
Result | 1 returned error. |
Example Event
system:
provider: Microsoft-Windows-AAD
guid: 4DE9BC9C-B27A-43C9-8994-0915F1A5E24F
event_source_name: ''
event_id: 1104
version: 0
level: 2
task: 101
opcode: 0
keywords: 4611686018427387922
time_created: '2022-04-07T16:53:02.149442+00:00'
event_record_id: 10
correlation:
ActivityID: E0AAB88C-4A9F-0000-71B9-AAE09F4AD801
execution:
process_id: 664
thread_id: 668
channel: Microsoft-Windows-AAD/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
API: Plugin initialize
Result: 3221521494
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1105 — Device registration API call %1 returned error: %2.
Message
Fields
| Name | Description |
|---|---|
API | — |
Result | — |
Event ID 1106 — Number of security groups received %1.
Message
Fields
| Name | Description |
|---|---|
value | — |
CorrelationID | — |
Event ID 1107 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1108 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1109 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1110 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1111 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1112 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1113 — Code: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Code | — |
OperationCode | — |
OperationMessage | — |
AdditionalInformation | — |
Event ID 1114 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1115 — Error: %1 %2 %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorMessage | — |
AdditionalInformation | — |
Event ID 1116 — Get Enterprise STS OAuth Info failure.
Message
Fields
| Name | Description |
|---|---|
Status | — |
CorrelationID | — |
References
Event ID 1117 — Enterprise STS Refresh token failure.
Message
Fields
| Name | Description |
|---|---|
Status | — |
CorrelationID | — |
References
Event ID 1118 — Enterprise STS Logon failure.
Message
Fields
| Name | Description |
|---|---|
Enterprise_STS_Logon_failure_Status | Enterprise STS Logon failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
References
Event ID 1119 — Enterprise STS OAuth Info response.
Message
Fields
| Name | Description |
|---|---|
Enterprise_STS_OAuth_Info_response | — |
Request_status | — |
Response | — |
Status | — |
References
Event ID 1120 — Enterprise STS Refresh token is expired.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1121 — Enterprise STS RefreshToken Correlation ID.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1122 — Refresh token subject don't match.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1123 — AadCloudAPPlugin smart card logon for non-federated user.
Message
Event ID 1124 — Device is DRS joined but Enterprise STS is disabled.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1125 — AadCloudAPPlugin loaded as surrogate, no key recovery
Message
Event ID 1126 — AadCloudAPPlugin device is Enterprise joined
Message
Event ID 1127 — AadCloudAPPlugin device P2P certificate update thread started
Message
References
Event ID 1128 — AadCloudAPPlugin device P2P certificate update thread stopped
Message
Event ID 1129 — AadCloudAPPlugin Uninitialize Stop
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1130 — AadCloudAPPlugin DeviceP2PCertificateUpdate Correlation ID.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_DeviceP2PCertificateUpdate_Correlation_ID | — |
value | — |
Event ID 1131 — Update P2P device certificate failure.
Message
Fields
| Name | Description |
|---|---|
Status | — |
CorrelationID | — |
Event ID 1132 — AadCloudAPPlugin GetCertificateFromCred Correlation ID.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_GetCertificateFromCred_Correlation_ID | — |
value | — |
Event ID 1133 — Update P2P user certificate failure.
Message
Fields
| Name | Description |
|---|---|
Status | — |
CorrelationID | — |
Event ID 1134 — AAD Cloud AP plugin call %1 returned error: %2.
Message
Fields
| Name | Description |
|---|---|
API | — |
Result | — |
Event ID 1135 — AadCloudAPPlugin RenewCertificate Correlation ID.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_RenewCertificate_Correlation_ID | — |
value | — |
Event ID 1136 — AadCloudAPPlugin AcceptPeerCertificate Start
Message
Event ID 1137 — AadCloudAPPlugin AcceptPeerCertificate Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1138 — AadCloudAPPlugin RenewCertificate Start
Message
Event ID 1139 — AadCloudAPPlugin RenewCertificate Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1140 — AadCloudAPPlugin GetCertificateFromCred Start
Message
Event ID 1141 — AadCloudAPPlugin GetCertificateFromCred Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1142 — Get token user names don't match.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1143 — Generic Call Package call type.
Message
Fields
| Name | Description |
|---|---|
Generic_Call_Packate_call_type | — |
Correlation_ID | — |
value | — |
CorrelationID | — |
Event ID 1144 — Realm discovery for: %2 authority: %3 fallback domain hint: %4 useUpn: %1.
Message
Fields
| Name | Description |
|---|---|
value | — |
Method | — |
EndpointUri | — |
CorrelationID | — |
Event ID 1145 — AAD Cloud AP plugin token needs refresh reason.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1146 — Token is not refreshed.
Message
Fields
| Name | Description |
|---|---|
NoOfTargets | — |
RequestType | — |
Event ID 1147 — AadCloudAPPlugin AssembleOpaqueData Start
Message
Event ID 1148 — AadCloudAPPlugin AssembleOpaqueData Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1149 — AadCloudAPPlugin DisassembleOpaqueData Start
Message
References
Event ID 1150 — AadCloudAPPlugin DisassembleOpaqueData Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1151 — AadCloudAPPlugin P2P device certificate update error.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1152 — AadCloudAPPlugin device certificate key error.
Message
Fields
| Name | Description |
|---|---|
Result | — |
Event ID 1153 — AadCloudAPPlugin device certificate not available for logon.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1154 — Password expiration claims.
Message
Fields
| Name | Description |
|---|---|
Password_expiration_claims_Seconds | Password expiration claims. Seconds. |
URI | — |
seconds | — |
Event ID 1155 — Logon with session key failure.
Message
Fields
| Name | Description |
|---|---|
Status | — |
CorrelationID | — |
Event ID 1156 — Password expiration fields.
Message
Fields
| Name | Description |
|---|---|
Password_expiration_fields_Status | Password expiration fields. Status. |
Date | — |
URI | — |
Status | — |
ExpiryTime | — |
PasswordChangeURI | — |
Event ID 1157 — AadCloudAPPlugin PostLogonProcessing Start
Message
Event ID 1158 — AadCloudAPPlugin PostLogonProcessing Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1159 — AadCloudAPPlugin S2U logon failed.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_S2U_logon_failed_Status | AadCloudAPPlugin S2U logon failed. Status. |
Status | — |
Event ID 1160 — Logon failure.
Message
Fields
| Name | Description |
|---|---|
Logon_failure_Status | Logon failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1161 — Logon failure.
Message
Fields
| Name | Description |
|---|---|
Logon_failure_Status | Logon failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1162 — Logon failure.
Message
Fields
| Name | Description |
|---|---|
Logon_failure_Status | Logon failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1163 — Logon failure.
Message
Fields
| Name | Description |
|---|---|
Logon_failure_Status | Logon failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1164 — Logon failure.
Message
Fields
| Name | Description |
|---|---|
Logon_failure_Status | Logon failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1165 — Logon failure.
Message
Fields
| Name | Description |
|---|---|
Logon_failure_Status | Logon failure. Status. |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1200 — BrowserCore operation started
Message
Event ID 1201 — BrowserCore operation completed successfully
Message
Fields
| Name | Description |
|---|---|
Method | — |
CorrelationID | — |
Event ID 1202 — BrowserCore operation completed with a failure.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Error_Message | — |
Result | — |
ErrorMessage | — |
Method | — |
CorrelationID | — |
Event ID 1203 — BrowserCore inner operation %2 completed with error: %1.
Message
Fields
| Name | Description |
|---|---|
Result | — |
FunctionName | — |
Event ID 1204 — AadCloudAPPlugin LookupSIDFromIdentityName Start
Message
Event ID 1205 — AadCloudAPPlugin LookupSIDFromIdentityName Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1206 — AadCloudAPPlugin LookupIdentityFromSIDName Start
Message
Event ID 1207 — AadCloudAPPlugin LookupIdentityFromSIDName Stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1208 — AadCloudAPPlugin LookupSIDFromIdentity Identity: %1 Correlation ID: %2.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_LookupSIDFromIdentity_Identity | — |
Correlation_ID | — |
value1 | — |
value2 | — |
Event ID 1209 — AadCloudAPPlugin LookupIdentityFromSID SID: %1 Correlation ID: %2.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_LookupIdentityFromSID_SID | — |
Correlation_ID | — |
value1 | — |
value2 | — |
Event ID 1210 — AadCloudAPPlugin password expired, password change URI.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1211 — Writing RunRecovery registry value failed.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1212 — Enterprise logon.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Correlation_ID | — |
CorrelationID | — |
Event ID 1213 — WamExtension process token operation started
Message
Event ID 1214 — WamExtension process token operation completed successfully
Message
Event ID 1215 — WamExtension process token operation completed with error.
Message
Fields
| Name | Description |
|---|---|
Data | WamExtension process token operation completed with error. |
Example Event
system:
provider: Microsoft-Windows-AAD
guid: 4DE9BC9C-B27A-43C9-8994-0915F1A5E24F
event_source_name: ''
event_id: 1215
version: 0
level: 2
task: 107
opcode: 2
keywords: 4611686018427387922
time_created: '2022-04-07T16:44:49.386586+00:00'
event_record_id: 2
correlation: {}
execution:
process_id: 2080
thread_id: 2748
channel: Microsoft-Windows-AAD/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
Data:
Name: Result
Value: "\x04�\x04�"
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1216 — WamExtension device authentication call status: %1 Correlation ID: %2.
Message
Fields
| Name | Description |
|---|---|
Result | — |
Target | — |
Event ID 1217 — Get device token.
Message
Fields
| Name | Description |
|---|---|
Get_device_token_Resource | Get device token. Resource. |
ClientID | — |
Scope | — |
value1 | — |
value2 | — |
value3 | — |
Event ID 1218 — StartFidoAuthenticationSession start
Message
Event ID 1219 — StartFidoAuthenticationSession stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1220 — CloseFidoAuthenticationSession start
Message
Event ID 1221 — CloseFidoAuthenticationSession stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1222 — GetClientData start
Message
Event ID 1223 — GetClientData stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1224 — SignClientDataFido start
Message
Event ID 1225 — SignClientDataFido stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1226 — ChangePin start
Message
Event ID 1227 — ChangePin stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1228 — GetSerializedAuthBuffer start
Message
Event ID 1229 — GetSerializedAuthBuffer stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1230 — AuthHelper call %1 returned error: %2.
Message
Fields
| Name | Description |
|---|---|
API | — |
Result | — |
Event ID 1231 — AadCloudAPPlugin Resource infomation.
Message
Fields
| Name | Description |
|---|---|
AadCloudAPPlugin_Resource_infomation | — |
Request_status | — |
Response | — |
Status | — |
Event ID 1232 — AadCloudAPPlugin RBAC authorization code response.
Message
Fields
| Name | Description |
|---|---|
Response | — |
Status | — |
Event ID 1233 — AadCloudAPPlugin User access control role.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1234 — AadCloudAPPlugin using resource id from the Idtoken.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1235 — RBAC Status: %1 Correlation ID: %2.
Message
Fields
| Name | Description |
|---|---|
RBAC_Status | — |
Correlation_ID | — |
Status | — |
CorrelationID | — |
Event ID 1236 — Failed to create the resource id
Message
Event ID 1237 — Device is configured for RBAC authorization
Message
Event ID 1238 — Not sending the client certificate as it is optional on the server
Message
Event ID 1239 — Doing RBAC logon
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1240 — Skipping Rbac Logon because AadCloudAPPlugin is loaded as surrogate
Message
Event ID 1241 — On-prem tgt error.
Message
Fields
| Name | Description |
|---|---|
Onprem_tgt_error | On-prem tgt error. |
value | — |
Event ID 1242 — Added user to admins security group
Message
Event ID 1243 — Removed user from admins security group
Message
Event ID 1244 — Security groups were not loaded.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1245 — Security groups were not updated.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1246 — User sid: %1 Group sids: %2.
Message
Fields
| Name | Description |
|---|---|
User_sid | — |
Group_sids | — |
value1 | — |
value2 | — |
Event ID 1247 — RunRecovery registry value successfully written.
Message
Fields
| Name | Description |
|---|---|
Context | — |
Reason | — |
value | — |
Result | — |
Event ID 1248 — AuthHelper auth buff local nonce
Message
Event ID 1249 — Cloud tgt error.
Message
Fields
| Name | Description |
|---|---|
Cloud_tgt_error | — |
value | — |
Event ID 1250 — DoGetToken Diagnostic Event: Result: %1 User Identity: %2 Credential Type: %3 Correlation ID: %4 Endpoint Uri: %5 HTTP Status: %6 HTTP Method: %7 E...
Message
Fields
| Name | Description |
|---|---|
Result | [DoGetToken Diagnostic Event] Result. |
User_Identity | [DoGetToken Diagnostic Event] User Identity. |
Credential_Type | [DoGetToken Diagnostic Event] Credential Type. |
Correlation_ID | [DoGetToken Diagnostic Event] Correlation ID. |
Endpoint_Uri | [DoGetToken Diagnostic Event] Endpoint Uri. |
HTTP_Status | [DoGetToken Diagnostic Event] HTTP Status. |
HTTP_Method | [DoGetToken Diagnostic Event] HTTP Method. |
ErrorCode | [DoGetToken Diagnostic Event] ErrorCode. |
Error_Description | [DoGetToken Diagnostic Event] Error Description. |
UserIdentity | — |
CredentialType | — |
CorrelationID | — |
EndpointUri | — |
Method | — |
HTTPTransportError | — |
HTTPStatus | — |
ErrorDescription | — |
Event ID 1251 — DoGetEnterpriseToken Diagnostic Event: Result: %1 User Identity: %2 Credential Type: %3 Correlation ID: %4 Endpoint Uri: %5 HTTP Status: %6 HTTP Me...
Message
Fields
| Name | Description |
|---|---|
Result | [DoGetEnterpriseToken Diagnostic Event] Result. |
User_Identity | [DoGetEnterpriseToken Diagnostic Event] User Identity. |
Credential_Type | [DoGetEnterpriseToken Diagnostic Event] Credential Type. |
Correlation_ID | [DoGetEnterpriseToken Diagnostic Event] Correlation ID. |
Endpoint_Uri | [DoGetEnterpriseToken Diagnostic Event] Endpoint Uri. |
HTTP_Status | [DoGetEnterpriseToken Diagnostic Event] HTTP Status. |
HTTP_Method | [DoGetEnterpriseToken Diagnostic Event] HTTP Method. |
ErrorCode | [DoGetEnterpriseToken Diagnostic Event] ErrorCode. |
Error_Description | [DoGetEnterpriseToken Diagnostic Event] Error Description. |
UserIdentity | — |
CredentialType | — |
CorrelationID | — |
EndpointUri | — |
Method | — |
HTTPTransportError | — |
HTTPStatus | — |
ErrorDescription | — |
Event ID 1252 — DoRefreshToken Diagnostic Event: Result: %1 User Identity: %2 Credential Type: %3 Correlation ID: %4 Endpoint Uri: %5 HTTP Status: %6 HTTP Method: ...
Message
Fields
| Name | Description |
|---|---|
Result | [DoRefreshToken Diagnostic Event] Result. |
User_Identity | [DoRefreshToken Diagnostic Event] User Identity. |
Credential_Type | [DoRefreshToken Diagnostic Event] Credential Type. |
Correlation_ID | [DoRefreshToken Diagnostic Event] Correlation ID. |
Endpoint_Uri | [DoRefreshToken Diagnostic Event] Endpoint Uri. |
HTTP_Status | [DoRefreshToken Diagnostic Event] HTTP Status. |
HTTP_Method | [DoRefreshToken Diagnostic Event] HTTP Method. |
ErrorCode | [DoRefreshToken Diagnostic Event] ErrorCode. |
Error_Description | [DoRefreshToken Diagnostic Event] Error Description. |
UserIdentity | — |
CredentialType | — |
NewToken | — |
CorrelationID | — |
EndpointUri | — |
Method | — |
HTTPTransportError | — |
HTTPStatus | — |
ErrorDescription | — |
Event ID 1253 — DoRefreshEnterpriseToken Diagnostic Event: Result: %1 User Identity: %2 Credential Type: %3 Correlation ID: %4 Endpoint Uri: %5 HTTP Status: %6 HTT...
Message
Fields
| Name | Description |
|---|---|
Result | [DoRefreshEnterpriseToken Diagnostic Event] Result. |
User_Identity | [DoRefreshEnterpriseToken Diagnostic Event] User Identity. |
Credential_Type | [DoRefreshEnterpriseToken Diagnostic Event] Credential Type. |
Correlation_ID | [DoRefreshEnterpriseToken Diagnostic Event] Correlation ID. |
Endpoint_Uri | [DoRefreshEnterpriseToken Diagnostic Event] Endpoint Uri. |
HTTP_Status | [DoRefreshEnterpriseToken Diagnostic Event] HTTP Status. |
HTTP_Method | [DoRefreshEnterpriseToken Diagnostic Event] HTTP Method. |
ErrorCode | [DoRefreshEnterpriseToken Diagnostic Event] ErrorCode. |
Error_Description | [DoRefreshEnterpriseToken Diagnostic Event] Error Description. |
UserIdentity | — |
CredentialType | — |
NewToken | — |
CorrelationID | — |
EndpointUri | — |
Method | — |
HTTPTransportError | — |
HTTPStatus | — |
ErrorDescription | — |
Event ID 1254 — Response content type.
Message
Fields
| Name | Description |
|---|---|
Response_content_type | — |
value | — |
Event ID 1255 — AD TGT: %1 Cloud TGT: %2.
Message
Fields
| Name | Description |
|---|---|
AD_TGT | — |
Cloud_TGT | — |
NoOfTargets | — |
RequestType | — |
Event ID 1256 — P2P certificate update error.
Message
Fields
| Name | Description |
|---|---|
P2P_certificate_update_error_Status | P2P certificate update error. Status. |
Correlation_ID | — |
Result | — |
Target | — |
Event ID 1257 — Credbuffer correlation ID: %1 Correlation ID: %2.
Message
Fields
| Name | Description |
|---|---|
Credbuffer_correlation_ID | — |
Correlation_ID | — |
value1 | — |
value2 | — |
Event ID 1258 — CA cert hash (keyID): %1 Correlation ID: %2.
Message
Fields
| Name | Description |
|---|---|
CA_cert_hash_keyID | CA cert hash (keyID). |
Correlation_ID | — |
value1 | — |
value2 | — |
Event ID 1259 — CA certificate update error.
Message
Fields
| Name | Description |
|---|---|
CA_certificate_update_error_Status | CA certificate update error. Status. |
Correlation_ID | — |
Result | — |
Target | — |
Event ID 1260 — RetryGetClientData start
Message
Event ID 1261 — RetryGetClientData stop.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1262 — Binding key tag check failed.
Message
Fields
| Name | Description |
|---|---|
Binding_key_tag_check_failed | — |
Status | — |
Event ID 1263 — BrowserCore inner operation %2 with account pairwiseID %1 not found error.
Message
Fields
| Name | Description |
|---|---|
PairwiseID | — |
FunctionName | — |
Event ID 1264 — Token binding key created.
Message
Fields
| Name | Description |
|---|---|
KeyType | — |
ClientId | — |
Resource | — |
Scope | — |
Event ID 1265 — WamExtension preprocess token operation started.
Message
Event ID 1266 — WamExtension preprocess token operation completed successfully
Message
Event ID 1267 — WamExtension preprocess token operation completed with error.
Message
Fields
| Name | Description |
|---|---|
Result | — |
Event ID 1268 — WamExtension postprocess token operation started.
Message
Fields
| Name | Description |
|---|---|
Stage | — |
Event ID 1269 — WamExtension postprocess token operation completed successfully.
Message
Fields
| Name | Description |
|---|---|
Stage | — |
Event ID 1270 — WamExtension postprocess token operation completed with error.
Message
Fields
| Name | Description |
|---|---|
Stage | — |
Result | — |
Event ID 1271 — Token binding claim(s) included in the request.
Message
Fields
| Name | Description |
|---|---|
CorrelationID | — |
Event ID 1272 — Token binding key is not healthy and needs to be re-created.
Message
Fields
| Name | Description |
|---|---|
KeyType | — |
ClientId | — |
Resource | — |
Scope | — |
KeyTestResult | — |
Event ID 1273 — Token binding claims need to be re-generated due to changes in attestation key(s).
Message
Fields
| Name | Description |
|---|---|
KeyType | — |
ClientId | — |
Resource | — |
Scope | — |
Event ID 1274 — Token binding claims generated.
Message
Fields
| Name | Description |
|---|---|
KeyType | — |
ClientId | — |
Resource | — |
Scope | — |
Event ID 1275 — Token binding claims generated for UI request.
Message
Fields
| Name | Description |
|---|---|
KeyType | — |
ClientId | — |
Resource | — |
Scope | — |
Event ID 1276 — Token binding claims count.
Message
Fields
| Name | Description |
|---|---|
ClaimsCount | — |
Event ID 1277 — KeyGuard availability detection failed.
Message
Fields
| Name | Description |
|---|---|
Result | — |
Event ID 1278 — KeyGuard with attestation support is not detected.
Message
Event ID 1279 — Token binding claims of type %1 could not be generated because AIK does not exist.
Message
Fields
| Name | Description |
|---|---|
KeyType | — |
JoinType | — |
TenantId | — |
Event ID 1280 — PRT session key needs to be rolled.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
RollReason | — |
Event ID 1281 — Token binding key deleted.
Message
Fields
| Name | Description |
|---|---|
Key | — |
Event ID 1282 — SHR property in request is not allowed.
Message
Fields
| Name | Description |
|---|---|
PropertyName | — |
Event ID 1283 — Invalid registry value was ignored.
Message
Fields
| Name | Description |
|---|---|
RegistryLocation | — |
RegistryValueName | — |
Value | — |
Event ID 1284 — Token binding claims need to be re-generated as cached claims were generated for different attestation key(s).
Message
Fields
| Name | Description |
|---|---|
KeyType | — |
ClientId | — |
Resource | — |
Scope | — |