Microsoft-Windows-AppModel-Runtime

131 events across 6 channels

Event IDTitleChannel
1Process %1 started at time %2 by parent %3 running as package %4 with executable …Analytic
2%2: Cannot create the process for package %1 because an error was encountered.Admin
3%2: Cannot create the process for package %1 because an error was encountered …Admin
4%2: Cannot create the process for package %1 because an error was encountered …Admin
5%2: Cannot create the process for package %1 because an error was encountered …Admin
6%2: Cannot create the process for package %1 because an error was encountered …Admin
7%2: Cannot create the process for package %1 because an error was encountered …Admin
8App %1 was terminated with error %2 because of an issue with application binary …Admin
9App %1 was terminated with error %2 because of an issue with Windows binary %3.Application
11App %1 prevented the load of generated binary %3 due to error %2.Admin
12An app prevented the load of a binary due to error %1.Admin
14%2: Package runtime information %1 is corrupted (address=%5, size=%3, offset=%4, …Admin
15%2: Package runtime information %1 is missing expected data (address=%4, …Admin
16%2: Package runtime information %1 contains conflicting data (address=%5, …Admin
17%2: Package runtime information %1 contains unexpected data (address=%5, …Admin
18%2: Package runtime information %1 failed to load (processid=%3).Admin
19Package runtime information %1 failed to load because exception %2 occurred.Admin
20%2: Cannot create the process for package %1 because an error was encountered …Admin
21CreateAppContainerProfile failed for AppContainer %2 with error %1.Admin
22DeleteAppContainerProfile failed for AppContainer %2 with error %1.Admin
23UpdateAppContainerProfile failed for AppContainer %2 with error %1.Admin
24CreateAppContainerProfile failed with error %1 because it was unable to create …Admin
25CreateAppContainerProfile failed with error %1 because it was unable to set …Admin
26AppContainer profile failed with error %1 because it was unable to delete …Admin
27CreateAppContainerProfile failed with error %1 because it was unable to create …Admin
28CreateAppContainerProfile failed with error %1 because it was unable to set …Admin
29CreateAppContainerProfile failed with error %1 because it was unable to verify …Admin
30CreateAppContainerProfile failed with error %1 because it was unable to verify …Admin
31CreateAppContainerProfile failed with error %1 because it was unable to find the …Admin
32AppContainer profile failed with error %1 because it was unable to delete folder …Admin
33AppContainer profile failed with error %1 because it was unable to look up the …Admin
34AppContainer profile failed with error %1 because it was unable to look up the …Admin
35CreateAppContainerProfile failed with error %1 because it was unable to register …Admin
36EndAdmin
37App Container profile failed with error %1 because it was unable to register the …Admin
38DeleteAppContainerProfile failed with error %1 because it was unable to …Admin
39Successfully created AppContainer %1.Admin
40AppContainer %1 was not created because it already exists.Admin
41The Scenario Event Mapper is configured with more than the maximum number of …Admin
42The Scenario Event Mapper is configured with an unsupported scenario.Admin
43%2: Package runtime information %1 is missing expected data (address=%4, …Admin
44%2: Application identity not accessible while loading package runtime …Admin
45Failed with %1 while retrieving AppContainer %2 information during interaction …Admin
46Failed with %1 while retrieving AppContainer information during interaction with …Admin
47Failed with %1 while retrieving AppContainer information.Admin
48Failed to create shared context object for Restricted AppContainer %2 with %1.Admin
49Failed to activate Restricted AppContainer %2 with %1.Admin
50Creation of Restricted AppContainer %2 failed with %1 because an invalid …Admin
51Opening existing Restricted AppContainer %2 failed with %1 because the …Admin
52Failed to create the capabilities storage value for Restricted AppContainer %2 …Admin
53The package %1 requires validation.Admin
54Modification was detected in package %1.Admin
55Failed to terminate app with package %1.Admin
56Validation of app with package %1 was successful.Admin
57Failed with %1 to retrieve the trust state of the package %2 folder.Admin
58App Integrity check failed with %1 while checking %2.Admin
59App Integrity terminated an application.Admin
60App Integrity check for %1 timed out.Admin
61%2: Cannot create the process for package %1 because an error was encountered …Admin
62Deployment server integrity check of package %1 failed with %2.Admin
63Failed with %1 retrieving AppModel Runtime group policy values.Admin
64Failed with %1 validating AppModel Runtime group policy values.Admin
65Failed with %1 retrieving AppModel Runtime status for package %2.Admin
66Failed with %1 retrieving AppModel Runtime status for package %2 for user %3.Admin
67Failed with %1 modifying AppModel Runtime status for package %2 (current status …Admin
68AppModel Runtime status for package %1 successfully updated to %2 (previous …Admin
69Failed with %1 modifying AppModel Runtime status for package %2 for user %3 …Admin
70Successfully updated AppModel Runtime status for package %1 for user %2 …Admin
71Failed with %1 modifying AppModel Runtime status version (context = %2).Admin
72AppModel Runtime status version successfully updated.Debug
73%2: Cannot create the process for package %1 because an error was encountered …Admin
74Package runtime information %1 failed to refresh because the following error %2 …Admin
75error %2: Cannot register the %1 package because the following error was …Admin
76error %4: Cannot register the %1 package because the following error was …Admin
77error %4 : Cannot register the %1 package because the following error was …Admin
78error %4: Cannot register the %1 package because the following error was …Admin
79%2: Package family %1 runtime information is corrupted.Admin
80%2: Package family %1 runtime information is corrupted but we cannot repair it …Admin
81Failed with %1 to get IsPackageStageInPlace info from State Repository cache for …Admin
101Creating AppContainer %1.Diagnostics
102Finished creating AppContainer %2 with %1.Diagnostics
103Deleting AppContainer %1.Diagnostics
104Finished deleting AppContainer %2 with %1.Diagnostics
105Updating AppContainer %1.Diagnostics
106Finished updating AppContainer %2 with %1.Diagnostics
107Creating firewall rules for AppContainer %1.Diagnostics
108Finished creating firewall rules for AppContainer %2 with %1.Diagnostics
109Deleting firewall rules for AppContainer %1.Diagnostics
110Finished deleting firewall rules for AppContainer %2 with %1.Diagnostics
111Creating Restricted AppContainer %1.Diagnostics
112Finished creating Restricted AppContainer %2 with %1.Diagnostics
113Deleting Restricted AppContainer %1.Diagnostics
114Finished deleting Restricted AppContainer %2 with %1.Diagnostics
115Opening Restricted AppContainer %1.Diagnostics
116Finished opening Restricted AppContainer %2 with %1.Diagnostics
117Enumerating all Restricted AppContainers for %1.Diagnostics
118Finished enumerating all Restricted AppContainers for AppContainer %2 with %1.Diagnostics
119Launching process in Restricted AppContainer %1.Diagnostics
120Finished launching process in Restricted AppContainer %2 with %1.Diagnostics
121Terminating all processes in Restricted AppContainer %1.Diagnostics
122Finished terminating all processes in Restricted AppContainer %2 with %1.Diagnostics
123Checking package graph for %1.Diagnostics
124Package graph check for %2 finished with %1.Diagnostics
125Performing app integrity check for package %1.Diagnostics
126App integrity check for package %2 finished with %1.Diagnostics
127Performing runtime app integrity check for package %1.Diagnostics
128Runtime app integrity check for package %2 finished with %1.Diagnostics
129Firewall Service not running.Diagnostics
130Updating Restricted AppContainer Capabilities %1.Diagnostics
131Finished Updating Restricted AppContainer Capabilities %2 with %1.Diagnostics
201Created process %1 for application %4 in package %2.Admin
202%4: Cannot create the process for package %1 because an error was encountered.Admin
203%4: Cannot create the process for package %1 because an error was encountered …Admin
204%4: Cannot create the process for package %1 because an error was encountered …Admin
205%4: Cannot create the process for package %1 because UI Access is not supported …Admin
206%4: Cannot create the process for package %1 because an error was encountered …Admin
207%4: Cannot create the process for package %1 because an error was encountered …Admin
208%4: Cannot create the process for package %1 because an error was encountered …Admin
209%4: Cannot create the process for package %1 because an error was encountered …Admin
210Intel TXT SENTER time: MicrosoftWindows.Admin
211Added process 6212 to Desktop AppX container …Admin
212%1: Cannot add process %2 to Desktop AppX container %4 for package %3 because an …Admin
213%1: Cannot create the Desktop AppX container for package %2 because an error was …Admin
214%1: Cannot create the Desktop AppX container for package %2 because an error was …Admin
215%1: Cannot create the Desktop AppX container for package %2 because an error was …Admin
216%1: Cannot create the Desktop AppX container for package %2 because an error was …Admin
217Soft reboot complete prepare finished: MicrosoftWindows.Admin
218Cannot destroy Desktop AppX container %2 for package %1.Admin
219PSMFlags for Desktop AppX process %1 with applicationID %2 is %3.Admin
220Operational
220Cannot start the process %2 because the executable was not found the package %1.Admin

Event ID 1 — Process %1 started at time %2 by parent %3 running as package %4 with executable %5 is application %6.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Analytic

Message

Process %1 started at time %2 by parent %3 running as package %4 with executable %5 is application %6.

Fields

NameDescription
ProcessID
CreateTime
ParentProcessID
PackageFullName
ImageName
PackageRelativeApplicationId

Event ID 2 — %2: Cannot create the process for package %1 because an error was encountered.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Cannot create the process for package %1 because an error was encountered. %3

Fields

NameDescription
PackageFullName
ErrorCode
ErrorMessage

Event ID 3 — %2: Cannot create the process for package %1 because an error was encountered while querying the fast cache.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Cannot create the process for package %1 because an error was encountered while querying the fast cache. %3

Fields

NameDescription
PackageFullName
ErrorCode
ErrorMessage

Event ID 4 — %2: Cannot create the process for package %1 because an error was encountered while preparing the App credentials.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Cannot create the process for package %1 because an error was encountered while preparing the App credentials. %3

Fields

NameDescription
PackageFullName
ErrorCode
ErrorMessage

Event ID 5 — %2: Cannot create the process for package %1 because an error was encountered while checking the user-level package status.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Cannot create the process for package %1 because an error was encountered while checking the user-level package status. %3

Fields

NameDescription
PackageFullName
ErrorCode
ErrorMessage

Event ID 6 — %2: Cannot create the process for package %1 because an error was encountered while checking the machine-level package status.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Cannot create the process for package %1 because an error was encountered while checking the machine-level package status. %3

Fields

NameDescription
PackageFullName
ErrorCode
ErrorMessage

Event ID 7 — %2: Cannot create the process for package %1 because an error was encountered while verifying the App credentials.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Cannot create the process for package %1 because an error was encountered while verifying the App credentials. %3

Fields

NameDescription
PackageFullName
ErrorCode
ErrorMessage

Event ID 8 — App %1 was terminated with error %2 because of an issue with application binary %3.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

App %1 was terminated with error %2 because of an issue with application binary %3. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with. Reinstall the application to fix this issue.

Fields

NameDescription
PackageFullName
ErrorCode
FailedBinary

Event ID 9 — App %1 was terminated with error %2 because of an issue with Windows binary %3.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Application

Message

App %1 was terminated with error %2 because of an issue with Windows binary %3. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with. Refresh your PC to fix this issue.

Fields

NameDescription
PackageFullName
ErrorCode
FailedBinary

Event ID 11 — App %1 prevented the load of generated binary %3 due to error %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

App %1 prevented the load of generated binary %3 due to error %2. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with.

Fields

NameDescription
PackageFullName
ErrorCode
FailedBinary

Event ID 12 — An app prevented the load of a binary due to error %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

An app prevented the load of a binary due to error %1. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with.

Fields

NameDescription
ErrorCode

Event ID 14 — %2: Package runtime information %1 is corrupted (address=%5, size=%3, offset=%4, section=%6, processid=%7).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Package runtime information %1 is corrupted (address=%5, size=%3, offset=%4, section=%6, processid=%7). Reinstall the package to fix this issue.

Fields

NameDescription
FileName
ErrorCode
Size
Offset
HeaderAddr
Section
ProcessId

Event ID 15 — %2: Package runtime information %1 is missing expected data (address=%4, size=%3, section=%5, processid=%6).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Package runtime information %1 is missing expected data (address=%4, size=%3, section=%5, processid=%6). Reinstall the package to fix this issue.

Fields

NameDescription
FileName
ErrorCode
Size
HeaderAddr
Section
ProcessId

Event ID 16 — %2: Package runtime information %1 contains conflicting data (address=%5, size=%3, offset=%4, section=%6, processid=%7).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Package runtime information %1 contains conflicting data (address=%5, size=%3, offset=%4, section=%6, processid=%7). Reinstall the package to fix this issue.

Fields

NameDescription
FileName
ErrorCode
Size
Offset
HeaderAddr
Section
ProcessId

Event ID 17 — %2: Package runtime information %1 contains unexpected data (address=%5, size=%3, offset=%4, section=%6, processid=%7).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Package runtime information %1 contains unexpected data (address=%5, size=%3, offset=%4, section=%6, processid=%7). Reinstall the package to fix this issue.

Fields

NameDescription
FileName
ErrorCode
Size
Offset
HeaderAddr
Section
ProcessId

Event ID 18 — %2: Package runtime information %1 failed to load (processid=%3).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Package runtime information %1 failed to load (processid=%3).

Fields

NameDescription
FileName
ErrorCode
ProcessId

Event ID 19 — Package runtime information %1 failed to load because exception %2 occurred.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Package runtime information %1 failed to load because exception %2 occurred.

Fields

NameDescription
FileName
ExceptionCode

Event ID 20 — %2: Cannot create the process for package %1 because an error was encountered while loading the runtime information.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Cannot create the process for package %1 because an error was encountered while loading the runtime information. %3

Fields

NameDescription
PackageFullName
ErrorCode
ErrorMessage

Event ID 21 — CreateAppContainerProfile failed for AppContainer %2 with error %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
2
Samples
1

Message

CreateAppContainerProfile failed for AppContainer %2 with error %1.

Fields

NameDescription
ErrorCode
Context

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 21
  version: 0
  level: 2
  task: 0
  opcode: 0
  keywords: 2305913377957871618
  time_created: '2022-04-07T16:44:41.304110+00:00'
  event_record_id: 1
  correlation: {}
  execution:
    process_id: 500
    thread_id: 556
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: S-1-5-18
event_data:
  ErrorCode: 2147942410
  Context: onecore\ds\security\gina\profile\profext\appcontainer.cpp Line:1862 Usermode
    Font Driver Host microsoft.windows.fontdrvhost
message: ''

References

Event ID 22 — DeleteAppContainerProfile failed for AppContainer %2 with error %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

DeleteAppContainerProfile failed for AppContainer %2 with error %1.

Fields

NameDescription
ErrorCode
Context

Event ID 23 — UpdateAppContainerProfile failed for AppContainer %2 with error %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

UpdateAppContainerProfile failed for AppContainer %2 with error %1.

Fields

NameDescription
ErrorCode
Context

Event ID 24 — CreateAppContainerProfile failed with error %1 because it was unable to create registry key %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

CreateAppContainerProfile failed with error %1 because it was unable to create registry key %2.

Fields

NameDescription
ErrorCode
Context

Event ID 25 — CreateAppContainerProfile failed with error %1 because it was unable to set security on registry key %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

CreateAppContainerProfile failed with error %1 because it was unable to set security on registry key %2.

Fields

NameDescription
ErrorCode
Context

Event ID 26 — AppContainer profile failed with error %1 because it was unable to delete registry key %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

AppContainer profile failed with error %1 because it was unable to delete registry key %2.

Fields

NameDescription
ErrorCode
Context

Event ID 27 — CreateAppContainerProfile failed with error %1 because it was unable to create folder %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

CreateAppContainerProfile failed with error %1 because it was unable to create folder %2.

Fields

NameDescription
ErrorCode
Context

Event ID 28 — CreateAppContainerProfile failed with error %1 because it was unable to set attributes on folder %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

CreateAppContainerProfile failed with error %1 because it was unable to set attributes on folder %2.

Fields

NameDescription
ErrorCode
Context

Event ID 29 — CreateAppContainerProfile failed with error %1 because it was unable to verify the existence of registry key %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

CreateAppContainerProfile failed with error %1 because it was unable to verify the existence of registry key %2.

Fields

NameDescription
ErrorCode
Context

Event ID 30 — CreateAppContainerProfile failed with error %1 because it was unable to verify the existence of folder %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

CreateAppContainerProfile failed with error %1 because it was unable to verify the existence of folder %2.

Fields

NameDescription
ErrorCode
Context

Event ID 31 — CreateAppContainerProfile failed with error %1 because it was unable to find the users local app data folder.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

CreateAppContainerProfile failed with error %1 because it was unable to find the users local app data folder.

Fields

NameDescription
ErrorCode

Event ID 32 — AppContainer profile failed with error %1 because it was unable to delete folder %2 or its contents.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

AppContainer profile failed with error %1 because it was unable to delete folder %2 or its contents.

Fields

NameDescription
ErrorCode
Context

Event ID 33 — AppContainer profile failed with error %1 because it was unable to look up the AppContainer name.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

AppContainer profile failed with error %1 because it was unable to look up the AppContainer name.

Fields

NameDescription
ErrorCode

Event ID 34 — AppContainer profile failed with error %1 because it was unable to look up the AppContainer display name.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

AppContainer profile failed with error %1 because it was unable to look up the AppContainer display name.

Fields

NameDescription
ErrorCode

Event ID 35 — CreateAppContainerProfile failed with error %1 because it was unable to register with the firewall.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

CreateAppContainerProfile failed with error %1 because it was unable to register with the firewall.

Fields

NameDescription
ErrorCode

Event ID 36 — End

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
2
Samples
1

Message

DeleteAppContainerProfile failed with error %1 because it was unable to unregister with the firewall.

Fields

NameDescription
Data

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 36
  version: 0
  level: 2
  task: 0
  opcode: 0
  keywords: 2305843009213693954
  time_created: '2023-10-26T04:16:53.639661+00:00'
  event_record_id: 1
  correlation: {}
  execution:
    process_id: 684
    thread_id: 748
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WIN-OQ6R0RVA4NF
  security:
    user_id: S-1-5-18
event_data:
  Data:
    Name: ErrorCode
    Value: 2147944122
message: End

References

Event ID 37 — App Container profile failed with error %1 because it was unable to register the AppContainer SID.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

App Container profile failed with error %1 because it was unable to register the AppContainer SID.

Fields

NameDescription
ErrorCode

Event ID 38 — DeleteAppContainerProfile failed with error %1 because it was unable to unregister the AppContainer SID.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

DeleteAppContainerProfile failed with error %1 because it was unable to unregister the AppContainer SID.

Fields

NameDescription
ErrorCode

Event ID 39 — Successfully created AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

Successfully created AppContainer %1.

Fields

NameDescription
Data

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 39
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693954
  time_created: '2023-11-05T22:33:20.087771+00:00'
  event_record_id: 251
  correlation:
    ActivityID: E4DB489E-1037-0002-F76B-DBE43710DA01
  execution:
    process_id: 4660
    thread_id: 5424
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
  Data:
    Name: AppContainerName
    Value: Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy
message: The Scenario Event Mapper is configured with more than the maximum number
  of context providers for the scenario with provider AppContainerName (event ID Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy).  The
  scenario will be ignored.

References

Event ID 40 — AppContainer %1 was not created because it already exists.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

AppContainer %1 was not created because it already exists.

Fields

NameDescription
Data

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 40
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693954
  time_created: '2023-11-06T06:25:28.239888+00:00'
  event_record_id: 202
  correlation: {}
  execution:
    process_id: 736
    thread_id: 776
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  Data:
    Name: AppContainerName
    Value: onecore\ds\security\gina\profile\profext\appcontainer.cpp Line:1850 Usermode
      Font Driver Host microsoft.windows.fontdrvhost
message: The Scenario Event Mapper is configured with more than the maximum number
  of end events for the scenario with provider AppContainerName (event ID onecore\ds\security\gina\profile\profext\appcontainer.cpp
  Line:1850 Usermode Font Driver Host microsoft.windows.fontdrvhost).  The scenario
  will be ignored.

References

Event ID 41 — The Scenario Event Mapper is configured with more than the maximum number of providers.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

Successfully deleted AppContainer %1.

Fields

NameDescription
Data

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 41
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693954
  time_created: '2023-10-26T04:18:43.498634+00:00'
  event_record_id: 5
  correlation: {}
  execution:
    process_id: 2888
    thread_id: 3124
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WIN-OQ6R0RVA4NF
  security:
    user_id: S-1-5-18
event_data:
  Data:
    Name: AppContainerName
    Value: MPENG_9430677C-98FB-4F60-AE90-7960774C825F
message: The Scenario Event Mapper is configured with more than the maximum number
  of providers.  The provider AppContainerName will be ignored.

References

Event ID 42 — The Scenario Event Mapper is configured with an unsupported scenario.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

Successfully updated AppContainer %1.

Fields

NameDescription
Data

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 42
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693954
  time_created: '2023-11-05T22:29:23.081725+00:00'
  event_record_id: 227
  correlation:
    ActivityID: 59A0D65F-1037-0001-20F2-A0593710DA01
  execution:
    process_id: 5296
    thread_id: 5800
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
  Data:
    Name: AppContainerName
    Value: Microsoft.VCLibs.140.00.UWPDesktop_8wekyb3d8bbwe
message: The Scenario Event Mapper is configured with an unsupported scenario. The
  scenario for provider AppContainerName (event ID Microsoft.VCLibs.140.00.UWPDesktop_8wekyb3d8bbwe)
  encountered error code %3 and will be ignored.

References

Event ID 43 — %2: Package runtime information %1 is missing expected data (address=%4, size=%3, section=%5, processid=%6).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Package runtime information %1 is missing expected data (address=%4, size=%3, section=%5, processid=%6). Reinstall the package to fix this issue.

Fields

NameDescription
FileName
ErrorCode
Size
HeaderAddr
ApplicationUserModelId
ProcessId

Event ID 44 — %2: Application identity not accessible while loading package runtime information %1 (address=%4, size=%3, processid=%5).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Application identity not accessible while loading package runtime information %1 (address=%4, size=%3, processid=%5).

Fields

NameDescription
FileName
ErrorCode
Size
HeaderAddr
ProcessId

Event ID 45 — Failed with %1 while retrieving AppContainer %2 information during interaction with Restricted AppContainer.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed with %1 while retrieving AppContainer %2 information during interaction with Restricted AppContainer.

Fields

NameDescription
ErrorCode
Context

Event ID 46 — Failed with %1 while retrieving AppContainer information during interaction with Restricted AppContainer.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed with %1 while retrieving AppContainer information during interaction with Restricted AppContainer.

Fields

NameDescription
ErrorCode

Event ID 47 — Failed with %1 while retrieving AppContainer information.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed with %1 while retrieving AppContainer information. Call invalid from this process type.

Fields

NameDescription
ErrorCode

Event ID 48 — Failed to create shared context object for Restricted AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed to create shared context object for Restricted AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 49 — Failed to activate Restricted AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed to activate Restricted AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 50 — Creation of Restricted AppContainer %2 failed with %1 because an invalid capability was specified.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Creation of Restricted AppContainer %2 failed with %1 because an invalid capability was specified.

Fields

NameDescription
ErrorCode
Context

Event ID 51 — Opening existing Restricted AppContainer %2 failed with %1 because the capabilities storage value could not be read.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Opening existing Restricted AppContainer %2 failed with %1 because the capabilities storage value could not be read.

Fields

NameDescription
ErrorCode
Context

Event ID 52 — Failed to create the capabilities storage value for Restricted AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed to create the capabilities storage value for Restricted AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 53 — The package %1 requires validation.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

The package %1 requires validation.

Fields

NameDescription
PackageFullName

Event ID 54 — Modification was detected in package %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Modification was detected in package %1.

Fields

NameDescription
PackageFullName

Event ID 55 — Failed to terminate app with package %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed to terminate app with package %1.

Fields

NameDescription
PackageFullName

Event ID 56 — Validation of app with package %1 was successful.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Validation of app with package %1 was successful.

Fields

NameDescription
PackageFullName

Event ID 57 — Failed with %1 to retrieve the trust state of the package %2 folder.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed with %1 to retrieve the trust state of the package %2 folder.

Fields

NameDescription
ErrorCode
PackageFullName

Event ID 58 — App Integrity check failed with %1 while checking %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

App Integrity check failed with %1 while checking %2.

Fields

NameDescription
ErrorCode
PackageFullName

Event ID 59 — App Integrity terminated an application.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

App Integrity terminated an application. Integrity check for %2 returned %1.

Fields

NameDescription
ErrorCode
PackageFullName

Event ID 60 — App Integrity check for %1 timed out.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

App Integrity check for %1 timed out.

Fields

NameDescription
PackageFullName

Event ID 61 — %2: Cannot create the process for package %1 because an error was encountered while performing the integrity check.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Cannot create the process for package %1 because an error was encountered while performing the integrity check. %3

Fields

NameDescription
PackageFullName
ErrorCode
ErrorMessage

Event ID 62 — Deployment server integrity check of package %1 failed with %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Deployment server integrity check of package %1 failed with %2.

Fields

NameDescription
ErrorCode
PackageFullName

Event ID 63 — Failed with %1 retrieving AppModel Runtime group policy values.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed with %1 retrieving AppModel Runtime group policy values.

Fields

NameDescription
ErrorCode
Resource

Event ID 64 — Failed with %1 validating AppModel Runtime group policy values.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed with %1 validating AppModel Runtime group policy values.

Fields

NameDescription
ErrorCode
Resource

Event ID 65 — Failed with %1 retrieving AppModel Runtime status for package %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed with %1 retrieving AppModel Runtime status for package %2.

Fields

NameDescription
ErrorCode
PackageFullName

Event ID 66 — Failed with %1 retrieving AppModel Runtime status for package %2 for user %3.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
2
Samples
1

Message

Failed with %1 retrieving AppModel Runtime status for package %2 for user %3.

Fields

NameDescription
ErrorCode
PackageFullName
User

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 66
  version: 0
  level: 2
  task: 0
  opcode: 0
  keywords: 2305843009213693953
  time_created: '2022-04-07T16:53:25.460837+00:00'
  event_record_id: 56
  correlation: {}
  execution:
    process_id: 4128
    thread_id: 5340
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
  ErrorCode: 87
  PackageFullName: Windows
  User: S-1-5-21-2121334350-1110938707-2888912545-500
message: ''

References

Event ID 67 — Failed with %1 modifying AppModel Runtime status for package %2 (current status = %4, desired status = %3).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed with %1 modifying AppModel Runtime status for package %2 (current status = %4, desired status = %3).

Fields

NameDescription
ErrorCode
PackageFullName
DesiredStatus
CurrentStatus

Event ID 68 — AppModel Runtime status for package %1 successfully updated to %2 (previous status = %3).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

AppModel Runtime status for package %1 successfully updated to %2 (previous status = %3).

Fields

NameDescription
PackageFullName
DesiredStatus
CurrentStatus

Event ID 69 — Failed with %1 modifying AppModel Runtime status for package %2 for user %3 (clear=%4, set=%5).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

Failed with %1 modifying AppModel Runtime status for package %2 for user %3 (clear=%4, set=%5).

Fields

NameDescription
ErrorCode
PackageFullName
User
DesiredStatus
CurrentStatus

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 69
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693953
  time_created: '2022-04-07T17:04:34.316467+00:00'
  event_record_id: 69
  correlation:
    ActivityID: DD7B0B6A-4A9E-0001-314A-7BDD9E4AD801
  execution:
    process_id: 5972
    thread_id: 2672
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: S-1-5-18
event_data:
  ErrorCode: 1168
  PackageFullName: Microsoft.UI.Xaml.2.4_2.42007.9001.0_x64__8wekyb3d8bbwe
  User: S-1-5-21-2121334350-1110938707-2888912545-500
  DesiredStatus: 32
  CurrentStatus: 0
message: ''

References

Event ID 70 — Successfully updated AppModel Runtime status for package %1 for user %2 (clear=%3, set=%4).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

Successfully updated AppModel Runtime status for package %1 for user %2 (clear=%3, set=%4).

Fields

NameDescription
PackageFullName
User
DesiredStatus
CurrentStatus

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 70
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693953
  time_created: '2022-04-07T17:04:43.551444+00:00'
  event_record_id: 139
  correlation:
    ActivityID: DD7B0B6A-4A9E-0001-7475-7BDD9E4AD801
  execution:
    process_id: 5972
    thread_id: 904
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: S-1-5-18
event_data:
  PackageFullName: MicrosoftWindows.UndockedDevKit_10.0.20348.1_neutral_neutral_cw5n1h2txyewy
  User: S-1-5-21-2121334350-1110938707-2888912545-500
  DesiredStatus: 0
  CurrentStatus: 2048
message: ''

References

Event ID 71 — Failed with %1 modifying AppModel Runtime status version (context = %2).

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed with %1 modifying AppModel Runtime status version (context = %2).

Fields

NameDescription
ErrorCode
Context

Event ID 72 — AppModel Runtime status version successfully updated.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Debug

Message

AppModel Runtime status version successfully updated.

Event ID 73 — %2: Cannot create the process for package %1 because an error was encountered while performing the app data creation.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Cannot create the process for package %1 because an error was encountered while performing the app data creation. %3

Fields

NameDescription
PackageFullName
ErrorCode
ErrorMessage

Event ID 74 — Package runtime information %1 failed to refresh because the following error %2 occurred in operation type %3.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Package runtime information %1 failed to refresh because the following error %2 occurred in operation type %3.

Fields

NameDescription
FileName
ErrorCode
Type
ProcessId

Event ID 75 — error %2: Cannot register the %1 package because the following error was encountered while opening the HKEY_USERS registry key.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

error %2: Cannot register the %1 package because the following error was encountered while opening the HKEY_USERS registry key

Fields

NameDescription
PackageFullName
ErrorCode

Event ID 76 — error %4: Cannot register the %1 package because the following error was encountered while enumerating to remove the %2\%3 package family registry ...

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

error %4: Cannot register the %1 package because the following error was encountered while enumerating to remove the %2\%3 package family registry key

Fields

NameDescription
PackageFullName
Key
Subkey
ErrorCode

Event ID 77 — error %4 : Cannot register the %1 package because the following error was encountered while creating the %2\%3 package family registry key.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

error %4 : Cannot register the %1 package because the following error was encountered while creating the %2\%3 package family registry key

Fields

NameDescription
PackageFullName
Key
Subkey
ErrorCode

Event ID 78 — error %4: Cannot register the %1 package because the following error was encountered while removing the %2\%3 package family registry key.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

error %4: Cannot register the %1 package because the following error was encountered while removing the %2\%3 package family registry key

Fields

NameDescription
PackageFullName
Key
Subkey
ErrorCode

Event ID 79 — %2: Package family %1 runtime information is corrupted.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Package family %1 runtime information is corrupted. Attempting to correct the issue.

Fields

NameDescription
PackageFamilyName
ErrorCode

Event ID 80 — %2: Package family %1 runtime information is corrupted but we cannot repair it at this time.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%2: Package family %1 runtime information is corrupted but we cannot repair it at this time.

Fields

NameDescription
PackageFamilyName
ErrorCode

Event ID 81 — Failed with %1 to get IsPackageStageInPlace info from State Repository cache for package %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Failed with %1 to get IsPackageStageInPlace info from State Repository cache for package %2. The app will by default require integrity check.

Fields

NameDescription
ErrorCode
PackageFullName

Event ID 101 — Creating AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Creating AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 102 — Finished creating AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished creating AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 103 — Deleting AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Deleting AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 104 — Finished deleting AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished deleting AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 105 — Updating AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Updating AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 106 — Finished updating AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished updating AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 107 — Creating firewall rules for AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Creating firewall rules for AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 108 — Finished creating firewall rules for AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished creating firewall rules for AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 109 — Deleting firewall rules for AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Deleting firewall rules for AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 110 — Finished deleting firewall rules for AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished deleting firewall rules for AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 111 — Creating Restricted AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Creating Restricted AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 112 — Finished creating Restricted AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished creating Restricted AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 113 — Deleting Restricted AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Deleting Restricted AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 114 — Finished deleting Restricted AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished deleting Restricted AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 115 — Opening Restricted AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Opening Restricted AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 116 — Finished opening Restricted AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished opening Restricted AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 117 — Enumerating all Restricted AppContainers for %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Enumerating all Restricted AppContainers for %1.

Fields

NameDescription
AppContainerName

Event ID 118 — Finished enumerating all Restricted AppContainers for AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished enumerating all Restricted AppContainers for AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 119 — Launching process in Restricted AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Launching process in Restricted AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 120 — Finished launching process in Restricted AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished launching process in Restricted AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 121 — Terminating all processes in Restricted AppContainer %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Terminating all processes in Restricted AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 122 — Finished terminating all processes in Restricted AppContainer %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished terminating all processes in Restricted AppContainer %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 123 — Checking package graph for %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Checking package graph for %1.

Fields

NameDescription
PackageFullName

Event ID 124 — Package graph check for %2 finished with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Package graph check for %2 finished with %1.

Fields

NameDescription
ErrorCode
PackageFullName

Event ID 125 — Performing app integrity check for package %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Performing app integrity check for package %1.

Fields

NameDescription
PackageFullName

Event ID 126 — App integrity check for package %2 finished with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

App integrity check for package %2 finished with %1.

Fields

NameDescription
ErrorCode
PackageFullName

Event ID 127 — Performing runtime app integrity check for package %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Performing runtime app integrity check for package %1.

Fields

NameDescription
PackageFullName

Event ID 128 — Runtime app integrity check for package %2 finished with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Runtime app integrity check for package %2 finished with %1.

Fields

NameDescription
ErrorCode
PackageFullName

Event ID 129 — Firewall Service not running.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Firewall Service not running. Skipping creation of firewall rules for AppContainer %1.

Fields

NameDescription
AppContainerName

Event ID 130 — Updating Restricted AppContainer Capabilities %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Updating Restricted AppContainer Capabilities %1.

Fields

NameDescription
AppContainerName

Event ID 131 — Finished Updating Restricted AppContainer Capabilities %2 with %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Diagnostics

Message

Finished Updating Restricted AppContainer Capabilities %2 with %1.

Fields

NameDescription
ErrorCode
Context

Event ID 201 — Created process %1 for application %4 in package %2.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

Created process %1 for application %4 in package %2. %5

Fields

NameDescription
ProcessID
PackageName
ImageName
ApplicationName
Message

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 201
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693956
  time_created: '2023-11-06T01:55:56.247720+00:00'
  event_record_id: 466
  correlation: {}
  execution:
    process_id: 5324
    thread_id: 18660
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  ProcessID: 21588
  PackageName: Microsoft.WindowsNotepad_11.2307.27.0_x64__8wekyb3d8bbwe
  ImageName: Notepad.exe
  ApplicationName: Microsoft.WindowsNotepad_8wekyb3d8bbwe!App
  Message: '[FinishPackageActivation]'
message: ''

Sigma Rules

  • Sysinternals Tools AppX Versions Execution
    Detects execution of Sysinternals tools via an AppX package. Attackers could install the Sysinternals Suite to get access to tools such as psexec and procdump to avoid detection based on System paths.

References

Event ID 202 — %4: Cannot create the process for package %1 because an error was encountered.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%4: Cannot create the process for package %1 because an error was encountered. %5

Fields

NameDescription
PackageName
ImageName
ApplicationName
ErrorCode
Message

Event ID 203 — %4: Cannot create the process for package %1 because an error was encountered while preparing for activation.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%4: Cannot create the process for package %1 because an error was encountered while preparing for activation. %5

Fields

NameDescription
PackageName
ImageName
ApplicationName
ErrorCode
Message

Event ID 204 — %4: Cannot create the process for package %1 because an error was encountered while elevating the token.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%4: Cannot create the process for package %1 because an error was encountered while elevating the token. %5

Fields

NameDescription
PackageName
ImageName
ApplicationName
ErrorCode
Message

Event ID 205 — %4: Cannot create the process for package %1 because UI Access is not supported for Desktop AppX processes.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%4: Cannot create the process for package %1 because UI Access is not supported for Desktop AppX processes. %5

Fields

NameDescription
PackageName
ImageName
ApplicationName
ErrorCode
Message

Event ID 206 — %4: Cannot create the process for package %1 because an error was encountered while adjusting the token.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%4: Cannot create the process for package %1 because an error was encountered while adjusting the token. %5

Fields

NameDescription
PackageName
ImageName
ApplicationName
ErrorCode
Message

Event ID 207 — %4: Cannot create the process for package %1 because an error was encountered while launching.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%4: Cannot create the process for package %1 because an error was encountered while launching. %5

Fields

NameDescription
PackageName
ImageName
ApplicationName
ErrorCode
Message

Event ID 208 — %4: Cannot create the process for package %1 because an error was encountered while configuring runtime.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%4: Cannot create the process for package %1 because an error was encountered while configuring runtime. %5

Fields

NameDescription
PackageName
ImageName
ApplicationName
ErrorCode
Message

Event ID 209 — %4: Cannot create the process for package %1 because an error was encountered while resuming the thread.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%4: Cannot create the process for package %1 because an error was encountered while resuming the thread. %5

Fields

NameDescription
PackageName
ImageName
ApplicationName
ErrorCode
Message

Event ID 210 — Intel TXT SENTER time: MicrosoftWindows.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

Created Desktop AppX container %3 for package %1.

Fields

NameDescription
PackageName
ContainerName
ContainerId

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 210
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693960
  time_created: '2023-11-05T22:32:34.540536+00:00'
  event_record_id: 239
  correlation:
    ActivityID: E4DB489E-1037-0003-2157-DBE43710DA01
  execution:
    process_id: 920
    thread_id: 472
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  PackageName: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy
  ContainerName: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy-S-1-5-21-1992711665-1655669231-58201500-1000
  ContainerId: '{22A04431-7C2B-11EE-936C-000C293379BA}'
message: 'Intel TXT SENTER time: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy
  ms.'

References

Event ID 211 — Added process 6212 to Desktop AppX container {22A04431-7C2B-11EE-936C-000C293379BA} for package MicrosoftWindows.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

Added process %1 to Desktop AppX container %3 for package %2.

Fields

NameDescription
ProcessID
PackageName
ContainerId

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 211
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693960
  time_created: '2023-11-05T22:32:34.540594+00:00'
  event_record_id: 240
  correlation:
    ActivityID: E4DB489E-1037-0003-2157-DBE43710DA01
  execution:
    process_id: 920
    thread_id: 472
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  ProcessID: 6212
  PackageName: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy
  ContainerId: '{22A04431-7C2B-11EE-936C-000C293379BA}'
message: Added process 6212 to Desktop AppX container {22A04431-7C2B-11EE-936C-000C293379BA}
  for package MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy.

References

Event ID 212 — %1: Cannot add process %2 to Desktop AppX container %4 for package %3 because an error was encountered.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%1: Cannot add process %2 to Desktop AppX container %4 for package %3 because an error was encountered.

Fields

NameDescription
ErrorCode
ProcessID
PackageName
ContainerId

Event ID 213 — %1: Cannot create the Desktop AppX container for package %2 because an error was encountered creating the job.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%1: Cannot create the Desktop AppX container for package %2 because an error was encountered creating the job.

Fields

NameDescription
ErrorCode
PackageName
ContainerName

Event ID 214 — %1: Cannot create the Desktop AppX container for package %2 because an error was encountered creating the description.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%1: Cannot create the Desktop AppX container for package %2 because an error was encountered creating the description.

Fields

NameDescription
ErrorCode
PackageName
ContainerName

Event ID 215 — %1: Cannot create the Desktop AppX container for package %2 because an error was encountered converting the job.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%1: Cannot create the Desktop AppX container for package %2 because an error was encountered converting the job.

Fields

NameDescription
ErrorCode
PackageName
ContainerName

Event ID 216 — %1: Cannot create the Desktop AppX container for package %2 because an error was encountered configuring the runtime.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

%1: Cannot create the Desktop AppX container for package %2 because an error was encountered configuring the runtime.

Fields

NameDescription
ErrorCode
PackageName
ContainerName

Event ID 217 — Soft reboot complete prepare finished: MicrosoftWindows.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

Destroyed Desktop AppX container %2 for package %1.

Fields

NameDescription
PackageName
ContainerId

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
  event_source_name: ''
  event_id: 217
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693960
  time_created: '2023-11-05T22:31:32.531960+00:00'
  event_record_id: 236
  correlation:
    ActivityID: 59A0D65F-1037-0002-A9F7-A0593710DA01
  execution:
    process_id: 928
    thread_id: 6576
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  PackageName: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy
  ContainerId: '{975E2192-7C2A-11EE-936B-000C293379BA}'
message: 'Soft reboot complete prepare finished: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy.'

References

Event ID 218 — Cannot destroy Desktop AppX container %2 for package %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Cannot destroy Desktop AppX container %2 for package %1.

Fields

NameDescription
CleanupContainerErrorCode
MakeTemporaryErrorCode
PackageName
ContainerId

Event ID 219 — PSMFlags for Desktop AppX process %1 with applicationID %2 is %3.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin
Level
4
Samples
1

Message

PSMFlags for Desktop AppX process %1 with applicationID %2 is %3.

Fields

NameDescription
PackageFullName
ApplicationId
PsmFlags

Example Event

system:
  provider: Microsoft-Windows-AppModel-Runtime
  guid: '{f1ef270a-0d32-4352-ba52-dbab41e1d859}'
  event_source_name: ''
  event_id: 219
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213693956
  time_created: '2023-11-06T01:55:55.914607+00:00'
  event_record_id: 463
  correlation: {}
  execution:
    process_id: 5324
    thread_id: 18660
  channel: Microsoft-Windows-AppModel-Runtime/Admin
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''

References

Event ID 220 —

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Operational

Fields

NameDescription
PackageName
ImageName
ApplicationName
ErrorCode
Message

Event ID 220 — Cannot start the process %2 because the executable was not found the package %1.

Provider
Microsoft-Windows-AppModel-Runtime
Channel
Admin

Message

Cannot start the process %2 because the executable was not found the package %1.

Fields

NameDescription
PackageName
ImageName
ApplicationName
ErrorCode
Message