Microsoft-Windows-EFS
172 events across 3 channels
Event ID 1 — An API call failed at FileNumber.
Event ID 2 — An API call failed at Data.
Event ID 3 — An API call failed at Data.
Event ID 4 — FileNumber.
Event ID 256 — EFS key promoted from current key.
Description
EFS key promoted from current key. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.
Message #
Fields #
| Name | Description |
|---|---|
CertValidated UInt32 | — |
cbHash UInt32 | — |
pbHash AnsiString | — |
ContainerName UnicodeString | — |
ProviderName UnicodeString | — |
DisplayInformation UnicodeString | — |
dwCapabilities AnsiString | — |
bIsCurrentKey AnsiString | — |
eKeyType AnsiString | — |
Event ID 257 — EFS key demoted from current key.
Description
EFS key demoted from current key. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.
Message #
Fields #
| Name | Description |
|---|---|
CertValidated UInt32 | — |
cbHash UInt32 | — |
pbHash AnsiString | — |
ContainerName UnicodeString | — |
ProviderName UnicodeString | — |
DisplayInformation UnicodeString | — |
dwCapabilities AnsiString | — |
bIsCurrentKey AnsiString | — |
eKeyType AnsiString | — |
Event ID 258 — EFS key flushed from cache.
Description
EFS key flushed from cache. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.
Message #
Fields #
| Name | Description |
|---|---|
CertValidated UInt32 | — |
cbHash UInt32 | — |
pbHash AnsiString | — |
ContainerName UnicodeString | — |
ProviderName UnicodeString | — |
DisplayInformation UnicodeString | — |
dwCapabilities AnsiString | — |
bIsCurrentKey AnsiString | — |
eKeyType AnsiString | — |
Event ID 259 — FileNumber.
Event ID 260 — FileNumber.
Event ID 261 — FileNumber.
Event ID 262 — FileNumber.
Event ID 263 — FileNumber.
Event ID 264 — FileNumber.
Event ID 265 — FileNumber.
Event ID 272 — FileNumber.
Event ID 273 — FileNumber.
Event ID 274 — FileNumber.
Event ID 275 — FileNumber.
Event ID 276 — FileNumber.
Event ID 277 — FileNumber.
Event ID 278 — FileNumber.
Event ID 279 — FileNumber.
Event ID 280 — FileNumber.
Event ID 281 — FileNumber.
Event ID 288 — FileNumber.
Event ID 289 — FileNumber.
Event ID 290 — FileNumber.
Event ID 512 — FileNumber.
Event ID 513 — FileNumber.
Event ID 514 — FileNumber.
Event ID 515 — FileNumber.
Event ID 516 — FileNumber.
Event ID 517 — EFS key added to user cache.
Description
EFS key added to user cache. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.
Message #
Fields #
| Name | Description |
|---|---|
CertValidated UInt32 | — |
cbHash UInt32 | — |
pbHash AnsiString | — |
ContainerName UnicodeString | — |
ProviderName UnicodeString | — |
DisplayInformation UnicodeString | — |
dwCapabilities AnsiString | — |
bIsCurrentKey AnsiString | — |
eKeyType AnsiString | — |
Event ID 518 — FileNumber.
Event ID 519 — FileNumber.
Event ID 520 — FileNumber.
Event ID 521 — FileNumber.
Event ID 768 — FileNumber.
Event ID 769 — FileNumber.
Event ID 770 — FileNumber.
Event ID 771 — FileNumber.
Event ID 772 — FileNumber.
Event ID 773 — FileNumber.
Event ID 774 — FileNumber.
Event ID 775 — FileNumber.
Event ID 776 — FileNumber.
Event ID 777 — FileNumber.
Event ID 784 — FileNumber.
Event ID 785 — FileNumber.
Event ID 786 — FileNumber.
Event ID 787 — FileNumber.
Event ID 788 — FileNumber.
Event ID 789 — FileNumber.
Event ID 790 — FileNumber.
Event ID 791 — FileNumber.
Event ID 792 — FileNumber.
Event ID 793 — FileNumber.
Event ID 800 — FileNumber.
Event ID 801 — FileNumber.
Event ID 802 — FileNumber.
Event ID 803 — FileNumber.
Event ID 804 — FileNumber.
Event ID 805 — FileNumber.
Event ID 1024 — FileNumber.
Event ID 1040 — FileNumber.
Event ID 1041 — FileNumber.
Event ID 1042 — FileNumber.
Event ID 1280 — Actual.
Event ID 1281 — Actual.
Event ID 1282 — FileNumber.
Event ID 1283 — FileNumber.
Event ID 1284 — FileNumber.
Event ID 1536 — PIN prompt dialog has closed
Event ID 1537 — Prompt the user to select a smartcard-based EFS cert
Event ID 1538 — Smartcard-based EFS cert successfully selected by the user
Event ID 1539 — Prompt the user for PIN
Event ID 1540 — PIN successfully acquired from the user
Event ID 1541 — Perfect match found in cache.
Event ID 1542 — Masterkey history already loaded
Event ID 1543 — Current key loaded from cache
Event ID 1544 — Current key loaded from registry
Event ID 1545 — FileNumber.
Event ID 4096 — FileNumber.
Event ID 4097 — FileNumber.
Event ID 4098 — FileNumber.
Event ID 4099 — FileNumber.
Event ID 4100 — FileNumber.
Event ID 4101 — FileNumber.
Event ID 4102 — FileNumber.
Event ID 4353 — FileNumber.
Event ID 4354 — FileNumber.
Event ID 4355 — FileNumber.
Event ID 4356 — FileNumber.
Event ID 4357 — FileNumber.
Event ID 4358 — FileNumber.
Event ID 4359 — FileNumber.
Event ID 4360 — FileNumber.
Event ID 4361 — FileNumber.
Event ID 4368 — FileNumber.
Event ID 4369 — FileNumber.
Event ID 4370 — FileNumber.
Description
FileNumber.LineNumber: Param1 was opened by File ID successfully the first time but not the second time. No recovery operation was tried on file Param2. This is an internal error.
Message #
Fields #
| Name | Description |
|---|---|
FileNumber UInt32 | — |
LineNumber UInt32 | — |
Param1 UnicodeString | — |
Param2 UnicodeString | — |
Event ID 4371 — FileNumber.
Event ID 4372 — FileNumber.
Event ID 4373 — FileNumber.
Event ID 4374 — FileNumber.
Event ID 4375 — FileNumber.
Event ID 4376 — EFS Service failed to start.
Event ID 4377 — FileNumber.
Event ID 4378 — FileNumber.
Event ID 4379 — EFS service was unable to populate SID information.
Event ID 4380 — EFS service was unable to determine the computer name.
Event ID 4381 — EFS service was unable to initialize cache lock.
Event ID 4382 — EFS service was unable to initialize the BCrypt Algorithm Provider.
Event ID 4383 — EFS service was unable to query Software Licensing for the cache size.
Event ID 4384 — EFS service was unable to open handle to the MS_DEF_PROV provider.
Event ID 4385 — EFS service was unable to setup notifications from LSA.
Event ID 4386 — EFS service was unable to initialize the recovery policy resource.
Event ID 4387 — EFS service was unable process the recovery policy.
Event ID 4388 — EFS service was unable to notify NTFS of its state.
Event ID 4389 — EFS service was unable to setup group policy change notifications.
Event ID 4390 — EFS service was unable to process active user sessions.
Event ID 4391 — Encrypting File System server ready to accept calls.
Event ID 4392 — FileNumber.
Event ID 4393 — FileNumber.
Event ID 4400 — FileNumber.
Event ID 4401 — FileNumber.
Event ID 4402 — FileNumber.
Event ID 4403 — FileNumber.
Event ID 4404 — FileNumber.
Event ID 4405 — FileNumber.
Event ID 4406 — Code.
Event ID 4407 — FileNumber.
Event ID 4408 — FileNumber.
Event ID 4409 — FileNumber.
Event ID 4410 — FileNumber.
Event ID 4411 — Code.
Event ID 4412 — Code.
Event ID 4413 — Code.
Event ID 4414 — FileNumber.
Event ID 4415 — FileNumber.
Event ID 4416 — Code.
Event ID 4417 — Code.
Event ID 4418 — FileNumber.
Event ID 4419 — Thread ThreadId: File, Line LineNumber, HRESULT HRESULT, Message: 'Message'.
Event ID 4420 — A client attempted to call an EFS service API without privacy level authentication.
Event ID 4421 — A client that called an EFS service API without privacy level authentication was allowed.
Description
A client that called an EFS service API without privacy level authentication was allowed. See https://go.microsoft.com/fwlink/?linkid=2181030.
Message #
Event ID 4422 — Failed to unprotect device user credential key using Windows Hello for user: Param1.
Event ID 4423 — Personal Data Encryption and Windows Hello status updated: 1) Windows Hello availability: Param1; 2) Windows Hello logon capability: Param2; 3) Windows Hel...
Event ID 4424 — Personal Data Encryption enabled for user Param1.
Event ID 4425 — Personal Data Encryption disabled for user Param1.
Event ID 4432 — User Param1 attempted to access user Param2's data protected with Personal Data Encryption and was denied.
Event ID 4433 — Personal Data Encryption conversion started.
Event ID 4434 — Personal Data Encryption conversion completed.
Event ID 4435 — Personal Data Encryption conversion did not complete.
Description
Personal Data Encryption conversion did not complete.
Message #
Fields #
| Name | Description |
|---|---|
FileNumber UInt32 | — |
LineNumber UInt32 | — |
Param1 UnicodeString | — |
Param2 UnicodeString | — |
Param3 UnicodeString | — |
Param4 UnicodeString | — |
Param5 UInt32 | — |
Param6 UInt64 | — |
Param7 UInt64 | — |
Param8 UInt64 | — |
Param9 UInt64 | — |
Param10 UInt64 | — |
Param11 UInt64 | — |
Param12 UInt64 | — |