Microsoft-Windows-EFS

172 events across 3 channels

Event IDTitleChannel
1An API call failed at %1.Debug
2An API call failed at %1.Debug
3An API call failed at %1.Debug
4%1.Debug
256EFS key promoted from current key.Debug
257EFS key demoted from current key.Debug
258EFS key flushed from cache.Debug
259%1.Debug
260%1.Debug
261%1.Debug
262%1.Debug
263%1.Debug
264%1.Debug
265%1.Debug
272%1.Debug
273%1.Debug
274%1.Debug
275%1.Debug
276%1.Debug
277%1.Debug
278%1.Debug
279%1.Debug
280%1.Debug
281%1.Debug
288%1.Debug
289%1.Debug
290%1.Debug
512%1.Debug
513%1.Debug
514%1.Debug
515%1.Debug
516%1.Debug
517EFS key added to user cache.Debug
518%1.Debug
519%1.Debug
520%1.Debug
521%1.Debug
768%1.Debug
769%1.Debug
770%1.Debug
771%1.Debug
772%1.Debug
773%1.Debug
774%1.Debug
775%1.Debug
776%1.Debug
777%1.Debug
784%1.Debug
785%1.Debug
786%1.Debug
787%1.Debug
788%1.Debug
789%1.Debug
790%1.Debug
791%1.Debug
792%1.Debug
793%1.Debug
800%1.Debug
801%1.Debug
802%1.Debug
803%1.Debug
804%1.Debug
805%1.Debug
1024%1.Debug
1040%1.Debug
1041%1.Debug
1042%1.Debug
1280%1.Debug
1281%1.Debug
1282%1.Debug
1283%1.Debug
1284%1.Debug
1536PIN prompt dialog has closedDebug
1537Prompt the user to select a smartcard-based EFS certDebug
1538Smartcard-based EFS cert successfully selected by the userDebug
1539Prompt the user for PINDebug
1540PIN successfully acquired from the userDebug
1541Perfect match found in cache.Debug
1542Masterkey history already loadedDebug
1543Current key loaded from cacheDebug
1544Current key loaded from registryDebug
1545%1.Debug
4096%1.Debug
4097%1.Debug
4098%1.Debug
4099%1.Debug
4100%1.Debug
4101%1.Debug
4102%1.Debug
4353%1.Debug
4354%1.Debug
4355%1.Debug
4356%1.Debug
4357%1.Debug
4358%1.Debug
4359%1.Debug
4360%1.Debug
4361%1.Debug
4368%1.Debug
4369%1.Debug
4370%1.Debug
4371%1.Debug
4372%1.Debug
4373%1.Debug
4374%1.Debug
4375%1.Debug
4376EFS Service failed to start.Application
4377%1.Debug
4378%1.Debug
4379EFS service was unable to populate SID information.Application
4380EFS service was unable to determine the computer name.Application
4381EFS service was unable to initialize cache lock.Application
4382EFS service was unable to initialize the BCrypt Algorithm Provider.Application
4383EFS service was unable to query Software Licensing for the cache size.Application
4384EFS service was unable to open handle to the MS_DEF_PROV provider.Application
4385EFS service was unable to setup notifications from LSA.Application
4386EFS service was unable to initialize the recovery policy resource.Application
4387EFS service was unable process the recovery policy.Application
4388EFS service was unable to notify NTFS of its state.Application
4389EFS service was unable to setup group policy change notifications.Application
4390EFS service was unable to process active user sessions.Application
4391Encrypting File System server ready to accept calls.Debug
4392%1.Application
4393%1.Application
4400%1.Application
4401%1.Application
4402%1.Application
4403%1.Application
4404%1.Application
4405%1.Debug
4406%1.Debug
4407%1.Debug
4408%1.Debug
4409%1.Debug
4410%1.Debug
4411%1.Debug
4412%1.Debug
4413%1.Debug
4414%1.Debug
4415%1.Debug
4416%1.Debug
4417%1.Debug
4418%1.Application
4419Thread %1: %2, Line %3, HRESULT %4, Message: '%5'.Debug
4420A client attempted to call an EFS service API without privacy level …Application
4421A client that called an EFS service API without privacy level authentication was …Application
4422Failed to unprotect device user credential key using Windows Hello for user.Operational
4423Personal Data Encryption and Windows Hello status updated: 1) Windows Hello …Operational
4424Personal Data Encryption enabled for user %3.Operational
4425Personal Data Encryption disabled for user %3.Operational
4432User %3 attempted to access user %4's data protected with Personal Data …Operational
4433Personal Data Encryption conversion started.Operational
4434Personal Data Encryption conversion completed.Operational
4435Personal Data Encryption conversion did not complete.Operational
4436Personal Data Encryption conversion failed to convert one or more files or …Operational
4437Personal Data Encryption policy for Desktop folder is set to %4 for user %3.Operational
4438Personal Data Encryption policy for Documents folder is set to %4 for user %3.Operational
4439Personal Data Encryption policy for Pictures folder is set to %4 for user %3.Operational
4440Personal Data Encryption policy for Desktop folder is deleted for user %3.Operational
4441Personal Data Encryption policy for Documents folder is deleted for user %3.Operational
4448Personal Data Encryption policy for Pictures folder is deleted for user %3.Operational
4449Personal Data Encryption policy for Desktop folder is mapped to path ".Operational
4450Personal Data Encryption policy for Documents folder is mapped to path ".Operational
4451Personal Data Encryption policy for Pictures folder is mapped to path ".Operational
4452Personal Data Encryption: paths to protect folders is empty for user %3.Operational
4453Windows Information Protection has been disabled.Operational
4454Windows Information Protection could not be disabled.Operational
4455Personal Data Encryption conversion did not complete the last time it was run.Operational
4456Personal Data Encryption is not available for the current device.Operational
4457Personal Data Encryption is not available for the current device.Operational
7000Machine role cannot be determined.Application
7002Default group policy object cannot be created.Application

Event ID 1 — An API call failed at %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

An API call failed at %1.%2.  Error code: %3

Fields

NameDescription
FileNumber
LineNumber
Param

Event ID 2 — An API call failed at %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

An API call failed at %1.%2.  Error code: %3, Data: %4

Fields

NameDescription
Data
FileNumber
LineNumber
Param1
Param2

Event ID 3 — An API call failed at %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

An API call failed at %1.%2.  Error code: %3, Data: %4, %5

Fields

NameDescription
Data
FileNumber
LineNumber
Param1
Param2
Param3

Event ID 4 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Failed to allocate %3 bytes.

Fields

NameDescription
FileNumber
LineNumber
Param

Event ID 256 — EFS key promoted from current key.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

EFS key promoted from current key.  CertValidated: %1, cbHash: %2, pbHash: %3, ContainerName: %4, ProviderName: %5, DisplayInformation: %6, dwCapabilities: %7, bIsCurrentKey: %8, eKeyType: %9

Fields

NameDescription
CertValidated
cbHash
pbHash
ContainerName
ProviderName
DisplayInformation
dwCapabilities
bIsCurrentKey
eKeyType

Event ID 257 — EFS key demoted from current key.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

EFS key demoted from current key.  CertValidated: %1, cbHash: %2, pbHash: %3, ContainerName: %4, ProviderName: %5, DisplayInformation: %6, dwCapabilities: %7, bIsCurrentKey: %8, eKeyType: %9

Fields

NameDescription
CertValidated
cbHash
pbHash
ContainerName
ProviderName
DisplayInformation
dwCapabilities
bIsCurrentKey
eKeyType

Event ID 258 — EFS key flushed from cache.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

EFS key flushed from cache.  CertValidated: %1, cbHash: %2, pbHash: %3, ContainerName: %4, ProviderName: %5, DisplayInformation: %6, dwCapabilities: %7, bIsCurrentKey: %8, eKeyType: %9

Fields

NameDescription
CertValidated
cbHash
pbHash
ContainerName
ProviderName
DisplayInformation
dwCapabilities
bIsCurrentKey
eKeyType

Event ID 259 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: The specified key is not valid for EFS

Fields

NameDescription
FileNumber
LineNumber

Event ID 260 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Attempt to create a new EFS key

Fields

NameDescription
FileNumber
LineNumber

Event ID 261 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: A new EFS key was successfully created

Fields

NameDescription
FileNumber
LineNumber

Event ID 262 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Begin searching the MY store for a valid EFS key

Fields

NameDescription
FileNumber
LineNumber

Event ID 263 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Begin searching the MY store for a valid EFS key

Fields

NameDescription
FileNumber
LineNumber

Event ID 264 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Deleting currentkey from registry

Fields

NameDescription
FileNumber
LineNumber

Event ID 265 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: The EFS cert is self-signed, but self-signed certs are disabled by policy

Fields

NameDescription
FileNumber
LineNumber

Event ID 272 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: RSA is required by policy, but the key does not support RSA encryption

Fields

NameDescription
FileNumber
LineNumber

Event ID 273 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: MASTERKEY is required by policy, but the key does not support MASTERKEY encryption

Fields

NameDescription
FileNumber
LineNumber

Event ID 274 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: SMARTCARDS are required by policy, but the key is not SMARTCARD-based

Fields

NameDescription
FileNumber
LineNumber

Event ID 275 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: key is expired

Fields

NameDescription
FileNumber
LineNumber

Event ID 276 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: key is valid

Fields

NameDescription
FileNumber
LineNumber

Event ID 277 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: try and locate the matching key based on cert hash

Fields

NameDescription
FileNumber
LineNumber

Event ID 278 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: key successfully loaded from registry

Fields

NameDescription
FileNumber
LineNumber

Event ID 279 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: try and locate the matching key in cache

Fields

NameDescription
FileNumber
LineNumber

Event ID 280 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: trying to load the masterkey history

Fields

NameDescription
FileNumber
LineNumber

Event ID 281 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: masterkey history loaded

Fields

NameDescription
FileNumber
LineNumber

Event ID 288 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: failed to encrypt: SIS or HSM file

Fields

NameDescription
FileNumber
LineNumber

Event ID 289 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Suite B is disabled by policy, but the key is a Suite B key

Fields

NameDescription
FileNumber
LineNumber

Event ID 290 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Suite B is required by policy, but the key is not a Suite B key

Fields

NameDescription
FileNumber
LineNumber

Event ID 512 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: releasing user cache object.  Refcount: %3

Fields

NameDescription
FileNumber
LineNumber
Param

Event ID 513 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: trying to stop cache polling thread

Fields

NameDescription
FileNumber
LineNumber

Event ID 514 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: no decryption status in cache

Fields

NameDescription
FileNumber
LineNumber

Event ID 515 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: found matching decryption status in cache

Fields

NameDescription
FileNumber
LineNumber

Event ID 516 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: attempting to add key to user cache

Fields

NameDescription
FileNumber
LineNumber

Event ID 517 — EFS key added to user cache.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

EFS key added to user cache.  CertValidated: %1, cbHash: %2, pbHash: %3, ContainerName: %4, ProviderName: %5, DisplayInformation: %6, dwCapabilities: %7, bIsCurrentKey: %8, eKeyType: %9

Fields

NameDescription
CertValidated
cbHash
pbHash
ContainerName
ProviderName
DisplayInformation
dwCapabilities
bIsCurrentKey
eKeyType

Event ID 518 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: ensuring user has cache node

Fields

NameDescription
FileNumber
LineNumber

Event ID 519 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: found cache node in user info

Fields

NameDescription
FileNumber
LineNumber

Event ID 520 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: found cache node in global cache

Fields

NameDescription
FileNumber
LineNumber

Event ID 521 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: creating new cache node for user

Fields

NameDescription
FileNumber
LineNumber

Event ID 768 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Policy settings specified flush on card removal.  Starting the polling thread...

Fields

NameDescription
FileNumber
LineNumber

Event ID 769 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Policy settings specified NO flush on timeout.  Stopping the polling thread...

Fields

NameDescription
FileNumber
LineNumber

Event ID 770 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Policy settings specified flush on timeout.  Starting the polling thread...

Fields

NameDescription
FileNumber
LineNumber

Event ID 771 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Policy settings specified new cache flush interval: %3.  Stop polling (will restart if there are active user caches)

Fields

NameDescription
FileNumber
LineNumber
Param

Event ID 772 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Polling thread stopped

Fields

NameDescription
FileNumber
LineNumber

Event ID 773 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Flush cache specified by policy, and we have active user caches.  Start polling.

Fields

NameDescription
FileNumber
LineNumber

Event ID 774 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Polling thread started

Fields

NameDescription
FileNumber
LineNumber

Event ID 775 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: User logon detected.  Beginning SSO processing.

Fields

NameDescription
FileNumber
LineNumber

Event ID 776 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: User logon detected, but is not smartcard-based.  No SSO processing required.

Fields

NameDescription
FileNumber
LineNumber

Event ID 777 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Smartcard notification detected.  Beginning SSO processing.

Fields

NameDescription
FileNumber
LineNumber

Event ID 784 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Smartcard notification detected, but the logon cert is already cached.  No processing required.

Fields

NameDescription
FileNumber
LineNumber

Event ID 785 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Current key matches the logon cert.  Setting up the PIN cache.

Fields

NameDescription
FileNumber
LineNumber

Event ID 786 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: User does not yet have a current key.  If smartcard is required by policy, the logon cert and PIN will be cached.

Fields

NameDescription
FileNumber
LineNumber

Event ID 787 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Logon notification detected on DC.  Beginning DRA install.

Fields

NameDescription
FileNumber
LineNumber

Event ID 788 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: user does not already have a cache: generating one now

Fields

NameDescription
FileNumber
LineNumber

Event ID 789 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: generating pre-cache for PIN and logon cert

Fields

NameDescription
FileNumber
LineNumber

Event ID 790 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: tried to install logon cert, but it's not available (not a smartcard logon, or the smartcard was removed)

Fields

NameDescription
FileNumber
LineNumber

Event ID 791 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: logon cert successfully installed

Fields

NameDescription
FileNumber
LineNumber

Event ID 792 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: trying to install logon cert

Fields

NameDescription
FileNumber
LineNumber

Event ID 793 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: User lock detected.  Beginning SSO processing.

Fields

NameDescription
FileNumber
LineNumber

Event ID 800 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: User logoff detected.  Beginning SSO processing.

Fields

NameDescription
FileNumber
LineNumber

Event ID 801 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Flushing the user cache

Fields

NameDescription
FileNumber
LineNumber

Event ID 802 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: User has locked workstation, but policy says not to flush cache

Fields

NameDescription
FileNumber
LineNumber

Event ID 803 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Checking for expired cache entries

Fields

NameDescription
FileNumber
LineNumber

Event ID 804 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Expired certificate in recovery policy

Fields

NameDescription
FileNumber
LineNumber

Event ID 805 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Certificate in recovery policy is not yet valid

Fields

NameDescription
FileNumber
LineNumber

Event ID 1024 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: SL policy successfully updated

Fields

NameDescription
FileNumber
LineNumber

Event ID 1040 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS is disabled by SL policy

Fields

NameDescription
FileNumber
LineNumber

Event ID 1041 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS is not yet initialized

Fields

NameDescription
FileNumber
LineNumber

Event ID 1042 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS is disabled

Fields

NameDescription
FileNumber
LineNumber

Event ID 1280 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: the data received by the API was too large.  Expected: %3, Actual: %4

Fields

NameDescription
Actual
FileNumber
LineNumber
Param1
Param2

Event ID 1281 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: the data received by the API was too small.  Expected: %3, Actual: %4

Fields

NameDescription
Actual
FileNumber
LineNumber
Param1
Param2

Event ID 1282 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: POSSIBLE EFS ATTACK DETECTED: %3, %4, %5

Fields

NameDescription
FileNumber
LineNumber
DomainName
UserName
AttackId

Event ID 1283 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: attempting to validate EFS stream

Fields

NameDescription
FileNumber
LineNumber

Event ID 1284 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS stream validated

Fields

NameDescription
FileNumber
LineNumber

Event ID 1536 — PIN prompt dialog has closed

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

PIN prompt dialog has closed

Fields

NameDescription
FileNumber
LineNumber

Event ID 1537 — Prompt the user to select a smartcard-based EFS cert

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

Prompt the user to select a smartcard-based EFS cert

Fields

NameDescription
FileNumber
LineNumber

Event ID 1538 — Smartcard-based EFS cert successfully selected by the user

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

Smartcard-based EFS cert successfully selected by the user

Fields

NameDescription
FileNumber
LineNumber

Event ID 1539 — Prompt the user for PIN

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

Prompt the user for PIN

Fields

NameDescription
FileNumber
LineNumber

Event ID 1540 — PIN successfully acquired from the user

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

PIN successfully acquired from the user

Fields

NameDescription
FileNumber
LineNumber

Event ID 1541 — Perfect match found in cache.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

Perfect match found in cache.

Fields

NameDescription
FileNumber
LineNumber

Event ID 1542 — Masterkey history already loaded

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

Masterkey history already loaded

Fields

NameDescription
FileNumber
LineNumber

Event ID 1543 — Current key loaded from cache

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

Current key loaded from cache

Fields

NameDescription
FileNumber
LineNumber

Event ID 1544 — Current key loaded from registry

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

Current key loaded from registry

Fields

NameDescription
FileNumber
LineNumber

Event ID 1545 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Masterkey history: failed size consistency check.  %3, %4, %5

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2
Param3

Event ID 4096 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Encrypted keys not equal

Fields

NameDescription
FileNumber
LineNumber

Event ID 4097 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: doing a REKEY, but the DDF entry already exists

Fields

NameDescription
FileNumber
LineNumber

Event ID 4098 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: replace operation added a DDF (unexpected)

Fields

NameDescription
FileNumber
LineNumber

Event ID 4099 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: user is modifying a DDF entry not matching the PoP entry.  Require WRITE_ATTRIBUTES

Fields

NameDescription
FileNumber
LineNumber

Event ID 4100 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: user is modifying a DDF matching the PoP entry, or the DRF.  Don't require WRITE_ATTRIBUTES

Fields

NameDescription
FileNumber
LineNumber

Event ID 4101 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: UNEXPECTED condition: no ENCRYPTED_KEY for SC failure

Fields

NameDescription
FileNumber
LineNumber

Event ID 4102 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Plug-n-Play service not ready. EFS server will not try to detect interrupted encryption/decryption operation(s).

Fields

NameDescription
FileNumber
LineNumber

Event ID 4353 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Cannot open log file. Encryption/decryption operation(s) cannot be recovered.

Fields

NameDescription
FileNumber
LineNumber

Event ID 4354 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Cannot read log file. Encryption/decryption operation(s) cannot be recovered.

Fields

NameDescription
FileNumber
LineNumber

Event ID 4355 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: A corrupted or different format log file has been found. No action was taken.

Fields

NameDescription
FileNumber
LineNumber

Event ID 4356 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: The log file cannot be opened as non-cached IO. No action was taken.

Fields

NameDescription
FileNumber
LineNumber

Event ID 4357 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Interrupted encryption/decryption operation(s) found on a volume. Recovery procedure started.

Fields

NameDescription
FileNumber
LineNumber

Event ID 4358 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS recovery service cannot open the file %3. The interrupted encryption/decryption operation cannot be recovered.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4359 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS service recovered %3 successfully.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4360 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS service could not open all the streams on file %3  The file was not recovered.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4361 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: %3 could not be recovered Completely.  EFS driver may be missing.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4368 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: IO Error occurred during stream recovery.  %3 was not recovered.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4369 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS recovery service cannot open the backup file %3 by name. The interrupted encryption/decryption operation (on file %4) may be recovered.  The backup file will not be deleted. User should delete the backup file if the recovery operation is done successfully.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4370 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: %3 was opened by File ID successfully the first time but not the second time. No recovery operation was tried on file %4. This is an internal error.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4371 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS recovery service cannot get the backup file name. The interrupted encryption/decryption operation (on file %3) may be recovered.  The temporary backup file %4 is not deleted.  User should delete the backup file if the recovery operation is done successfully.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4372 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: %3 could not be opened. %4 was not recovered.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4373 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Stream Information could not be got from %3. %4 was not recovered.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4374 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS service could not open all the streams on file %3.  %4 was not recovered.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4375 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: EFS Service received logon notification.

Fields

NameDescription
FileNumber
LineNumber

Event ID 4376 — EFS Service failed to start.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS Service failed to start. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4377 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: User cache entry purged. Reference count: %3.

Fields

NameDescription
FileNumber
LineNumber
Param

Event ID 4378 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: All user cache entries purged. Reference count: %3.

Fields

NameDescription
FileNumber
LineNumber
Param

Event ID 4379 — EFS service was unable to populate SID information.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to populate SID information. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4380 — EFS service was unable to determine the computer name.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to determine the computer name. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4381 — EFS service was unable to initialize cache lock.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to initialize cache lock. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4382 — EFS service was unable to initialize the BCrypt Algorithm Provider.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to initialize the BCrypt Algorithm Provider. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4383 — EFS service was unable to query Software Licensing for the cache size.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to query Software Licensing for the cache size. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4384 — EFS service was unable to open handle to the MS_DEF_PROV provider.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to open handle to the MS_DEF_PROV provider. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4385 — EFS service was unable to setup notifications from LSA.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to setup notifications from LSA. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4386 — EFS service was unable to initialize the recovery policy resource.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to initialize the recovery policy resource. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4387 — EFS service was unable process the recovery policy.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable process the recovery policy. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4388 — EFS service was unable to notify NTFS of its state.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to notify NTFS of its state. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4389 — EFS service was unable to setup group policy change notifications.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to setup group policy change notifications. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4390 — EFS service was unable to process active user sessions.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

EFS service was unable to process active user sessions. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4391 — Encrypting File System server ready to accept calls.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

Encrypting File System server ready to accept calls.

Fields

NameDescription
FileNumber
LineNumber

Event ID 4392 — %1.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

%1.%2: EFS service failed to subscribe for updates to an MDM policy. Index: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4393 — %1.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

%1.%2: Failed to initialize one or more synchronization objects. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4400 — %1.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

%1.%2: EFS service failed to process MDM policy updates. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4401 — %1.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

%1.%2: EFS service failed to provision a user for Windows Information Protection. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4402 — %1.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

%1.%2: EFS service failed to provision a user for DPL. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4403 — %1.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

%1.%2: EFS service failed to initialize file encryption queues. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4404 — %1.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

%1.%2: Recovery policy data is in an invalid format. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4405 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Start: %3.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4406 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Complete: %3. Code: %4.

Fields

NameDescription
Code
FileNumber
LineNumber
Param1
Param2

Event ID 4407 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Error Code: %3.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4408 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Status Code: %3.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4409 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Enter: %3.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4410 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Leave: %3.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4411 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Leave: %3. Code: %4.

Fields

NameDescription
Code
FileNumber
LineNumber
Param1
Param2

Event ID 4412 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Error: %3. Code: %4.

Fields

NameDescription
Code
FileNumber
LineNumber
Param1
Param2

Event ID 4413 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Warning: %3. Code: %4.

Fields

NameDescription
Code
FileNumber
LineNumber
Param1
Param2

Event ID 4414 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: %3. Code: %4.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4415 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: %3. Value: %4.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4416 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Complete: %3. Code: %4.

Fields

NameDescription
Code
FileNumber
LineNumber
Param1
Param2

Event ID 4417 — %1.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

%1.%2: Leave: %3. Code: %4.

Fields

NameDescription
Code
FileNumber
LineNumber
Param1
Param2

Event ID 4418 — %1.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

%1.%2: EFS service failed to provision RMS for Windows Information Protection. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4419 — Thread %1: %2, Line %3, HRESULT %4, Message: '%5'.

Provider
Microsoft-Windows-EFS
Channel
Debug

Message

Thread %1: %2, Line %3, HRESULT %4, Message: '%5'

Fields

NameDescription
ThreadId
File
LineNumber
HRESULT
Message

Event ID 4420 — A client attempted to call an EFS service API without privacy level authentication.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

A client attempted to call an EFS service API without privacy level authentication. Error code: %3. See https://go.microsoft.com/fwlink/?linkid=2181030.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4421 — A client that called an EFS service API without privacy level authentication was allowed.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

A client that called an EFS service API without privacy level authentication was allowed. See https://go.microsoft.com/fwlink/?linkid=2181030.

Event ID 4422 — Failed to unprotect device user credential key using Windows Hello for user.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Failed to unprotect device user credential key using Windows Hello for user: %3. Error code: %4

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4423 — Personal Data Encryption and Windows Hello status updated: 1) Windows Hello availability: %3; 2) Windows Hello logon capability: %4; 3) Windows Hel...

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption and Windows Hello status updated: 1) Windows Hello availability: %3; 2) Windows Hello logon capability: %4; 3) Windows Hello hardware capability: %5; 4) Remote Desktop remote connections disabled: %6; 5) Windows automatic restart sign-on disabled: %7.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2
Param3
Param4
Param5

Event ID 4424 — Personal Data Encryption enabled for user %3.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption enabled for user %3.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4425 — Personal Data Encryption disabled for user %3.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption disabled for user %3. 1) Policy value: %4; and 2) Is opted out: %5.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2
Param3

Event ID 4432 — User %3 attempted to access user %4's data protected with Personal Data Encryption and was denied.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

User %3 attempted to access user %4's data protected with Personal Data Encryption and was denied.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4433 — Personal Data Encryption conversion started.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption conversion started.
Mode: "%3",
paths in policy: "%4",
paths protected: "%5",
paths attempted: "%6",
status: %7.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2
Param3
Param4
Param5

Event ID 4434 — Personal Data Encryption conversion completed.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption conversion completed.
Mode: "%3",
paths in policy: "%4",
paths protected: "%5",
paths attempted: "%6",
status: %7,
number of items converted: %8 (total bytes converted: %9),
number of system items : %10,
number of read-only files : %11,
number of items looked at : %12.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2
Param3
Param4
Param5
Param6
Param7
Param8
Param9
Param10

Event ID 4435 — Personal Data Encryption conversion did not complete.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption conversion did not complete.
Mode: "%3",
paths in policy: "%4",
paths protected: "%5",
paths attempted: "%6",
status: %7,
number of items converted: %8 (total bytes converted: %9),
number of system items: %10,
number of read-only files : %11,
number of items looked at : %12,
number of unknown failures: %13,
number of items not protectable: %14.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2
Param3
Param4
Param5
Param6
Param7
Param8
Param9
Param10
Param11
Param12

Event ID 4436 — Personal Data Encryption conversion failed to convert one or more files or folders.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption conversion failed to convert one or more files or folders. First encountered failure on file or folder "%3" was %4.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4437 — Personal Data Encryption policy for Desktop folder is set to %4 for user %3.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption policy for Desktop folder is set to %4 for user %3.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4438 — Personal Data Encryption policy for Documents folder is set to %4 for user %3.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption policy for Documents folder is set to %4 for user %3.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4439 — Personal Data Encryption policy for Pictures folder is set to %4 for user %3.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption policy for Pictures folder is set to %4 for user %3.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4440 — Personal Data Encryption policy for Desktop folder is deleted for user %3.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption policy for Desktop folder is deleted for user %3.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4441 — Personal Data Encryption policy for Documents folder is deleted for user %3.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption policy for Documents folder is deleted for user %3.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4448 — Personal Data Encryption policy for Pictures folder is deleted for user %3.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption policy for Pictures folder is deleted for user %3.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4449 — Personal Data Encryption policy for Desktop folder is mapped to path ".

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption policy for Desktop folder is mapped to path "%3" for user %4.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4450 — Personal Data Encryption policy for Documents folder is mapped to path ".

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption policy for Documents folder is mapped to path "%3" for user %4.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4451 — Personal Data Encryption policy for Pictures folder is mapped to path ".

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption policy for Pictures folder is mapped to path "%3" for user %4.

Fields

NameDescription
FileNumber
LineNumber
Param1
Param2

Event ID 4452 — Personal Data Encryption: paths to protect folders is empty for user %3.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption: paths to protect folders is empty for user %3.

Fields

NameDescription
FileNumber
LineNumber
Param1

Event ID 4453 — Windows Information Protection has been disabled.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Windows Information Protection has been disabled.

Fields

NameDescription
FileNumber
LineNumber

Event ID 4454 — Windows Information Protection could not be disabled.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Windows Information Protection could not be disabled. Error code: %3.

Fields

NameDescription
FileNumber
LineNumber
ErrorCode

Event ID 4455 — Personal Data Encryption conversion did not complete the last time it was run.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption conversion did not complete the last time it was run. Last run mode: %3.

Fields

NameDescription
FileNumber
LineNumber
Param

Event ID 4456 — Personal Data Encryption is not available for the current device.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption is not available for the current device. Only Azure AD joined devices are supported.

Fields

NameDescription
FileNumber
LineNumber

Event ID 4457 — Personal Data Encryption is not available for the current device.

Provider
Microsoft-Windows-EFS
Channel
Operational

Message

Personal Data Encryption is not available for the current device. Supported device types are Azure AD joined and Hybrid Azure AD joined devices.

Fields

NameDescription
FileNumber
LineNumber

Event ID 7000 — Machine role cannot be determined.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

Machine role cannot be determined. %1

Fields

NameDescription
Reason

Event ID 7002 — Default group policy object cannot be created.

Provider
Microsoft-Windows-EFS
Channel
Application

Message

Default group policy object cannot be created. %1

Fields

NameDescription
Reason