Microsoft-Windows-GroupPolicy

177 events across 2 channels

Event IDTitleChannel
1002The processing of Group Policy failed because of a system allocation failure.System
1006The processing of Group Policy failed.System
1007The processing of Group Policy failed.System
1030The processing of Group Policy failed.System
1052The processing of Group Policy failed.System
1053The processing of Group Policy failed.System
1054The processing of Group Policy failed.System
1055The processing of Group Policy failed.System
1058The processing of Group Policy failed.System
1065The processing of Group Policy failed.System
1068The processing of Group Policy was interrupted.System
1079The processing of Group Policy failed.System
1080The processing of Group Policy failed.System
1085Windows failed to apply the %8 settings.System
1088The processing of Group Policy failed.System
1089Windows failed to record Resultant Set of Policy (RSoP) information, which …System
1090Windows failed to record Resultant Set of Policy (RSoP) information, which …System
1091Windows could not record the Resultant Set of Policy (RSoP) information for the …System
1095Windows encountered an error while recording Resultant Set of Policy (RSoP) …System
1096The processing of Group Policy failed.System
1097The processing of Group Policy failed.System
1101The processing of Group Policy failed.System
1104Windows was unable to read the Windows Management Instrumentation (WMI) filter …System
1109The user account is in a different forest than the computer account.System
1110The processing of Group Policy failed.System
1112The Group Policy Client Side Extension %8 was unable to apply one or more …System
1125The processing of Group Policy failed because of an internal system error.System
1126Windows was unable to determine whether new Group Policy settings defined by a …System
1127The processing of Group Policy failed due to an internal error.System
1128The Group Policy Client Side Extension %3 may have caused the Group Policy …System
1129The processing of Group Policy failed because of lack of network connectivity to …System
1130%5 failed.System
1500The Group Policy settings for the computer were processed successfully.System
1501The Group Policy settings for the user were processed successfully.System
1502The Group Policy settings for the computer were processed successfully.System
1503The Group Policy settings for the user were processed successfully.System
4000Starting computer boot policy processing for %2.Operational
4001Starting user logon Policy processing for %2.Operational
4002Starting policy processing due to network state change for computer %2.Operational
4003Starting policy processing due to network state change for user %2.Operational
4004Starting manual processing of policy for computer %2.Operational
4005Starting manual processing of policy for user %2.Operational
4006Starting periodic policy processing for computer %2.Operational
4007Starting periodic policy processing for user %2.Operational
4016Starting %2 Extension Processing.Operational
4017Operational
4018Starting %2 for %1.Operational
4019Running script name %1.Operational
4115Group Policy Service started.Operational
4116Started the Group Policy service initialization phase.Operational
4117Group Policy Session started.Operational
4126Group Policy receiving applicable GPOs from the domain controller.Operational
4216Starting to save policies to the local datastore.Operational
4217Starting to load policies from the local datastore.Operational
4218Starting the first WMI query for the policy.Operational
4257Starting to download policies.Operational
4326Group Policy is trying to discover the Domain Controller information.Operational
5016Completed %3 Extension Processing in %1 milliseconds.Operational
5017%3 %4 The call completed in %1 milliseconds.Operational
5018Completed %4 for %3 in %1 seconds.Operational
5019Completed %3 in %1 seconds.Operational
5115Group Policy Service stopped.Operational
5116Successfully completed the Group Policy Service initialization phase.Operational
5117Group policy session completed successfully.Operational
5126Group Policy successfully got applicable GPOs from the domain controller.Operational
5216Successfully saved policies to the local datastore.Operational
5217Successfully loaded policies from the local datastore.Operational
5218Successfully completed the first WMI query.Operational
5257Successfully completed downloading policies.Operational
5308Domain Controller details: Domain Controller Name : %1 Domain Controller IP …Operational
5309Computer details: Computer role : %1 Network name : %2.Operational
5310Account details: Account Name : %1 Account Domain Name : %2 DC Name : %3 DC …Operational
5311The loopback policy processing mode is %1.Operational
5312List of applicable Group Policy objects.Operational
5313The following Group Policy objects were not applicable because they were …Operational
5314A %6 link was detected.Operational
5315Next policy processing for %1 will be attempted in %2 %3.Operational
5320Operational
5321%1 Parameter: %2.Operational
5322Group Policy waited for %3 milliseconds for the network subsystem at computer …Operational
5323Invalid Error Message.Operational
5324Group Policy received the notification %1 from Winlogon for session %2.Operational
5325Group Policy received %1 notification from Service Control Manager.Operational
5326Group Policy successfully discovered the Domain Controller in %1 milliseconds.Operational
5327Estimated network bandwidth on one of the connections: %1 kbps.Operational
5331Service configuration update to standalone was attempted due to the presence of …Operational
5332Group Policy waited for %3 milliseconds for the Direct Access CorpNet …Operational
5340The Group Policy processing mode is %1.Operational
5351Group policy session returned to winlogon.Operational
6000Invalid Error Message.Operational
6001Invalid Error Message.Operational
6002Invalid Error Message.Operational
6003Invalid Error Message.Operational
6004Invalid Error Message.Operational
6005Invalid Error Message.Operational
6006Invalid Error Message.Operational
6007Invalid Error Message.Operational
6016Completed %3 Extension Processing in %1 milliseconds.Operational
6017Invalid Error Message.Operational
6018Invalid Error Message.Operational
6019Invalid Error Message.Operational
6033Skipped %1 Extension based on Group Policy client-side processing rules.Operational
6034Group Policy changed from synchronous foreground to asynchronous foreground …Operational
6035%1 Extension deferred processing until next synchronous foreground.Operational
6226Invalid Error Message.Operational
6308Invalid Error Message.Operational
6309Invalid Error Message.Operational
6310Invalid Error Message.Operational
6311Invalid Error Message.Operational
6312Invalid Error Message.Operational
6313Invalid Error Message.Operational
6314Group Policy bandwidth estimation failed.Operational
6315Invalid Error Message.Operational
6320Warning: %1 Warning code %2.Operational
6321Warning: %1 Parameter: %3 : Warning code %2.Operational
6322Invalid Error Message.Operational
6323Group Policy dependency did not start.Operational
6324Invalid Error Message.Operational
6325Invalid Error Message.Operational
6326Invalid Error Message.Operational
6327Invalid Error Message.Operational
6330An unfinished invocation of the Group Policy Client Side Extension %1 from a …Operational
6331Invalid Error Message.Operational
6332Invalid Error Message.Operational
6337Group Policy network connection is via Direct Access.Operational
6338Group Policy Winlogon status reporting has completed.Operational
6339Group Policy Winlogon Start Shell handling completed.Operational
6341A Group Policy setting was used to override the fast/slow link detection.Operational
6342The network connection is using a WWAN device for connectivity.Operational
6344Group Policy detected a slow link during sync mode processing.Operational
6345The connection to DC timed out during the Group Policy sync mode process.Operational
6346Group Policy switched the sync mode process to async mode.Operational
7000Computer boot policy processing failed for %3 in %1 seconds.Operational
7001User logon policy processing failed for %3 in %1 seconds.Operational
7002Policy processing due to network state change failed for computer %3 in %1 …Operational
7003Policy processing due to network state change failed for user %3 in %1 seconds.Operational
7004Manual processing of policy failed for computer %3 in %1 seconds.Operational
7005Manual processing of policy failed for user %3 in %1 seconds.Operational
7006Periodic policy processing failed for computer %3 in %1 seconds.Operational
7007Periodic policy processing failed for user %3 in %1 seconds.Operational
7016Completed %3 Extension Processing in %1 milliseconds.Operational
7017%3 %4 The call failed after %1 milliseconds.Operational
7018Script for %3 failed in %1 seconds.Operational
7019Invalid Error Message.Operational
7117Group policy session completed with error.Operational
7126Group Policy could not get applicable GPOs from the domain controller.Operational
7216Saved policies to the local datastore with error.Operational
7217Loaded policies from the local datastore with error.Operational
7257Downloaded policies with error.Operational
7308Invalid Error Message.Operational
7309Invalid Error Message.Operational
7310Invalid Error Message.Operational
7311Invalid Error Message.Operational
7312Invalid Error Message.Operational
7313Invalid Error Message.Operational
7314Invalid Error Message.Operational
7315Invalid Error Message.Operational
7320Error: %1 Error code %2.Operational
7321Error: %1 Parameter: %3 : Error code %2.Operational
7322Invalid Error Message.Operational
7323Invalid Error Message.Operational
7324Invalid Error Message.Operational
7325Invalid Error Message.Operational
7326Group Policy failed to discover the Domain Controller details in %1 …Operational
7327Invalid Error Message.Operational
7331Service configuration update to standalone was attempted due to the presence of …Operational
7332Invalid Error Message.Operational
8000Completed computer boot policy processing for %3 in %1 seconds.Operational
8001Completed user logon policy processing for %3 in %1 seconds.Operational
8002Completed policy processing due to network state change for computer %3 in %1 …Operational
8003Completed policy processing due to network state change for user %3 in %1 …Operational
8004Completed manual processing of policy for computer %3 in %1 seconds.Operational
8005Completed manual processing of policy for user %3 in %1 seconds.Operational
8006Completed periodic policy processing for computer %3 in %1 seconds.Operational
8007Completed periodic policy processing for user %3 in %1 seconds.Operational
8016%1 Extension (%2) requests a sync mode process.Operational
9001This machine is configured to retrieve Group Policy files from a file share in …Operational

Event ID 1002 — The processing of Group Policy failed because of a system allocation failure.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed because of a system allocation failure. Please ensure the computer is not running low on resources (memory, available disk space). Group Policy processing will be attempted at the next refresh cycle.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1006 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not authenticate to the Active Directory service on a domain controller. (LDAP Bind function call failed). Look in the details tab for error code and description.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1007 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not determine the site associated for this computer, which is required for Group Policy processing.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1030 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows attempted to retrieve new Group Policy settings for this user or computer. Look in the details tab for error code and description. Windows will automatically retry this operation at the next refresh cycle. Computers joined to the domain must have proper name resolution and network connectivity to a domain controller for discovery of new Group Policy objects and settings. An event will be logged when Group Policy is successful.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1052 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not determine the role of this computer. Role information (Workgroup, Member Server, or Domain Controller) is required to process Group Policy.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription

Event ID 1053 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not resolve the user name. This could be caused by one of more of the following: 
a) Name Resolution failure on the current domain controller. 
b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription

Event ID 1054 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription

Event ID 1055 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 
a) Name Resolution failure on the current domain controller. 
b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription

Event ID 1058 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows attempted to read the file %9 from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following: 
a) Name Resolution/Network Connectivity to the current domain controller. 
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller). 
c) The Distributed File System (DFS) client has been disabled.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName
GPOCNName
FilePath

Event ID 1065 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not evaluate the Windows Management Instrumentation (WMI) filter for the Group Policy object %8. This could be caused by RSOP being disabled  or Windows Management Instrumentation (WMI) service being disabled, stopped, or other WMI errors. Make sure the WMI service is started and the startup type is set to automatic. New Group Policy objects or settings will not process until this event has been resolved.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName
GPOCNName

Event ID 1068 — The processing of Group Policy was interrupted.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy was interrupted. Windows prematurely ended the discovery and enforcement of Group Policy settings because the computer was requested to shutdown or the user logged off. Group Policy processing will be attempted next refresh cycle, on the next computer reboot, or the next user logon.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
DCName

Event ID 1079 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not obtain the list of Group Policy objects applicable for this computer or user. View the event details for more information.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1080 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not search the Active Directory organization unit hierarchy. View the event details for more information.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1085 — Windows failed to apply the %8 settings.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

Windows failed to apply the %8 settings. %8 settings might have its own log file. Please click on the "More information" link.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName
ExtensionName
ExtensionId

References

Event ID 1088 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows attempted to query the list of Group Policy objects and exceeded the maximum limit (999).

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1089 — Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or u...

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or user. This could be caused by RSOP being disabled or Windows Management Instrumentation (WMI) service being disabled, stopped, or other WMI errors. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1090 — Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or u...

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or user. This could be caused by Windows Management Instrumentation (WMI) service being disabled, stopped, or other WMI errors. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
DCName

Event ID 1091 — Windows could not record the Resultant Set of Policy (RSoP) information for the Group Policy extension <.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

Windows could not record  the Resultant Set of Policy (RSoP) information for the Group Policy extension <%8>. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName
ExtensionName
ExtensionId

Event ID 1095 — Windows encountered an error while recording Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied ...

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

Windows encountered an error while recording Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or user. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1096 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not apply the registry-based policy settings for the Group Policy object %8. Group Policy settings will not be resolved until this event is resolved. View the event details for more information on the file name and path that caused the failure.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName
GPOCNName
FilePath

Event ID 1097 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not determine the computer account to enforce Group Policy settings. This may be transient. Group Policy settings, including computer configuration, will not be enforced for this computer.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1101 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not locate the directory object %8. Group Policy settings will not be enforced until this event is resolved. View the event details for more information on this error.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName
DSObjectName

Event ID 1104 — Windows was unable to read the Windows Management Instrumentation (WMI) filter information associated with the Group Policy object %8.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

Windows was unable to read the Windows Management Instrumentation (WMI) filter information associated with the Group Policy object %8.This may be caused by a deleted WMI Filter defined in the domain that is still in use by Group Policy objects. Group Policy settings for this Group Policy object will not be enforced. Other Group Policy objects may still apply. Windows will attempt to retrieve this information at the next policy cycle. This specific problem may be resolved by identifying all GPOs that reference the WMI filter and removing the references. Contact an administrator if this event recurs for several hours.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName
GPOCNName

Event ID 1109 — The user account is in a different forest than the computer account.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The user account is in a different forest than the computer account. The processing of Group Policy from another forest is not allowed. Group Policy will be processed using Loopback Replace mode. The scope of the user policy settings will be determined by the location of the computer object in Active Directory. The settings will be acquired from the User Configuration of these policies.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
DCName

Event ID 1110 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest. Ensure the user domain name matches the name of a trusted domain that resides in the same forest as the computer account.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription

Event ID 1112 — The Group Policy Client Side Extension %8 was unable to apply one or more settings because the changes must be processed before system startup or u...

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The Group Policy Client Side Extension %8 was unable to apply one or more settings because the changes must be processed before system startup or user logon. The system will wait for Group Policy processing to finish completely before the next startup or logon for this user, and this may result in slow startup and boot performance.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName
ExtensionName
ExtensionId

Event ID 1125 — The processing of Group Policy failed because of an internal system error.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed because of an internal system error. Please see the Group Policy operational log for the specific error message. An attempt will be made to process Group Policy again at the next refresh cycle.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription

References

Event ID 1126 — Windows was unable to determine whether new Group Policy settings defined by a network administrator should be enforced for this user or computer b...

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

Windows was unable to determine whether new Group Policy settings defined by a network administrator should be enforced for this user or computer because this computer's clock is not synchronized with the clock of one of the domain controllers for the domain. Because of this issue, this computer system may not be in compliance with the network administrator?s requirements, and users of this system may not be able to use some functionality on the network. Windows will periodically attempt to retry this operation, and it is possible that either this system or the domain controller will correct the time settings without intervention by an administrator, so the problem will be corrected. 

If this issue persists for more than an hour, checking the local system's clock settings to ensure they are accurate and are synchronized with the clocks on the network's domain controllers is one way to resolve this problem. A network administrator may be required to resolve the issue if correcting the local time settings does not address the problem.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1127 — The processing of Group Policy failed due to an internal error.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The processing of Group Policy failed due to an internal error. Please look into the Group Policy operational log for the specific error message. An attempt will be made to process Group Policy again at the next refresh cycle.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription
DCName

Event ID 1128 — The Group Policy Client Side Extension %3 may have caused the Group Policy Service to terminate unexpectedly.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

The Group Policy Client Side Extension %3 may have caused the Group Policy Service to terminate unexpectedly. To prevent further failures in the Group Policy Service, this extension has been temporarily disabled until after the next system restart. Group Policy settings managed by this extension may no longer be enforced until the system is restarted. The vendor of this extension should be contacted if this issue recurs.

Fields

NameDescription
SupportInfo1
SupportInfo2
ExtensionName
ExtensionId

Event ID 1129 — The processing of Group Policy failed because of lack of network connectivity to a domain controller.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
2
Samples
1

Message

The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
ErrorCode
ErrorDescription

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 1129
  version: 0
  level: 2
  task: 0
  opcode: 0
  keywords: 9223372036854775808
  time_created: '2022-04-07T16:57:06.407574+00:00'
  event_record_id: 1271
  correlation:
    ActivityID: B87F014A-16D6-49C2-8037-BBF193577383
  execution:
    process_id: 1352
    thread_id: 2676
  channel: System
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
  SupportInfo1: 1
  SupportInfo2: 2044
  ProcessingMode: 1
  ProcessingTimeInMilliseconds: 4078
  ErrorCode: 1222
  ErrorDescription: 'The network is not present or not started. '
message: ''

References

Event ID 1130 — %5 failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message

%5 failed. 
	GPO Name : %6
	GPO File System Path : %7
	Script Name: %8

Fields

NameDescription
GPO_Name
GPO_File_System_Path
Script_Name
SupportInfo1
SupportInfo2
ErrorCode
ErrorDescription
ScriptType
GPODisplayName
GPOFileSystemPath
GPOScriptCommandString

Event ID 1500 — The Group Policy settings for the computer were processed successfully.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
4
Samples
1

Message

The Group Policy settings for the computer were processed successfully. There were no changes detected since the last successful processing of Group Policy.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
DCName

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 1500
  version: 0
  level: 4
  task: 0
  opcode: 1
  keywords: 9223372036854775808
  time_created: '2023-11-05T22:44:13.952441+00:00'
  event_record_id: 1973
  correlation:
    ActivityID: 73911CA3-27B1-475D-92EC-CBFA1D10EB35
  execution:
    process_id: 1132
    thread_id: 2268
  channel: System
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  SupportInfo1: 1
  SupportInfo2: 4214
  ProcessingMode: 0
  ProcessingTimeInMilliseconds: 156
  DCName: ''
message: ''

References

Event ID 1501 — The Group Policy settings for the user were processed successfully.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
4
Samples
1

Message

The Group Policy settings for the user were processed successfully. There were no changes detected since the last successful processing of Group Policy.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
DCName

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 1501
  version: 0
  level: 4
  task: 0
  opcode: 1
  keywords: 9223372036854775808
  time_created: '2023-11-05T22:28:54.475787+00:00'
  event_record_id: 1832
  correlation:
    ActivityID: 5D6D5E8D-CE04-46CB-BF83-231A8B295C46
  execution:
    process_id: 1860
    thread_id: 4880
  channel: System
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
  SupportInfo1: 1
  SupportInfo2: 4214
  ProcessingMode: 1
  ProcessingTimeInMilliseconds: 734
  DCName: ''
message: ''

References

Event ID 1502 — The Group Policy settings for the computer were processed successfully.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
4
Samples
1

Message

The Group Policy settings for the computer were processed successfully. New settings from %6 Group Policy objects were detected and applied.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
DCName
NumberOfGroupPolicyObjects

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 1502
  version: 0
  level: 4
  task: 0
  opcode: 1
  keywords: 9223372036854775808
  time_created: '2023-11-05T23:49:58.052759+00:00'
  event_record_id: 2033
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: System
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  SupportInfo1: 1
  SupportInfo2: 4195
  ProcessingMode: 0
  ProcessingTimeInMilliseconds: 906
  DCName: ''
  NumberOfGroupPolicyObjects: 1
message: ''

References

Event ID 1503 — The Group Policy settings for the user were processed successfully.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
4
Samples
1

Message

The Group Policy settings for the user were processed successfully. New settings from %6 Group Policy objects were detected and applied.

Fields

NameDescription
SupportInfo1
SupportInfo2
ProcessingMode
ProcessingTimeInMilliseconds
DCName
NumberOfGroupPolicyObjects

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 1503
  version: 0
  level: 4
  task: 0
  opcode: 1
  keywords: 9223372036854775808
  time_created: '2022-04-07T17:34:38.149825+00:00'
  event_record_id: 1319
  correlation:
    ActivityID: DCA9073D-A053-4D86-A71A-A22443FB751F
  execution:
    process_id: 1352
    thread_id: 1684
  channel: System
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
  SupportInfo1: 1
  SupportInfo2: 4195
  ProcessingMode: 0
  ProcessingTimeInMilliseconds: 671
  DCName: \\WIN-FPV0DSIC9O6.sigma.fr
  NumberOfGroupPolicyObjects: 1
message: ''

References

Event ID 4000 — Starting computer boot policy processing for %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Starting computer boot policy processing for %2. 
Activity id: %1

Fields

NameDescription
PolicyActivityIdActivity id.
PrincipalSamName
IsMachine
IsDomainJoined
IsBackgroundProcessing
IsAsyncProcessing
IsServiceRestart
ReasonForSyncProcessing

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4000
  version: 1
  level: 4
  task: 0
  opcode: 1
  keywords: 4611686018427387904
  time_created: '2023-11-05T22:32:17.280621+00:00'
  event_record_id: 479
  correlation:
    ActivityID: 70C9A908-A206-406D-8A5D-D1CA7FEE9E13
  execution:
    process_id: 1132
    thread_id: 1348
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  PolicyActivityId: 70C9A908-A206-406D-8A5D-D1CA7FEE9E13
  PrincipalSamName: WORKGROUP\WINDEV2310EVAL$
  IsMachine: 1
  IsDomainJoined: false
  IsBackgroundProcessing: false
  IsAsyncProcessing: true
  IsServiceRestart: false
  ReasonForSyncProcessing: 0
message: ''

References

Event ID 4001 — Starting user logon Policy processing for %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Starting user logon Policy processing for %2. 
Activity id: %1

Fields

NameDescription
PolicyActivityIdActivity id.
PrincipalSamName
IsMachine
IsDomainJoined
IsBackgroundProcessing
IsAsyncProcessing
IsServiceRestart
ReasonForSyncProcessing

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4001
  version: 1
  level: 4
  task: 0
  opcode: 1
  keywords: 4611686018427387904
  time_created: '2023-11-05T22:32:20.905356+00:00'
  event_record_id: 495
  correlation:
    ActivityID: DE67DFB7-B871-42E1-B68C-4175341DA657
  execution:
    process_id: 1132
    thread_id: 3904
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  PolicyActivityId: DE67DFB7-B871-42E1-B68C-4175341DA657
  PrincipalSamName: WINDEV2310EVAL\User
  IsMachine: 0
  IsDomainJoined: false
  IsBackgroundProcessing: false
  IsAsyncProcessing: true
  IsServiceRestart: false
  ReasonForSyncProcessing: 0
message: ''

References

Event ID 4002 — Starting policy processing due to network state change for computer %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Starting policy processing due to network state change for computer %2. 
Activity id: %1

Fields

NameDescription
Activity_id
PolicyActivityId
PrincipalSamName
IsMachine
IsDomainJoined
IsBackgroundProcessing
IsAsyncProcessing
IsServiceRestart
ReasonForSyncProcessing

Event ID 4003 — Starting policy processing due to network state change for user %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Starting policy processing due to network state change for user %2. 
Activity id: %1

Fields

NameDescription
Activity_id
PolicyActivityId
PrincipalSamName
IsMachine
IsDomainJoined
IsBackgroundProcessing
IsAsyncProcessing
IsServiceRestart
ReasonForSyncProcessing

Event ID 4004 — Starting manual processing of policy for computer %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Starting manual processing of policy for computer %2. 
Activity id: %1

Fields

NameDescription
PolicyActivityIdActivity id.
PrincipalSamName
IsMachine
IsDomainJoined
IsBackgroundProcessing
IsAsyncProcessing
IsServiceRestart
ReasonForSyncProcessing

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4004
  version: 1
  level: 4
  task: 0
  opcode: 1
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:57.126023+00:00'
  event_record_id: 1152
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  PolicyActivityId: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  PrincipalSamName: WORKGROUP\WINDEV2310EVAL$
  IsMachine: 1
  IsDomainJoined: false
  IsBackgroundProcessing: true
  IsAsyncProcessing: false
  IsServiceRestart: false
  ReasonForSyncProcessing: 0
message: ''

References

Event ID 4005 — Starting manual processing of policy for user %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Starting manual processing of policy for user %2. 
Activity id: %1

Fields

NameDescription
PolicyActivityIdActivity id.
PrincipalSamName
IsMachine
IsDomainJoined
IsBackgroundProcessing
IsAsyncProcessing
IsServiceRestart
ReasonForSyncProcessing

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4005
  version: 1
  level: 4
  task: 0
  opcode: 1
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:34:37.483672+00:00'
  event_record_id: 835
  correlation:
    ActivityID: DCA9073D-A053-4D86-A71A-A22443FB751F
  execution:
    process_id: 1352
    thread_id: 1684
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  PolicyActivityId: DCA9073D-A053-4D86-A71A-A22443FB751F
  PrincipalSamName: SIGMA\Administrator
  IsMachine: 0
  IsDomainJoined: true
  IsBackgroundProcessing: true
  IsAsyncProcessing: false
  IsServiceRestart: false
  ReasonForSyncProcessing: 0
message: ''

References

Event ID 4006 — Starting periodic policy processing for computer %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Starting periodic policy processing for computer %2. 
Activity id: %1

Fields

NameDescription
PolicyActivityIdActivity id.
PrincipalSamName
IsMachine
IsDomainJoined
IsBackgroundProcessing
IsAsyncProcessing
IsServiceRestart
ReasonForSyncProcessing

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4006
  version: 1
  level: 4
  task: 0
  opcode: 1
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.484458+00:00'
  event_record_id: 866
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  PolicyActivityId: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  PrincipalSamName: SIGMA\WIN-FPV0DSIC9O6$
  IsMachine: 1
  IsDomainJoined: true
  IsBackgroundProcessing: true
  IsAsyncProcessing: false
  IsServiceRestart: false
  ReasonForSyncProcessing: 0
message: ''

References

Event ID 4007 — Starting periodic policy processing for user %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Starting periodic policy processing for user %2. 
Activity id: %1

Fields

NameDescription
Activity_id
PolicyActivityId
PrincipalSamName
IsMachine
IsDomainJoined
IsBackgroundProcessing
IsAsyncProcessing
IsServiceRestart
ReasonForSyncProcessing

Event ID 4016 — Starting %2 Extension Processing.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Starting %2 Extension Processing. 

List of applicable Group Policy objects: (%5)

%6

Fields

NameDescription
CSEExtensionId
CSEExtensionName
IsExtensionAsyncProcessing
IsGPOListChanged
GPOListStatusString
DescriptionString
ApplicableGPOList

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4016
  version: 0
  level: 4
  task: 0
  opcode: 1
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:57.906053+00:00'
  event_record_id: 1165
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  CSEExtensionId: F3CCC681-B74C-4060-9F26-CD84525DCA2A
  CSEExtensionName: Audit Policy Configuration
  IsExtensionAsyncProcessing: true
  IsGPOListChanged: true
  GPOListStatusString: '%%4102'
  DescriptionString: 'Local Group Policy

    '
  ApplicableGPOList: <GPO ID="Local Group Policy"><Name>Local Group Policy</Name></GPO>
message: ''

References

Event ID 4017 —

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

%1 
%2

Fields

NameDescription
OperationDescription
Parameter

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4017
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.551157+00:00'
  event_record_id: 886
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  OperationDescription: '%%4131'
  Parameter: \\sigma.fr\sysvol\sigma.fr\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\gpt.ini
message: ''

References

Event ID 4018 — Starting %2 for %1.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Starting %2 for %1.

Fields

NameDescription
PrincipalSamName
ScriptType
IsScriptHidden
IsScriptSync
IsScriptMinimized
SessionId

Event ID 4019 — Running script name %1.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Running script name %1.

Fields

NameDescription
ScriptName
ScriptFileSystemPath
ScriptArguments

Event ID 4115 — Group Policy Service started.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy Service started.

Fields

NameDescription
IsServiceRestart
IsMachineBoot

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4115
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T06:25:40.340217+00:00'
  event_record_id: 415
  correlation: {}
  execution:
    process_id: 2412
    thread_id: 2516
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  IsServiceRestart: false
  IsMachineBoot: true
message: ''

References

Event ID 4116 — Started the Group Policy service initialization phase.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Started the Group Policy service initialization phase.

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4116
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T06:25:40.239882+00:00'
  event_record_id: 414
  correlation: {}
  execution:
    process_id: 2412
    thread_id: 2516
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 4117 — Group Policy Session started.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy Session started.

Fields

NameDescription
IsMachine
IsBackgroundProcessing
IsAsyncProcessing

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4117
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T02:02:23.115992+00:00'
  event_record_id: 1272
  correlation: {}
  execution:
    process_id: 21104
    thread_id: 4724
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  IsMachine: false
  IsBackgroundProcessing: true
  IsAsyncProcessing: false
message: ''

References

Event ID 4126 — Group Policy receiving applicable GPOs from the domain controller.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy receiving applicable GPOs from the domain controller.

Fields

NameDescription
IsMachine

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4126
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:57.214177+00:00'
  event_record_id: 1155
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  IsMachine: true
message: ''

References

Event ID 4216 — Starting to save policies to the local datastore.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Starting to save policies to the local datastore.

Fields

NameDescription
IsMachine

Event ID 4217 — Starting to load policies from the local datastore.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Starting to load policies from the local datastore.

Fields

NameDescription
IsMachine

Event ID 4218 — Starting the first WMI query for the policy.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Starting the first WMI query for the policy.

Fields

NameDescription
IsMachine

Event ID 4257 — Starting to download policies.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Starting to download policies.

Fields

NameDescription
IsMachine
IsBackgroundProcessing
IsAsyncProcessing

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4257
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.495445+00:00'
  event_record_id: 882
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  IsMachine: true
  IsBackgroundProcessing: true
  IsAsyncProcessing: true
message: ''

References

Event ID 4326 — Group Policy is trying to discover the Domain Controller information.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy is trying to discover the Domain Controller information.

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 4326
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.485405+00:00'
  event_record_id: 872
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 5016 — Completed %3 Extension Processing in %1 milliseconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Completed %3 Extension Processing in %1 milliseconds.

Fields

NameDescription
CSEElaspedTimeInMilliSeconds
ErrorCode
CSEExtensionName
CSEExtensionId

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5016
  version: 0
  level: 4
  task: 0
  opcode: 2
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:58.046318+00:00'
  event_record_id: 1166
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  CSEElaspedTimeInMilliSeconds: 140
  ErrorCode: 2147483658
  CSEExtensionName: Audit Policy Configuration
  CSEExtensionId: F3CCC681-B74C-4060-9F26-CD84525DCA2A
message: ''

References

Event ID 5017 — %3 %4 The call completed in %1 milliseconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

%3 
%4
The call completed in %1 milliseconds.

Fields

NameDescription
OperationElaspedTimeInMilliSeconds
ErrorCode
OperationDescription
Parameter

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5017
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.553922+00:00'
  event_record_id: 887
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  OperationElaspedTimeInMilliSeconds: 0
  ErrorCode: 0
  OperationDescription: '%%4132'
  Parameter: \\sigma.fr\sysvol\sigma.fr\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\gpt.ini
message: ''

References

Event ID 5018 — Completed %4 for %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Completed %4 for %3 in %1 seconds.

Fields

NameDescription
ScriptElaspedTimeInSeconds
ErrorCode
PrincipalSamName
ScriptType

Event ID 5019 — Completed %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Completed %3 in %1 seconds.

Fields

NameDescription
ScriptElaspedTimeInSeconds
ErrorCode
ScriptName

Event ID 5115 — Group Policy Service stopped.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy Service stopped.

Fields

NameDescription
IsServiceRestart
IsMachineBoot
GpsvcTimeElapsedInMilliseconds

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5115
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T22:31:34.542622+00:00'
  event_record_id: 468
  correlation: {}
  execution:
    process_id: 1860
    thread_id: 1836
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  IsServiceRestart: false
  IsMachineBoot: true
  GpsvcTimeElapsedInMilliseconds: 175484
message: ''

References

Event ID 5116 — Successfully completed the Group Policy Service initialization phase.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Successfully completed the Group Policy Service initialization phase.

Fields

NameDescription
GpsvcInitTimeElapsedInMilliseconds

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5116
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T06:25:40.434301+00:00'
  event_record_id: 416
  correlation: {}
  execution:
    process_id: 2412
    thread_id: 2548
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  GpsvcInitTimeElapsedInMilliseconds: 203
message: ''

References

Event ID 5117 — Group policy session completed successfully.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group policy session completed successfully.

Fields

NameDescription
IsMachine
SessionTimeElapsedInMilliseconds

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5117
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T02:02:23.611150+00:00'
  event_record_id: 1279
  correlation:
    ActivityID: 30469375-F951-41D9-8DD5-460652667F6C
  execution:
    process_id: 21104
    thread_id: 18128
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  IsMachine: true
  SessionTimeElapsedInMilliseconds: 719
message: ''

References

Event ID 5126 — Group Policy successfully got applicable GPOs from the domain controller.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy successfully got applicable GPOs from the domain controller.

Fields

NameDescription
IsMachine
IsBackgroundProcessing
IsAsyncProcessing
NumberOfGPOsDownloaded
NumberOfGPOsApplicable
GPODownloadTimeElapsedInMilliseconds

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5126
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:57.224158+00:00'
  event_record_id: 1157
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  IsMachine: true
  IsBackgroundProcessing: true
  IsAsyncProcessing: false
  NumberOfGPOsDownloaded: 1
  NumberOfGPOsApplicable: 0
  GPODownloadTimeElapsedInMilliseconds: 0
message: ''

References

Event ID 5216 — Successfully saved policies to the local datastore.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Successfully saved policies to the local datastore.

Fields

NameDescription
IsMachine
SaveToCacheTimeElapsedInMilliseconds

Event ID 5217 — Successfully loaded policies from the local datastore.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Successfully loaded policies from the local datastore.

Fields

NameDescription
IsMachine
LoadFromCacheTimeElapsedInMilliseconds

Event ID 5218 — Successfully completed the first WMI query.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Successfully completed the first WMI query.

Fields

NameDescription
IsMachine
FirstWmiQueryTimeElapsedInMilliseconds

Event ID 5257 — Successfully completed downloading policies.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Successfully completed downloading policies.

Fields

NameDescription
IsMachine
PolicyDownloadTimeElapsedInMilliseconds

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5257
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:57.215760+00:00'
  event_record_id: 1156
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  IsMachine: true
  PolicyDownloadTimeElapsedInMilliseconds: 4681812
message: ''

References

Event ID 5308 — Domain Controller details: Domain Controller Name : %1 Domain Controller IP Address : %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Domain Controller details: 
	Domain Controller Name : %1
	Domain Controller IP Address : %2

Fields

NameDescription
DCName[Domain Controller details] Domain Controller Name.
DCIPAddress[Domain Controller details] Domain Controller IP Address.

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5308
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.488998+00:00'
  event_record_id: 876
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  DCName: WIN-FPV0DSIC9O6.sigma.fr
  DCIPAddress: 10.0.2.133
message: ''

References

Event ID 5309 — Computer details: Computer role : %1 Network name : %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Computer details: 
	Computer role : %1
	Network name : %2

Fields

NameDescription
MachineRole[Computer details] Computer role.
NetworkName[Computer details] Network name.

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5309
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.489467+00:00'
  event_record_id: 878
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  MachineRole: 3
  NetworkName: localdomain
message: ''

References

Event ID 5310 — Account details: Account Name : %1 Account Domain Name : %2 DC Name : %3 DC Domain Name : %4.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Account details: 
	Account Name : %1
	Account Domain Name : %2
	DC Name : %3
	DC Domain Name : %4

Fields

NameDescription
PrincipalCNName[Account details] Account Name.
PrincipalDomainName[Account details] Account Domain Name.
DCName[Account details] DC Name.
DCDomainName[Account details] DC Domain Name.

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5310
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.489469+00:00'
  event_record_id: 879
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  PrincipalCNName: CN=WIN-FPV0DSIC9O6,OU=Domain Controllers,DC=sigma,DC=fr
  PrincipalDomainName: sigma.fr
  DCName: \\WIN-FPV0DSIC9O6.sigma.fr
  DCDomainName: sigma.fr
message: ''

References

Event ID 5311 — The loopback policy processing mode is %1.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

The loopback policy processing mode is %1.

Fields

NameDescription
PolicyProcessingMode

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5311
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:57.213591+00:00'
  event_record_id: 1154
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  PolicyProcessingMode: 0
message: ''

References

Event ID 5312 — List of applicable Group Policy objects.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

List of applicable Group Policy objects: 

%1

Fields

NameDescription
DescriptionStringList of applicable Group Policy objects
GPOInfoList

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5312
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:57.225593+00:00'
  event_record_id: 1158
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  DescriptionString: 'Local Group Policy

    '
  GPOInfoList: <GPO ID="Local Group Policy"><Name>Local Group Policy</Name><Version>2621480</Version><SOM>Local</SOM><FSPath>C:\Windows\System32\GroupPolicy\Machine</FSPath><Extensions>[{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{D02B1F72-3407-48AE-BA88-E8213C6761F1}][{F3CCC681-B74C-4060-9F26-CD84525DCA2A}{0F3F3735-573D-9804-99E4-AB2A69BA5FD4}]</Extensions></GPO>
message: ''

References

Event ID 5313 — The following Group Policy objects were not applicable because they were filtered out.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

The following Group Policy objects were not applicable because they were filtered out : 

%1

Fields

NameDescription
DescriptionStringThe following Group Policy objects were not applicable because they were filtered out
GPOInfoList

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5313
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:57.225627+00:00'
  event_record_id: 1159
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  DescriptionString: None
  GPOInfoList: ''
message: ''

References

Event ID 5314 — A %6 link was detected.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

A %6 link was detected. The Estimated bandwidth is %1 kbps. The slow link threshold is %3 kbps.

Fields

NameDescription
BandwidthInkbps
IsSlowLink
ThresholdInkbps
PolicyApplicationMode
ErrorCode
LinkDescription

Event ID 5315 — Next policy processing for %1 will be attempted in %2 %3.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Next policy processing for %1 will be attempted in %2 %3.

Fields

NameDescription
PrincipalSamName
NextPolicyApplicationTime
NextPolicyApplicationTimeUnit

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5315
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.580689+00:00'
  event_record_id: 898
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  PrincipalSamName: SIGMA\WIN-FPV0DSIC9O6$
  NextPolicyApplicationTime: 5
  NextPolicyApplicationTimeUnit: '%%4100'
message: ''

References

Event ID 5320 —

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

%1

Fields

NameDescription
InfoDescription

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5320
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T06:25:47.222709+00:00'
  event_record_id: 419
  correlation: {}
  execution:
    process_id: 2412
    thread_id: 2548
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  InfoDescription: '%%4166'
message: ''

References

Event ID 5321 — %1 Parameter: %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

%1 Parameter: %2

Fields

NameDescription
InfoDescription
OperationParameter11 Parameter.

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5321
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T06:25:47.223028+00:00'
  event_record_id: 420
  correlation: {}
  execution:
    process_id: 2412
    thread_id: 2548
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  InfoDescription: '%%4167'
  OperationParameter1: 9c6b0019-6984-4ded-a867-f9ffb55eb5bf
message: ''

References

Event ID 5322 — Group Policy waited for %3 milliseconds for the network subsystem at computer boot.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy waited for %3 milliseconds for the network subsystem at computer boot.

Fields

NameDescription
IsPolicyConfigured
MaxTimeToWait
TimeWaitedAtStartup
PrevAvgWaitTimeout
NewAvgWaitTimeout
DidWaitTimeout

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5322
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T16:54:16.476862+00:00'
  event_record_id: 500
  correlation: {}
  execution:
    process_id: 1352
    thread_id: 3688
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  IsPolicyConfigured: false
  MaxTimeToWait: 120000
  TimeWaitedAtStartup: 35110
  PrevAvgWaitTimeout: 60000
  NewAvgWaitTimeout: 60000
  DidWaitTimeout: true
message: ''

References

Event ID 5323 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 5324 — Group Policy received the notification %1 from Winlogon for session %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy received the notification %1 from Winlogon for session %2.

Fields

NameDescription
NotificationType
SessionId

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5324
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T02:02:22.822586+00:00'
  event_record_id: 1268
  correlation: {}
  execution:
    process_id: 21104
    thread_id: 14860
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  NotificationType: 0
  SessionId: 0
message: ''

References

Event ID 5325 — Group Policy received %1 notification from Service Control Manager.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy received %1 notification from Service Control Manager.

Fields

NameDescription
NotificationType

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5325
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T22:31:34.541162+00:00'
  event_record_id: 467
  correlation: {}
  execution:
    process_id: 1860
    thread_id: 1864
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  NotificationType: 0
message: ''

References

Event ID 5326 — Group Policy successfully discovered the Domain Controller in %1 milliseconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy successfully discovered the Domain Controller in %1 milliseconds.

Fields

NameDescription
DCDiscoveryTimeInMilliSeconds
ErrorCode

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5326
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.489000+00:00'
  event_record_id: 877
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  DCDiscoveryTimeInMilliSeconds: 0
  ErrorCode: 0
message: ''

References

Event ID 5327 — Estimated network bandwidth on one of the connections: %1 kbps.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Estimated network bandwidth on one of the connections: %1 kbps.

Fields

NameDescription
NetworkBandwidthInKbps

Event ID 5331 — Service configuration update to standalone was attempted due to the presence of Group Policy client extension %1 that is not part of the operating ...

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Service configuration update to standalone was attempted due to the presence of Group Policy client extension %1 that is not part of the operating system and completed with status %3.

Fields

NameDescription
UpdateCauseExtensionName
UpdateCauseExtensionId
ErrorCode

Event ID 5332 — Group Policy waited for %3 milliseconds for the Direct Access CorpNet connectivity at computer boot.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Group Policy waited for %3 milliseconds for the Direct Access CorpNet connectivity at computer boot.

Fields

NameDescription
IsPolicyConfigured
MaxTimeToWait
TimeWaitedAtStartup
DidWaitTimeout

Event ID 5340 — The Group Policy processing mode is %1.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

The Group Policy processing mode is %1.

Fields

NameDescription
PolicyApplicationMode

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5340
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:57.141137+00:00'
  event_record_id: 1153
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  PolicyApplicationMode: 0
message: ''

References

Event ID 5351 — Group policy session returned to winlogon.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group policy session returned to winlogon.

Fields

NameDescription
IsMachine
WinlogonReturnTimeElapsedInMilliseconds

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 5351
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T02:02:22.915005+00:00'
  event_record_id: 1271
  correlation: {}
  execution:
    process_id: 21104
    thread_id: 14860
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  IsMachine: true
  WinlogonReturnTimeElapsedInMilliseconds: 0
message: ''

References

Event ID 6000 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6001 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6002 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6003 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6004 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6005 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6006 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6007 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6016 — Completed %3 Extension Processing in %1 milliseconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Completed %3 Extension Processing in %1 milliseconds.

Fields

NameDescription
CSEElaspedTimeInMilliSeconds
ErrorCode
CSEExtensionName
CSEExtensionId

Event ID 6017 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6018 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6019 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6033 — Skipped %1 Extension based on Group Policy client-side processing rules.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Skipped %1 Extension based on Group Policy client-side processing rules.  Refer to a Resultant Set of Policy report for more information.

Fields

NameDescription
CSEExtensionName
CSEExtensionID

Event ID 6034 — Group Policy changed from synchronous foreground to asynchronous foreground based on slow link detection.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Group Policy changed from synchronous foreground to asynchronous foreground based on slow link detection.

Event ID 6035 — %1 Extension deferred processing until next synchronous foreground.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

%1 Extension deferred processing until next synchronous foreground.  Refer to a Resultant Set of Policy report for more information.

Fields

NameDescription
CSEExtensionName
CSEExtensionID

Event ID 6226 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6308 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6309 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6310 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6311 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6312 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6313 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6314 — Group Policy bandwidth estimation failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
3
Samples
1

Message

Group Policy bandwidth estimation failed. Group Policy processing will continue. Assuming %6 link.

Fields

NameDescription
BandwidthInkbps
IsSlowLink
ThresholdInkbps
PolicyApplicationMode
ErrorCode
LinkDescription

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 6314
  version: 0
  level: 3
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.507287+00:00'
  event_record_id: 883
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  BandwidthInkbps: 1
  IsSlowLink: false
  ThresholdInkbps: 500
  PolicyApplicationMode: 0
  ErrorCode: 1
  LinkDescription: '%%4113'
message: ''

References

Event ID 6315 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6320 — Warning: %1 Warning code %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Warning: %1 Warning code %2.

Fields

NameDescription
Warning
WarningDescription
WarningCode

Event ID 6321 — Warning: %1 Parameter: %3 : Warning code %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Warning: %1 Parameter: %3 : Warning code %2.

Fields

NameDescription
Warning
Parameter
WarningDescription
WarningCode
OperationParameter1

Event ID 6322 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6323 — Group Policy dependency did not start.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Group Policy dependency (%1) did not start. As a result, network related features of Group Policy such as bandwidth estimation and response to network changes will not work.

Fields

NameDescription
DisplayName

Event ID 6324 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6325 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6326 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6327 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6330 — An unfinished invocation of the Group Policy Client Side Extension %1 from a previous instance of the Group Policy Service was detected.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

An unfinished invocation of the Group Policy Client Side Extension %1 from a previous instance of the Group Policy Service was detected.  This may indicate that the extension caused the Group Policy Client Service to terminate unexpectedly.

Fields

NameDescription
InfoDescription
OperationParameter1

Event ID 6331 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Fields

NameDescription
UpdateCauseExtensionName
UpdateCauseExtensionId
ErrorCode

Event ID 6332 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 6337 — Group Policy network connection is via Direct Access.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Group Policy network connection is via Direct Access.

Event ID 6338 — Group Policy Winlogon status reporting has completed.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy Winlogon status reporting has completed.

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 6338
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T22:28:54.477711+00:00'
  event_record_id: 461
  correlation: {}
  execution:
    process_id: 1860
    thread_id: 2032
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 6339 — Group Policy Winlogon Start Shell handling completed.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Group Policy Winlogon Start Shell handling completed.

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 6339
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T22:32:22.754428+00:00'
  event_record_id: 509
  correlation: {}
  execution:
    process_id: 1132
    thread_id: 1332
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 6341 — A Group Policy setting was used to override the fast/slow link detection.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

A Group Policy setting was used to override the fast/slow link detection.

Event ID 6342 — The network connection is using a WWAN device for connectivity.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

The network connection is using a WWAN device for connectivity.

Event ID 6344 — Group Policy detected a slow link during sync mode processing.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Group Policy detected a slow link during sync mode processing.

Fields

NameDescription
IsMachine
SlowlinkThresholdInMilliseconds
DcResponseTimeInMilliseconds

Event ID 6345 — The connection to DC timed out during the Group Policy sync mode process.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

The connection to DC timed out during the Group Policy sync mode process.

Fields

NameDescription
IsMachine
DcResponseTimeInMilliseconds

Event ID 6346 — Group Policy switched the sync mode process to async mode.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Group Policy switched the sync mode process to async mode.

Fields

NameDescription
IsMachine
CSEExtensionName
CSEExtensionID

Event ID 7000 — Computer boot policy processing failed for %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Computer boot policy processing failed for %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 7001 — User logon policy processing failed for %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

User logon policy processing failed for %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 7002 — Policy processing due to network state change failed for computer %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Policy processing due to network state change failed for computer %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 7003 — Policy processing due to network state change failed for user %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Policy processing due to network state change failed for user %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 7004 — Manual processing of policy failed for computer %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Manual processing of policy failed for computer %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 7005 — Manual processing of policy failed for user %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Manual processing of policy failed for user %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 7006 — Periodic policy processing failed for computer %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Periodic policy processing failed for computer %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 7007 — Periodic policy processing failed for user %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Periodic policy processing failed for user %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 7016 — Completed %3 Extension Processing in %1 milliseconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Completed %3 Extension Processing in %1 milliseconds.

Fields

NameDescription
CSEElaspedTimeInMilliSeconds
ErrorCode
CSEExtensionName
CSEExtensionId

Event ID 7017 — %3 %4 The call failed after %1 milliseconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
2
Samples
1

Message

%3 
%4
The call failed after %1 milliseconds.

Fields

NameDescription
OperationElaspedTimeInMilliSeconds
ErrorCode
OperationDescription
Parameter

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 7017
  version: 0
  level: 2
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T16:59:24.588821+00:00'
  event_record_id: 562
  correlation:
    ActivityID: 178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  OperationElaspedTimeInMilliSeconds: 2000
  ErrorCode: 58
  OperationDescription: '%%4120'
  Parameter: WIN-FPV0DSIC9O6.sigma.fr
message: ''

References

Event ID 7018 — Script for %3 failed in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Script for %3 failed in %1 seconds.

Fields

NameDescription
ScriptElaspedTimeInSeconds
ErrorCode
PrincipalSamName
ScriptType

Event ID 7019 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7117 — Group policy session completed with error.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Group policy session completed with error.

Fields

NameDescription
IsMachine
ErrorCode
SessionTimeElapsedInMilliseconds

Event ID 7126 — Group Policy could not get applicable GPOs from the domain controller.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Group Policy could not get applicable GPOs from the domain controller.

Fields

NameDescription
IsMachine
ErrorCode
GPODownloadTimeElapsedInMilliseconds

Event ID 7216 — Saved policies to the local datastore with error.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Saved policies to the local datastore with error.

Fields

NameDescription
IsMachine
ErrorCode
SessionTimeElapsedInMilliseconds

Event ID 7217 — Loaded policies from the local datastore with error.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Loaded policies from the local datastore with error.

Fields

NameDescription
IsMachine
ErrorCode
LoadFromCacheTimeElapsedInMilliseconds

Event ID 7257 — Downloaded policies with error.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Downloaded policies with error.

Fields

NameDescription
IsMachine
ErrorCode
PolicyDownloadTimeElapsedInMilliseconds

Event ID 7308 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7309 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7310 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7311 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7312 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7313 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7314 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7315 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7320 — Error: %1 Error code %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
2
Samples
1

Message

Error: %1 Error code %2.

Fields

NameDescription
ErrorDescriptionError.
ErrorCode

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 7320
  version: 0
  level: 2
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T16:59:24.590503+00:00'
  event_record_id: 564
  correlation:
    ActivityID: 178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  ErrorDescription: '%%4125'
  ErrorCode: 50
message: ''

References

Event ID 7321 — Error: %1 Parameter: %3 : Error code %2.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Error: %1 Parameter: %3 : Error code %2.

Fields

NameDescription
Error
Parameter
ErrorDescription
ErrorCode
OperationParameter1

Event ID 7322 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7323 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7324 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7325 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7326 — Group Policy failed to discover the Domain Controller details in %1 milliseconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
2
Samples
1

Message

Group Policy failed to discover the Domain Controller details in %1 milliseconds.

Fields

NameDescription
DCDiscoveryTimeInMilliSeconds
ErrorCode

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 7326
  version: 0
  level: 2
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2022-04-07T16:59:24.588837+00:00'
  event_record_id: 563
  correlation:
    ActivityID: 178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  DCDiscoveryTimeInMilliSeconds: 4000
  ErrorCode: 58
message: ''

References

Event ID 7327 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 7331 — Service configuration update to standalone was attempted due to the presence of Group Policy client extension %1 that is not part of the operating ...

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Service configuration update to standalone was attempted due to the presence of Group Policy client extension %1 that is not part of the operating system and completed with status %3.

Fields

NameDescription
UpdateCauseExtensionName
UpdateCauseExtensionId
ErrorCode

Event ID 7332 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Invalid Error Message.

Event ID 8000 — Completed computer boot policy processing for %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Completed computer boot policy processing for %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 8000
  version: 1
  level: 4
  task: 0
  opcode: 2
  keywords: 4611686018427387904
  time_created: '2023-11-05T22:32:17.445743+00:00'
  event_record_id: 490
  correlation:
    ActivityID: 70C9A908-A206-406D-8A5D-D1CA7FEE9E13
  execution:
    process_id: 1132
    thread_id: 1348
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  PolicyElaspedTimeInSeconds: 0
  ErrorCode: 0
  PrincipalSamName: WORKGROUP\WINDEV2310EVAL$
  IsMachine: 1
  IsConnectivityFailure: false
message: ''

References

Event ID 8001 — Completed user logon policy processing for %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Completed user logon policy processing for %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 8001
  version: 1
  level: 4
  task: 0
  opcode: 2
  keywords: 4611686018427387904
  time_created: '2023-11-05T22:32:22.302154+00:00'
  event_record_id: 506
  correlation:
    ActivityID: DE67DFB7-B871-42E1-B68C-4175341DA657
  execution:
    process_id: 1132
    thread_id: 3904
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  PolicyElaspedTimeInSeconds: 0
  ErrorCode: 0
  PrincipalSamName: WINDEV2310EVAL\User
  IsMachine: 0
  IsConnectivityFailure: false
message: ''

References

Event ID 8002 — Completed policy processing due to network state change for computer %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Completed policy processing due to network state change for computer %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 8003 — Completed policy processing due to network state change for user %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Completed policy processing due to network state change for user %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 8004 — Completed manual processing of policy for computer %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Completed manual processing of policy for computer %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 8004
  version: 1
  level: 4
  task: 0
  opcode: 2
  keywords: 4611686018427387904
  time_created: '2023-11-05T23:49:58.061228+00:00'
  event_record_id: 1167
  correlation:
    ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
  execution:
    process_id: 8540
    thread_id: 9876
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  PolicyElaspedTimeInSeconds: 0
  ErrorCode: 0
  PrincipalSamName: WORKGROUP\WINDEV2310EVAL$
  IsMachine: 1
  IsConnectivityFailure: false
message: ''

References

Event ID 8005 — Completed manual processing of policy for user %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Completed manual processing of policy for user %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 8005
  version: 1
  level: 4
  task: 0
  opcode: 2
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:34:38.174229+00:00'
  event_record_id: 864
  correlation:
    ActivityID: DCA9073D-A053-4D86-A71A-A22443FB751F
  execution:
    process_id: 1352
    thread_id: 1684
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  PolicyElaspedTimeInSeconds: 0
  ErrorCode: 0
  PrincipalSamName: SIGMA\Administrator
  IsMachine: 0
  IsConnectivityFailure: false
message: ''

References

Event ID 8006 — Completed periodic policy processing for computer %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
4
Samples
1

Message

Completed periodic policy processing for computer %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Example Event

system:
  provider: Microsoft-Windows-GroupPolicy
  guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
  event_source_name: ''
  event_id: 8006
  version: 1
  level: 4
  task: 0
  opcode: 2
  keywords: 4611686018427387904
  time_created: '2022-04-07T17:39:37.570483+00:00'
  event_record_id: 897
  correlation:
    ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
  execution:
    process_id: 1352
    thread_id: 4040
  channel: Microsoft-Windows-GroupPolicy/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  PolicyElaspedTimeInSeconds: 0
  ErrorCode: 0
  PrincipalSamName: SIGMA\WIN-FPV0DSIC9O6$
  IsMachine: 1
  IsConnectivityFailure: false
message: ''

References

Event ID 8007 — Completed periodic policy processing for user %3 in %1 seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

Completed periodic policy processing for user %3 in %1 seconds.

Fields

NameDescription
PolicyElaspedTimeInSeconds
ErrorCode
PrincipalSamName
IsMachine
IsConnectivityFailure

Event ID 8016 — %1 Extension (%2) requests a sync mode process.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

%1 Extension (%2) requests a sync mode process.

Fields

NameDescription
CSEExtensionName
CSEExtensionId

Event ID 9001 — This machine is configured to retrieve Group Policy files from a file share in an insecure way.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message

This machine is configured to retrieve Group Policy files from a file share in an insecure way.

UNC Path: %1
Mutual Authentication Enforced: %2
Integrity Enforced: %3

Guidance: The UNC path contains logon scripts and/or files that control system security policies. Microsoft recommends configuring Windows to require both mutual authentication and integrity when accessing files on this UNC path.

For details on configuring Windows machines to require additional security when accessing specific UNC paths, visit http://support.microsoft.com/kb/3000483.

Fields

NameDescription
UNC_PathUNC Path. Contains logon scripts and/or files that control system security policies.
Mutual_Authentication_Enforced
Integrity_Enforced
UncPath
MutualAuthenticationEnforced
IntegrityEnforced