Microsoft-Windows-GroupPolicy

177 events across 2 channels

Event IDTitleChannel
1002The processing of Group Policy failed because of a system allocation failure.System
1006The processing of Group Policy failed.System
1007The processing of Group Policy failed.System
1030The processing of Group Policy failed.System
1052The processing of Group Policy failed.System
1053The processing of Group Policy failed.System
1054The processing of Group Policy failed.System
1055The processing of Group Policy failed.System
1058The processing of Group Policy failed.System
1065The processing of Group Policy failed.System
1068The processing of Group Policy was interrupted.System
1079The processing of Group Policy failed.System
1080The processing of Group Policy failed.System
1085Windows failed to apply the ExtensionName settings.System
1088The processing of Group Policy failed.System
1089Windows failed to record Resultant Set of Policy (RSoP) information, which …System
1090Windows failed to record Resultant Set of Policy (RSoP) information, which …System
1091Windows could not record the Resultant Set of Policy (RSoP) information for the …System
1095Windows encountered an error while recording Resultant Set of Policy (RSoP) …System
1096The processing of Group Policy failed.System
1097The processing of Group Policy failed.System
1101The processing of Group Policy failed.System
1104Windows was unable to read the Windows Management Instrumentation (WMI) filter …System
1109The user account is in a different forest than the computer account.System
1110The processing of Group Policy failed.System
1112The Group Policy Client Side Extension ExtensionName was unable to apply one or …System
1125The processing of Group Policy failed because of an internal system error.System
1126Windows was unable to determine whether new Group Policy settings defined by a …System
1127The processing of Group Policy failed due to an internal error.System
1128The Group Policy Client Side Extension ExtensionName may have caused the Group …System
1129The processing of Group Policy failed because of lack of network connectivity to …System
1130SupportInfo2 failed.System
1500The Group Policy settings for the computer were processed successfully.System
1501The Group Policy settings for the user were processed successfully.System
1502The Group Policy settings for the computer were processed successfully.System
1503The Group Policy settings for the user were processed successfully.System
4000Starting computer boot policy processing for PrincipalSamName.Operational
4001Starting user logon Policy processing for PrincipalSamName.Operational
4002Starting policy processing due to network state change for computer …Operational
4003Starting policy processing due to network state change for user …Operational
4004Starting manual processing of policy for computer PrincipalSamName.Operational
4005Starting manual processing of policy for user PrincipalSamName.Operational
4006Starting periodic policy processing for computer PrincipalSamName.Operational
4007Starting periodic policy processing for user PrincipalSamName.Operational
4016Starting CSEExtensionName Extension Processing.Operational
4017OperationDescription Parameter.Operational
4018Starting ScriptType for PrincipalSamName.Operational
4019Running script name ScriptName.Operational
4115Group Policy Service started.Operational
4116Started the Group Policy service initialization phase.Operational
4117Group Policy Session started.Operational
4126Group Policy receiving applicable GPOs from the domain controller.Operational
4216Starting to save policies to the local datastore.Operational
4217Starting to load policies from the local datastore.Operational
4218Starting the first WMI query for the policy.Operational
4257Starting to download policies.Operational
4326Group Policy is trying to discover the Domain Controller information.Operational
5016Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds …Operational
5017OperationDescription Parameter The call completed in …Operational
5018Completed ScriptType for PrincipalSamName in ScriptElaspedTimeInSeconds seconds.Operational
5019Completed ScriptName in ScriptElaspedTimeInSeconds seconds.Operational
5115Group Policy Service stopped.Operational
5116Successfully completed the Group Policy Service initialization phase.Operational
5117Group policy session completed successfully.Operational
5126Group Policy successfully got applicable GPOs from the domain controller.Operational
5216Successfully saved policies to the local datastore.Operational
5217Successfully loaded policies from the local datastore.Operational
5218Successfully completed the first WMI query.Operational
5257Successfully completed downloading policies.Operational
5308Domain Controller details.Operational
5309Computer details.Operational
5310Account details.Operational
5311The loopback policy processing mode is PolicyProcessingMode.Operational
5312List of applicable Group Policy objects.Operational
5313The following Group Policy objects were not applicable because they were …Operational
5314A LinkDescription link was detected.Operational
5315Next policy processing for PrincipalSamName will be attempted in …Operational
5320InfoDescription.Operational
5321InfoDescription Parameter: OperationParameter1.Operational
5322Group Policy waited for TimeWaitedAtStartup milliseconds for the network …Operational
5323Invalid Error Message.Operational
5324Group Policy received the notification NotificationType from Winlogon for …Operational
5325Group Policy received NotificationType notification from Service Control …Operational
5326Group Policy successfully discovered the Domain Controller in …Operational
5327Estimated network bandwidth on one of the connections: NetworkBandwidthInKbps …Operational
5331Service configuration update to standalone was attempted due to the presence of …Operational
5332Group Policy waited for TimeWaitedAtStartup milliseconds for the Direct Access …Operational
5340The Group Policy processing mode is PolicyApplicationMode.Operational
5351Group policy session returned to winlogon.Operational
6000Invalid Error Message.Operational
6001Invalid Error Message.Operational
6002Invalid Error Message.Operational
6003Invalid Error Message.Operational
6004Invalid Error Message.Operational
6005Invalid Error Message.Operational
6006Invalid Error Message.Operational
6007Invalid Error Message.Operational
6016Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds …Operational
6017Invalid Error Message.Operational
6018Invalid Error Message.Operational
6019Invalid Error Message.Operational
6033Skipped CSEExtensionName Extension based on Group Policy client-side processing …Operational
6034Group Policy changed from synchronous foreground to asynchronous foreground …Operational
6035CSEExtensionName Extension deferred processing until next synchronous …Operational
6226Invalid Error Message.Operational
6308Invalid Error Message.Operational
6309Invalid Error Message.Operational
6310Invalid Error Message.Operational
6311Invalid Error Message.Operational
6312Invalid Error Message.Operational
6313Invalid Error Message.Operational
6314Group Policy bandwidth estimation failed.Operational
6315Invalid Error Message.Operational
6320Warning: Warning Warning code WarningDescription.Operational
6321Warning: Warning Parameter: WarningDescription : Warning code Parameter.Operational
6322Invalid Error Message.Operational
6323Group Policy dependency (DisplayName) did not start.Operational
6324Invalid Error Message.Operational
6325Invalid Error Message.Operational
6326Invalid Error Message.Operational
6327Invalid Error Message.Operational
6330An unfinished invocation of the Group Policy Client Side Extension …Operational
6331Invalid Error Message.Operational
6332Invalid Error Message.Operational
6337Group Policy network connection is via Direct Access.Operational
6338Group Policy Winlogon status reporting has completed.Operational
6339Group Policy Winlogon Start Shell handling completed.Operational
6341A Group Policy setting was used to override the fast/slow link detection.Operational
6342The network connection is using a WWAN device for connectivity.Operational
6344Group Policy detected a slow link during sync mode processing.Operational
6345The connection to DC timed out during the Group Policy sync mode process.Operational
6346Group Policy switched the sync mode process to async mode.Operational
7000Computer boot policy processing failed for PrincipalSamName in …Operational
7001User logon policy processing failed for PrincipalSamName in …Operational
7002Policy processing due to network state change failed for computer …Operational
7003Policy processing due to network state change failed for user PrincipalSamName …Operational
7004Manual processing of policy failed for computer PrincipalSamName in …Operational
7005Manual processing of policy failed for user PrincipalSamName in …Operational
7006Periodic policy processing failed for computer PrincipalSamName in …Operational
7007Periodic policy processing failed for user PrincipalSamName in …Operational
7016Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds …Operational
7017OperationDescription Parameter The call failed after …Operational
7018Script for PrincipalSamName failed in ScriptElaspedTimeInSeconds seconds.Operational
7019Invalid Error Message.Operational
7117Group policy session completed with error.Operational
7126Group Policy could not get applicable GPOs from the domain controller.Operational
7216Saved policies to the local datastore with error.Operational
7217Loaded policies from the local datastore with error.Operational
7257Downloaded policies with error.Operational
7308Invalid Error Message.Operational
7309Invalid Error Message.Operational
7310Invalid Error Message.Operational
7311Invalid Error Message.Operational
7312Invalid Error Message.Operational
7313Invalid Error Message.Operational
7314Invalid Error Message.Operational
7315Invalid Error Message.Operational
7320Error: ErrorDescription Error code ErrorCode.Operational
7321Error: Error Parameter: ErrorDescription : Error code Parameter.Operational
7322Invalid Error Message.Operational
7323Invalid Error Message.Operational
7324Invalid Error Message.Operational
7325Invalid Error Message.Operational
7326Group Policy failed to discover the Domain Controller details in …Operational
7327Invalid Error Message.Operational
7331Service configuration update to standalone was attempted due to the presence of …Operational
7332Invalid Error Message.Operational
8000Completed computer boot policy processing for PrincipalSamName in …Operational
8001Completed user logon policy processing for PrincipalSamName in …Operational
8002Completed policy processing due to network state change for computer …Operational
8003Completed policy processing due to network state change for user …Operational
8004Completed manual processing of policy for computer PrincipalSamName in …Operational
8005Completed manual processing of policy for user PrincipalSamName in …Operational
8006Completed periodic policy processing for computer PrincipalSamName in …Operational
8007Completed periodic policy processing for user PrincipalSamName in …Operational
8016CSEExtensionName Extension (CSEExtensionId) requests a sync mode process.Operational
9001This machine is configured to retrieve Group Policy files from a file share in …Operational

Event ID 1002 — The processing of Group Policy failed because of a system allocation failure.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The processing of Group Policy failed because of a system allocation failure. Please ensure the computer is not running low on resources (memory, available disk space). Group Policy processing will be attempted at the next refresh cycle.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Event ID 1006 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
Error
Opcode
Start

Message #

The processing of Group Policy failed. Windows could not authenticate to the Active Directory service on a domain controller. (LDAP Bind function call failed). Look in the details tab for error code and description.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 1006,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 1,
    "keywords": 9223372036854775808,
    "time_created": "2026-02-18T05:29:01.333607+00:00",
    "event_record_id": 1666,
    "correlation": {
      "ActivityID": "29E96F9C-8911-49C3-99BC-065B1FD48E8E"
    },
    "execution": {
      "process_id": 3396,
      "thread_id": 2868
    },
    "channel": "System",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SupportInfo1": 1,
    "SupportInfo2": 6168,
    "ProcessingMode": 0,
    "ProcessingTimeInMilliseconds": 156,
    "ErrorCode": 82,
    "ErrorDescription": "Local Error",
    "DCName": ""
  },
  "message": ""
}

Event ID 1007 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Description

The processing of Group Policy failed. Windows could not determine the site associated for this computer, which is required for Group Policy processing.

Message #

The processing of Group Policy failed. Windows could not determine the site associated for this computer, which is required for Group Policy processing.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Event ID 1030 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
Error
Opcode
Start

Message #

The processing of Group Policy failed. Windows attempted to retrieve new Group Policy settings for this user or computer. Look in the details tab for error code and description. Windows will automatically retry this operation at the next refresh cycle. Computers joined to the domain must have proper name resolution and network connectivity to a domain controller for discovery of new Group Policy objects and settings. An event will be logged when Group Policy is successful.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 1030,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 1,
    "keywords": 9223372036854775808,
    "time_created": "2026-02-12T18:17:33.749779+00:00",
    "event_record_id": 1267,
    "correlation": {
      "ActivityID": "B725C8D9-F151-4EBC-ADFE-2827DEDA46D8"
    },
    "execution": {
      "process_id": 4092,
      "thread_id": 12968
    },
    "channel": "System",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
    }
  },
  "event_data": {
    "SupportInfo1": 1,
    "SupportInfo2": 3018,
    "ProcessingMode": 0,
    "ProcessingTimeInMilliseconds": 31,
    "ErrorCode": 8341,
    "ErrorDescription": "A directory service error has occurred. ",
    "DCName": "\\\\LAB-DC01.ludus.domain"
  },
  "message": ""
}

Event ID 1052 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Description

The processing of Group Policy failed. Windows could not determine the role of this computer. Role information (Workgroup, Member Server, or Domain Controller) is required to process Group Policy.

Message #

The processing of Group Policy failed. Windows could not determine the role of this computer. Role information (Workgroup, Member Server, or Domain Controller) is required to process Group Policy.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString

Event ID 1053 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Description

The processing of Group Policy failed. Windows could not resolve the user name. This could be caused by one of more of the following.

Message #

The processing of Group Policy failed. Windows could not resolve the user name. This could be caused by one of more of the following: 
a) Name Resolution failure on the current domain controller. 
b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString

Event ID 1054 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString

Event ID 1055 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Description

The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following.

Message #

The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 
a) Name Resolution failure on the current domain controller. 
b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString

Event ID 1058 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The processing of Group Policy failed. Windows attempted to read the file %9 from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following: 
a) Name Resolution/Network Connectivity to the current domain controller. 
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller). 
c) The Distributed File System (DFS) client has been disabled.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString
GPOCNName UnicodeString
FilePath UnicodeString

Event ID 1065 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The processing of Group Policy failed. Windows could not evaluate the Windows Management Instrumentation (WMI) filter for the Group Policy object %8. This could be caused by RSOP being disabled  or Windows Management Instrumentation (WMI) service being disabled, stopped, or other WMI errors. Make sure the WMI service is started and the startup type is set to automatic. New Group Policy objects or settings will not process until this event has been resolved.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString
GPOCNName UnicodeString

Event ID 1068 — The processing of Group Policy was interrupted.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The processing of Group Policy was interrupted. Windows prematurely ended the discovery and enforcement of Group Policy settings because the computer was requested to shutdown or the user logged off. Group Policy processing will be attempted next refresh cycle, on the next computer reboot, or the next user logon.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
DCName UnicodeString

Event ID 1079 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Description

The processing of Group Policy failed. Windows could not obtain the list of Group Policy objects applicable for this computer or user. View the event details for more information.

Message #

The processing of Group Policy failed. Windows could not obtain the list of Group Policy objects applicable for this computer or user. View the event details for more information.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Event ID 1080 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Description

The processing of Group Policy failed. Windows could not search the Active Directory organization unit hierarchy. View the event details for more information.

Message #

The processing of Group Policy failed. Windows could not search the Active Directory organization unit hierarchy. View the event details for more information.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Event ID 1085 — Windows failed to apply the ExtensionName settings.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Description

Windows failed to apply the ExtensionName settings. ExtensionName settings might have its own log file. Please click on the "More information" link.

Message #

Windows failed to apply the %8 settings. %8 settings might have its own log file. Please click on the "More information" link.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString
ExtensionName UnicodeString
ExtensionId UnicodeString

References #

Event ID 1088 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Description

The processing of Group Policy failed. Windows attempted to query the list of Group Policy objects and exceeded the maximum limit (999).

Message #

The processing of Group Policy failed. Windows attempted to query the list of Group Policy objects and exceeded the maximum limit (999).

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Event ID 1089 — Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or u...

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or user. This could be caused by RSOP being disabled or Windows Management Instrumentation (WMI) service being disabled, stopped, or other WMI errors. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Event ID 1090 — Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or u...

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or user. This could be caused by Windows Management Instrumentation (WMI) service being disabled, stopped, or other WMI errors. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
DCName UnicodeString

Event ID 1091 — Windows could not record the Resultant Set of Policy (RSoP) information for the Group Policy extension <.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

Windows could not record  the Resultant Set of Policy (RSoP) information for the Group Policy extension <%8>. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString
ExtensionName UnicodeString
ExtensionId UnicodeString

Event ID 1095 — Windows encountered an error while recording Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied ...

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

Windows encountered an error while recording Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or user. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Event ID 1096 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The processing of Group Policy failed. Windows could not apply the registry-based policy settings for the Group Policy object %8. Group Policy settings will not be resolved until this event is resolved. View the event details for more information on the file name and path that caused the failure.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString
GPOCNName UnicodeString
FilePath UnicodeString

Event ID 1097 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The processing of Group Policy failed. Windows could not determine the computer account to enforce Group Policy settings. This may be transient. Group Policy settings, including computer configuration, will not be enforced for this computer.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Event ID 1101 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The processing of Group Policy failed. Windows could not locate the directory object %8. Group Policy settings will not be enforced until this event is resolved. View the event details for more information on this error.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString
DSObjectName UnicodeString

Event ID 1104 — Windows was unable to read the Windows Management Instrumentation (WMI) filter information associated with the Group Policy object GPOCNName.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

Windows was unable to read the Windows Management Instrumentation (WMI) filter information associated with the Group Policy object %8.This may be caused by a deleted WMI Filter defined in the domain that is still in use by Group Policy objects. Group Policy settings for this Group Policy object will not be enforced. Other Group Policy objects may still apply. Windows will attempt to retrieve this information at the next policy cycle. This specific problem may be resolved by identifying all GPOs that reference the WMI filter and removing the references. Contact an administrator if this event recurs for several hours.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString
GPOCNName UnicodeString

Event ID 1109 — The user account is in a different forest than the computer account.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The user account is in a different forest than the computer account. The processing of Group Policy from another forest is not allowed. Group Policy will be processed using Loopback Replace mode. The scope of the user policy settings will be determined by the location of the computer object in Active Directory. The settings will be acquired from the User Configuration of these policies.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
DCName UnicodeString

Event ID 1110 — The processing of Group Policy failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest. Ensure the user domain name matches the name of a trusted domain that resides in the same forest as the computer account.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString

Event ID 1112 — The Group Policy Client Side Extension ExtensionName was unable to apply one or more settings because the changes must be processed before system startup or u...

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The Group Policy Client Side Extension %8 was unable to apply one or more settings because the changes must be processed before system startup or user logon. The system will wait for Group Policy processing to finish completely before the next startup or logon for this user, and this may result in slow startup and boot performance.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString
ExtensionName UnicodeString
ExtensionId UnicodeString

Event ID 1125 — The processing of Group Policy failed because of an internal system error.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Collection Priority
Recommended (NSA)
Opcode
Start

Message #

The processing of Group Policy failed because of an internal system error. Please see the Group Policy operational log for the specific error message. An attempt will be made to process Group Policy again at the next refresh cycle.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString

References #

Event ID 1126 — Windows was unable to determine whether new Group Policy settings defined by a network administrator should be enforced for this user or computer b...

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
Error
Collection Priority
Recommended (NSA)
Opcode
Start

Message #

Windows was unable to determine whether new Group Policy settings defined by a network administrator should be enforced for this user or computer because this computer's clock is not synchronized with the clock of one of the domain controllers for the domain. Because of this issue, this computer system may not be in compliance with the network administrator?s requirements, and users of this system may not be able to use some functionality on the network. Windows will periodically attempt to retry this operation, and it is possible that either this system or the domain controller will correct the time settings without intervention by an administrator, so the problem will be corrected. 

If this issue persists for more than an hour, checking the local system's clock settings to ensure they are accurate and are synchronized with the clocks on the network's domain controllers is one way to resolve this problem. A network administrator may be required to resolve the issue if correcting the local time settings does not address the problem.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 1126,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 1,
    "keywords": 9223372036854775808,
    "time_created": "2026-02-15T19:48:55.427011+00:00",
    "event_record_id": 1406,
    "correlation": {
      "ActivityID": "D02B1188-929A-4E97-B63D-48B93E963B5B"
    },
    "execution": {
      "process_id": 6076,
      "thread_id": 10716
    },
    "channel": "System",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SupportInfo1": 5,
    "SupportInfo2": 347,
    "ProcessingMode": 0,
    "ProcessingTimeInMilliseconds": 47,
    "ErrorCode": 2148074276,
    "ErrorDescription": "The clocks on the client and server machines are skewed. ",
    "DCName": "\\\\LAB-DC01.ludus.domain"
  },
  "message": ""
}

Event ID 1127 — The processing of Group Policy failed due to an internal error.

Provider
Microsoft-Windows-GroupPolicy
Channel
System
Opcode
Start

Message #

The processing of Group Policy failed due to an internal error. Please look into the Group Policy operational log for the specific error message. An attempt will be made to process Group Policy again at the next refresh cycle.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
DCName UnicodeString

Event ID 1128 — The Group Policy Client Side Extension ExtensionName may have caused the Group Policy Service to terminate unexpectedly.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message #

The Group Policy Client Side Extension %3 may have caused the Group Policy Service to terminate unexpectedly. To prevent further failures in the Group Policy Service, this extension has been temporarily disabled until after the next system restart. Group Policy settings managed by this extension may no longer be enforced until the system is restarted. The vendor of this extension should be contacted if this issue recurs.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ExtensionName UnicodeString
ExtensionId UnicodeString

Event ID 1129 — The processing of Group Policy failed because of lack of network connectivity to a domain controller.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
Error
Collection Priority
Recommended (NSA)

Message #

The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
ErrorCode UInt32
ErrorDescription UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 1129,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2022-04-07T16:57:06.407574+00:00",
    "event_record_id": 1271,
    "correlation": {
      "ActivityID": "B87F014A-16D6-49C2-8037-BBF193577383"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 2676
    },
    "channel": "System",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "SupportInfo1": 1,
    "SupportInfo2": 2044,
    "ProcessingMode": 1,
    "ProcessingTimeInMilliseconds": 4078,
    "ErrorCode": 1222,
    "ErrorDescription": "The network is not present or not started. "
  },
  "message": ""
}

References #

Event ID 1130 — SupportInfo2 failed.

Provider
Microsoft-Windows-GroupPolicy
Channel
System

Message #

%5 failed. 
	GPO Name : %6
	GPO File System Path : %7
	Script Name: %8

Fields #

NameDescription
GPO_Name
GPO_File_System_Path
Script_Name
SupportInfo1 UInt32
SupportInfo2 UInt32
ErrorCode UInt32
ErrorDescription UnicodeString
ScriptType UInt32
GPODisplayName UnicodeString
GPOFileSystemPath UnicodeString
GPOScriptCommandString UnicodeString

Event ID 1500 — The Group Policy settings for the computer were processed successfully.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
Informational
Opcode
Start

Description

The Group Policy settings for the computer were processed successfully. There were no changes detected since the last successful processing of Group Policy.

Message #

The Group Policy settings for the computer were processed successfully. There were no changes detected since the last successful processing of Group Policy.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
DCName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 1500,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T22:44:13.952441+00:00",
    "event_record_id": 1973,
    "correlation": {
      "ActivityID": "73911CA3-27B1-475D-92EC-CBFA1D10EB35"
    },
    "execution": {
      "process_id": 1132,
      "thread_id": 2268
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SupportInfo1": 1,
    "SupportInfo2": 4214,
    "ProcessingMode": 0,
    "ProcessingTimeInMilliseconds": 156,
    "DCName": ""
  },
  "message": ""
}

References #

Event ID 1501 — The Group Policy settings for the user were processed successfully.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
Informational
Opcode
Start

Description

The Group Policy settings for the user were processed successfully. There were no changes detected since the last successful processing of Group Policy.

Message #

The Group Policy settings for the user were processed successfully. There were no changes detected since the last successful processing of Group Policy.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
DCName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 1501,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T22:28:54.475787+00:00",
    "event_record_id": 1832,
    "correlation": {
      "ActivityID": "5D6D5E8D-CE04-46CB-BF83-231A8B295C46"
    },
    "execution": {
      "process_id": 1860,
      "thread_id": 4880
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "SupportInfo1": 1,
    "SupportInfo2": 4214,
    "ProcessingMode": 1,
    "ProcessingTimeInMilliseconds": 734,
    "DCName": ""
  },
  "message": ""
}

References #

Event ID 1502 — The Group Policy settings for the computer were processed successfully.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
Informational
Opcode
Start

Description

The Group Policy settings for the computer were processed successfully. New settings from NumberOfGroupPolicyObjects Group Policy objects were detected and applied.

Message #

The Group Policy settings for the computer were processed successfully. New settings from %6 Group Policy objects were detected and applied.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
DCName UnicodeString
NumberOfGroupPolicyObjects UInt32Number of Group Policy objects that were processed

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 1502,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T23:49:58.052759+00:00",
    "event_record_id": 2033,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SupportInfo1": 1,
    "SupportInfo2": 4195,
    "ProcessingMode": 0,
    "ProcessingTimeInMilliseconds": 906,
    "DCName": "",
    "NumberOfGroupPolicyObjects": 1
  },
  "message": ""
}

References #

Event ID 1503 — The Group Policy settings for the user were processed successfully.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
System
Level
Informational
Opcode
Start

Description

The Group Policy settings for the user were processed successfully. New settings from NumberOfGroupPolicyObjects Group Policy objects were detected and applied.

Message #

The Group Policy settings for the user were processed successfully. New settings from %6 Group Policy objects were detected and applied.

Fields #

NameDescription
SupportInfo1 UInt32
SupportInfo2 UInt32
ProcessingMode UInt32
ProcessingTimeInMilliseconds UInt32
DCName UnicodeString
NumberOfGroupPolicyObjects UInt32Number of Group Policy objects that were processed

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 1503,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 9223372036854775808,
    "time_created": "2022-04-07T17:34:38.149825+00:00",
    "event_record_id": 1319,
    "correlation": {
      "ActivityID": "DCA9073D-A053-4D86-A71A-A22443FB751F"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 1684
    },
    "channel": "System",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "SupportInfo1": 1,
    "SupportInfo2": 4195,
    "ProcessingMode": 0,
    "ProcessingTimeInMilliseconds": 671,
    "DCName": "\\\\WIN-FPV0DSIC9O6.lab.local",
    "NumberOfGroupPolicyObjects": 1
  },
  "message": ""
}

References #

Event ID 4000 — Starting computer boot policy processing for PrincipalSamName.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Start

Description

Starting computer boot policy processing for PrincipalSamName.

Message #

Starting computer boot policy processing for %2. 
Activity id: %1

Fields #

NameDescription
PolicyActivityId GUIDActivity id.
PrincipalSamName UnicodeStringSAM name of the computer account for which GPO processing was started
IsMachine UInt32
IsDomainJoined Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean
IsServiceRestart Boolean
ReasonForSyncProcessing UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4000,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T22:32:17.280621+00:00",
    "event_record_id": 479,
    "correlation": {
      "ActivityID": "70C9A908-A206-406D-8A5D-D1CA7FEE9E13"
    },
    "execution": {
      "process_id": 1132,
      "thread_id": 1348
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyActivityId": "70C9A908-A206-406D-8A5D-D1CA7FEE9E13",
    "PrincipalSamName": "WORKGROUP\\WINDEV2310EVAL$",
    "IsMachine": 1,
    "IsDomainJoined": false,
    "IsBackgroundProcessing": false,
    "IsAsyncProcessing": true,
    "IsServiceRestart": false,
    "ReasonForSyncProcessing": 0
  },
  "message": ""
}

References #

Event ID 4001 — Starting user logon Policy processing for PrincipalSamName.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Start

Description

Starting user logon Policy processing for PrincipalSamName.

Message #

Starting user logon Policy processing for %2. 
Activity id: %1

Fields #

NameDescription
PolicyActivityId GUIDActivity id.
PrincipalSamName UnicodeStringSAM name of the user account for which GPO processing was started
IsMachine UInt32
IsDomainJoined Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean
IsServiceRestart Boolean
ReasonForSyncProcessing UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4001,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T22:32:20.905356+00:00",
    "event_record_id": 495,
    "correlation": {
      "ActivityID": "DE67DFB7-B871-42E1-B68C-4175341DA657"
    },
    "execution": {
      "process_id": 1132,
      "thread_id": 3904
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyActivityId": "DE67DFB7-B871-42E1-B68C-4175341DA657",
    "PrincipalSamName": "WINDEV2310EVAL\\User",
    "IsMachine": 0,
    "IsDomainJoined": false,
    "IsBackgroundProcessing": false,
    "IsAsyncProcessing": true,
    "IsServiceRestart": false,
    "ReasonForSyncProcessing": 0
  },
  "message": ""
}

References #

Event ID 4002 — Starting policy processing due to network state change for computer PolicyActivityId.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Start

Description

Starting policy processing due to network state change for computer PolicyActivityId.

Message #

Starting policy processing due to network state change for computer %2. 
Activity id: %1

Fields #

NameDescription
Activity_id
PolicyActivityId GUID
PrincipalSamName UnicodeString
IsMachine UInt32
IsDomainJoined Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean
IsServiceRestart Boolean
ReasonForSyncProcessing UInt32

Event ID 4003 — Starting policy processing due to network state change for user PolicyActivityId.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Start

Description

Starting policy processing due to network state change for user PolicyActivityId.

Message #

Starting policy processing due to network state change for user %2. 
Activity id: %1

Fields #

NameDescription
Activity_id
PolicyActivityId GUID
PrincipalSamName UnicodeString
IsMachine UInt32
IsDomainJoined Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean
IsServiceRestart Boolean
ReasonForSyncProcessing UInt32

Event ID 4004 — Starting manual processing of policy for computer PrincipalSamName.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Start

Description

Starting manual processing of policy for computer PrincipalSamName.

Message #

Starting manual processing of policy for computer %2. 
Activity id: %1

Fields #

NameDescription
PolicyActivityId GUIDActivity id.
PrincipalSamName UnicodeStringSAM name of the computer account for which GPO processing was started
IsMachine UInt32
IsDomainJoined Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean
IsServiceRestart Boolean
ReasonForSyncProcessing UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4004,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:57.126023+00:00",
    "event_record_id": 1152,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyActivityId": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3",
    "PrincipalSamName": "WORKGROUP\\WINDEV2310EVAL$",
    "IsMachine": 1,
    "IsDomainJoined": false,
    "IsBackgroundProcessing": true,
    "IsAsyncProcessing": false,
    "IsServiceRestart": false,
    "ReasonForSyncProcessing": 0
  },
  "message": ""
}

References #

Event ID 4005 — Starting manual processing of policy for user PrincipalSamName.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Start

Description

Starting manual processing of policy for user PrincipalSamName.

Message #

Starting manual processing of policy for user %2. 
Activity id: %1

Fields #

NameDescription
PolicyActivityId GUIDActivity id.
PrincipalSamName UnicodeStringSAM name of the user account for which GPO processing was started
IsMachine UInt32
IsDomainJoined Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean
IsServiceRestart Boolean
ReasonForSyncProcessing UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4005,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:34:37.483672+00:00",
    "event_record_id": 835,
    "correlation": {
      "ActivityID": "DCA9073D-A053-4D86-A71A-A22443FB751F"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 1684
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyActivityId": "DCA9073D-A053-4D86-A71A-A22443FB751F",
    "PrincipalSamName": "SIGMA\\Administrator",
    "IsMachine": 0,
    "IsDomainJoined": true,
    "IsBackgroundProcessing": true,
    "IsAsyncProcessing": false,
    "IsServiceRestart": false,
    "ReasonForSyncProcessing": 0
  },
  "message": ""
}

References #

Event ID 4006 — Starting periodic policy processing for computer PrincipalSamName.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Start

Description

Starting periodic policy processing for computer PrincipalSamName.

Message #

Starting periodic policy processing for computer %2. 
Activity id: %1

Fields #

NameDescription
PolicyActivityId GUIDActivity id.
PrincipalSamName UnicodeString
IsMachine UInt32
IsDomainJoined Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean
IsServiceRestart Boolean
ReasonForSyncProcessing UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4006,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.484458+00:00",
    "event_record_id": 866,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyActivityId": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234",
    "PrincipalSamName": "SIGMA\\WIN-FPV0DSIC9O6$",
    "IsMachine": 1,
    "IsDomainJoined": true,
    "IsBackgroundProcessing": true,
    "IsAsyncProcessing": false,
    "IsServiceRestart": false,
    "ReasonForSyncProcessing": 0
  },
  "message": ""
}

References #

Event ID 4007 — Starting periodic policy processing for user PrincipalSamName.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Start

Description

Starting periodic policy processing for user PrincipalSamName.

Message #

Starting periodic policy processing for user %2. 
Activity id: %1

Fields #

NameDescription
PolicyActivityId GUID
PrincipalSamName UnicodeString
IsMachine UInt32
IsDomainJoined Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean
IsServiceRestart Boolean
ReasonForSyncProcessing UInt32
Activity_id

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4007,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-14T01:40:41.526525+00:00",
    "event_record_id": 179683,
    "correlation": {
      "ActivityID": "261F3C8C-5577-42F1-99D9-89D7A88E5B00"
    },
    "execution": {
      "process_id": 1112,
      "thread_id": 6604
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyActivityId": "261F3C8C-5577-42F1-99D9-89D7A88E5B00",
    "PrincipalSamName": "ludus\\domainadmin",
    "IsMachine": 0,
    "IsDomainJoined": true,
    "IsBackgroundProcessing": true,
    "IsAsyncProcessing": false,
    "IsServiceRestart": false,
    "ReasonForSyncProcessing": 0
  },
  "message": ""
}

Event ID 4016 — Starting CSEExtensionName Extension Processing.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Start

Description

Starting CSEExtensionName Extension Processing.

Message #

Starting %2 Extension Processing. 

List of applicable Group Policy objects: (%5)

%6

Fields #

NameDescription
CSEExtensionId GUID
CSEExtensionName UnicodeString
IsExtensionAsyncProcessing Boolean
IsGPOListChanged Boolean
GPOListStatusString UnicodeString
DescriptionString UnicodeString
ApplicableGPOList UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4016,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:57.906053+00:00",
    "event_record_id": 1165,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "CSEExtensionId": "F3CCC681-B74C-4060-9F26-CD84525DCA2A",
    "CSEExtensionName": "Audit Policy Configuration",
    "IsExtensionAsyncProcessing": true,
    "IsGPOListChanged": true,
    "GPOListStatusString": "%%4102",
    "DescriptionString": "Local Group Policy\n",
    "ApplicableGPOList": "<GPO ID=\"Local Group Policy\"><Name>Local Group Policy</Name></GPO>"
  },
  "message": ""
}

References #

Event ID 4017 — OperationDescription Parameter.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Message #

%1 
%2

Fields #

NameDescription
OperationDescription UnicodeString
Parameter UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4017,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.551157+00:00",
    "event_record_id": 886,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "OperationDescription": "%%4131",
    "Parameter": "\\\\lab.local\\sysvol\\lab.local\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\gpt.ini"
  },
  "message": ""
}

References #

Event ID 4018 — Starting ScriptType for PrincipalSamName.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Start

Description

Starting ScriptType for PrincipalSamName.

Message #

Starting %2 for %1.

Fields #

NameDescription
PrincipalSamName UnicodeString
ScriptType UInt32
IsScriptHidden Boolean
IsScriptSync Boolean
IsScriptMinimized Boolean
SessionId UInt32

Event ID 4019 — Running script name ScriptName.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Running script name ScriptName.

Message #

Running script name %1.

Fields #

NameDescription
ScriptName UnicodeString
ScriptFileSystemPath UnicodeString
ScriptArguments UnicodeString

Event ID 4115 — Group Policy Service started.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy Service started.

Message #

Group Policy Service started.

Fields #

NameDescription
IsServiceRestart Boolean
IsMachineBoot Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4115,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T06:25:40.340217+00:00",
    "event_record_id": 415,
    "correlation": {},
    "execution": {
      "process_id": 2412,
      "thread_id": 2516
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsServiceRestart": false,
    "IsMachineBoot": true
  },
  "message": ""
}

References #

Event ID 4116 — Started the Group Policy service initialization phase.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Started the Group Policy service initialization phase.

Message #

Started the Group Policy service initialization phase.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4116,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T06:25:40.239882+00:00",
    "event_record_id": 414,
    "correlation": {},
    "execution": {
      "process_id": 2412,
      "thread_id": 2516
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 4117 — Group Policy Session started.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy Session started.

Message #

Group Policy Session started.

Fields #

NameDescription
IsMachine Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4117,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T02:02:23.115992+00:00",
    "event_record_id": 1272,
    "correlation": {},
    "execution": {
      "process_id": 21104,
      "thread_id": 4724
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsMachine": false,
    "IsBackgroundProcessing": true,
    "IsAsyncProcessing": false
  },
  "message": ""
}

References #

Event ID 4126 — Group Policy receiving applicable GPOs from the domain controller.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy receiving applicable GPOs from the domain controller.

Message #

Group Policy receiving applicable GPOs from the domain controller.

Fields #

NameDescription
IsMachine Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4126,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:57.214177+00:00",
    "event_record_id": 1155,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsMachine": true
  },
  "message": ""
}

References #

Event ID 4216 — Starting to save policies to the local datastore.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Starting to save policies to the local datastore.

Message #

Starting to save policies to the local datastore.

Fields #

NameDescription
IsMachine Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4216,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-09T00:48:47.640241+00:00",
    "event_record_id": 5485,
    "correlation": {
      "ActivityID": "9197D599-AFC9-4584-AEA0-64AEB7628F03"
    },
    "execution": {
      "process_id": 2268,
      "thread_id": 8268
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
    }
  },
  "event_data": {
    "IsMachine": false
  },
  "message": ""
}

Event ID 4217 — Starting to load policies from the local datastore.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Starting to load policies from the local datastore.

Message #

Starting to load policies from the local datastore.

Fields #

NameDescription
IsMachine Boolean

Event ID 4218 — Starting the first WMI query for the policy.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Starting the first WMI query for the policy.

Message #

Starting the first WMI query for the policy.

Fields #

NameDescription
IsMachine Boolean

Event ID 4257 — Starting to download policies.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Starting to download policies.

Message #

Starting to download policies.

Fields #

NameDescription
IsMachine Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4257,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.495445+00:00",
    "event_record_id": 882,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsMachine": true,
    "IsBackgroundProcessing": true,
    "IsAsyncProcessing": true
  },
  "message": ""
}

References #

Event ID 4326 — Group Policy is trying to discover the Domain Controller information.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy is trying to discover the Domain Controller information.

Message #

Group Policy is trying to discover the Domain Controller information.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 4326,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.485405+00:00",
    "event_record_id": 872,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 5016 — Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds milliseconds.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Stop

Description

Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds milliseconds.

Message #

Completed %3 Extension Processing in %1 milliseconds.

Fields #

NameDescription
CSEElaspedTimeInMilliSeconds UInt32
ErrorCode UInt32
CSEExtensionName UnicodeString
CSEExtensionId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5016,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 2,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:58.046318+00:00",
    "event_record_id": 1166,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "CSEElaspedTimeInMilliSeconds": 140,
    "ErrorCode": 2147483658,
    "CSEExtensionName": "Audit Policy Configuration",
    "CSEExtensionId": "F3CCC681-B74C-4060-9F26-CD84525DCA2A"
  },
  "message": ""
}

References #

Event ID 5017 — OperationDescription Parameter The call completed in OperationElaspedTimeInMilliSeconds milliseconds.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Message #

%3 
%4
The call completed in %1 milliseconds.

Fields #

NameDescription
OperationElaspedTimeInMilliSeconds UInt32
ErrorCode UInt32
OperationDescription UnicodeString
Parameter UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5017,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.553922+00:00",
    "event_record_id": 887,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "OperationElaspedTimeInMilliSeconds": 0,
    "ErrorCode": 0,
    "OperationDescription": "%%4132",
    "Parameter": "\\\\lab.local\\sysvol\\lab.local\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\gpt.ini"
  },
  "message": ""
}

References #

Event ID 5018 — Completed ScriptType for PrincipalSamName in ScriptElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Completed ScriptType for PrincipalSamName in ScriptElaspedTimeInSeconds seconds.

Message #

Completed %4 for %3 in %1 seconds.

Fields #

NameDescription
ScriptElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
ScriptType UInt32

Event ID 5019 — Completed ScriptName in ScriptElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Completed ScriptName in ScriptElaspedTimeInSeconds seconds.

Message #

Completed %3 in %1 seconds.

Fields #

NameDescription
ScriptElaspedTimeInSeconds UInt32
ErrorCode UInt32
ScriptName UnicodeString

Event ID 5115 — Group Policy Service stopped.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy Service stopped.

Message #

Group Policy Service stopped.

Fields #

NameDescription
IsServiceRestart Boolean
IsMachineBoot Boolean
GpsvcTimeElapsedInMilliseconds UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5115,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T22:31:34.542622+00:00",
    "event_record_id": 468,
    "correlation": {},
    "execution": {
      "process_id": 1860,
      "thread_id": 1836
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsServiceRestart": false,
    "IsMachineBoot": true,
    "GpsvcTimeElapsedInMilliseconds": 175484
  },
  "message": ""
}

References #

Event ID 5116 — Successfully completed the Group Policy Service initialization phase.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Successfully completed the Group Policy Service initialization phase.

Message #

Successfully completed the Group Policy Service initialization phase.

Fields #

NameDescription
GpsvcInitTimeElapsedInMilliseconds UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5116,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T06:25:40.434301+00:00",
    "event_record_id": 416,
    "correlation": {},
    "execution": {
      "process_id": 2412,
      "thread_id": 2548
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "GpsvcInitTimeElapsedInMilliseconds": 203
  },
  "message": ""
}

References #

Event ID 5117 — Group policy session completed successfully.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group policy session completed successfully.

Message #

Group policy session completed successfully.

Fields #

NameDescription
IsMachine Boolean
SessionTimeElapsedInMilliseconds UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5117,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T02:02:23.611150+00:00",
    "event_record_id": 1279,
    "correlation": {
      "ActivityID": "30469375-F951-41D9-8DD5-460652667F6C"
    },
    "execution": {
      "process_id": 21104,
      "thread_id": 18128
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsMachine": true,
    "SessionTimeElapsedInMilliseconds": 719
  },
  "message": ""
}

References #

Event ID 5126 — Group Policy successfully got applicable GPOs from the domain controller.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy successfully got applicable GPOs from the domain controller.

Message #

Group Policy successfully got applicable GPOs from the domain controller.

Fields #

NameDescription
IsMachine Boolean
IsBackgroundProcessing Boolean
IsAsyncProcessing Boolean
NumberOfGPOsDownloaded UInt32
NumberOfGPOsApplicable UInt32
GPODownloadTimeElapsedInMilliseconds UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5126,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:57.224158+00:00",
    "event_record_id": 1157,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsMachine": true,
    "IsBackgroundProcessing": true,
    "IsAsyncProcessing": false,
    "NumberOfGPOsDownloaded": 1,
    "NumberOfGPOsApplicable": 0,
    "GPODownloadTimeElapsedInMilliseconds": 0
  },
  "message": ""
}

References #

Event ID 5216 — Successfully saved policies to the local datastore.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Successfully saved policies to the local datastore.

Message #

Successfully saved policies to the local datastore.

Fields #

NameDescription
IsMachine Boolean
SaveToCacheTimeElapsedInMilliseconds UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5216,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-09T00:48:47.649684+00:00",
    "event_record_id": 5486,
    "correlation": {
      "ActivityID": "9197D599-AFC9-4584-AEA0-64AEB7628F03"
    },
    "execution": {
      "process_id": 2268,
      "thread_id": 8268
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
    }
  },
  "event_data": {
    "IsMachine": false,
    "SaveToCacheTimeElapsedInMilliseconds": 16
  },
  "message": ""
}

Event ID 5217 — Successfully loaded policies from the local datastore.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Successfully loaded policies from the local datastore.

Message #

Successfully loaded policies from the local datastore.

Fields #

NameDescription
IsMachine Boolean
LoadFromCacheTimeElapsedInMilliseconds UInt32

Event ID 5218 — Successfully completed the first WMI query.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Successfully completed the first WMI query.

Message #

Successfully completed the first WMI query.

Fields #

NameDescription
IsMachine Boolean
FirstWmiQueryTimeElapsedInMilliseconds UInt32

Event ID 5257 — Successfully completed downloading policies.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Successfully completed downloading policies.

Message #

Successfully completed downloading policies.

Fields #

NameDescription
IsMachine Boolean
PolicyDownloadTimeElapsedInMilliseconds UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5257,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:57.215760+00:00",
    "event_record_id": 1156,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsMachine": true,
    "PolicyDownloadTimeElapsedInMilliseconds": 4681812
  },
  "message": ""
}

References #

Event ID 5308 — Domain Controller details.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Domain Controller details.

Message #

Domain Controller details: 
	Domain Controller Name : %1
	Domain Controller IP Address : %2

Fields #

NameDescription
DCName UnicodeString[Domain Controller details] Domain Controller Name.
DCIPAddress UnicodeString[Domain Controller details] Domain Controller IP Address.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5308,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.488998+00:00",
    "event_record_id": 876,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DCName": "WIN-FPV0DSIC9O6.lab.local",
    "DCIPAddress": "10.0.2.133"
  },
  "message": ""
}

References #

Event ID 5309 — Computer details.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Computer details.

Message #

Computer details: 
	Computer role : %1
	Network name : %2

Fields #

NameDescription
MachineRole UInt32[Computer details] Computer role.
NetworkName UnicodeString[Computer details] Network name.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5309,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.489467+00:00",
    "event_record_id": 878,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "MachineRole": 3,
    "NetworkName": "localdomain"
  },
  "message": ""
}

References #

Event ID 5310 — Account details.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Account details.

Message #

Account details: 
	Account Name : %1
	Account Domain Name : %2
	DC Name : %3
	DC Domain Name : %4

Fields #

NameDescription
PrincipalCNName UnicodeString[Account details] Account Name.
PrincipalDomainName UnicodeString[Account details] Account Domain Name.
DCName UnicodeString[Account details] DC Name.
DCDomainName UnicodeString[Account details] DC Domain Name.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5310,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.489469+00:00",
    "event_record_id": 879,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PrincipalCNName": "CN=WIN-FPV0DSIC9O6,OU=Domain Controllers,DC=sigma,DC=fr",
    "PrincipalDomainName": "lab.local",
    "DCName": "\\\\WIN-FPV0DSIC9O6.lab.local",
    "DCDomainName": "lab.local"
  },
  "message": ""
}

References #

Event ID 5311 — The loopback policy processing mode is PolicyProcessingMode.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

The loopback policy processing mode is PolicyProcessingMode.

Message #

The loopback policy processing mode is %1.

Fields #

NameDescription
PolicyProcessingMode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5311,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:57.213591+00:00",
    "event_record_id": 1154,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyProcessingMode": 0
  },
  "message": ""
}

References #

Event ID 5312 — List of applicable Group Policy objects.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

List of applicable Group Policy objects.

Message #

List of applicable Group Policy objects: 

%1

Fields #

NameDescription
DescriptionString UnicodeStringList of applicable Group Policy objects
GPOInfoList UnicodeStringXML string containing information about the applicable Group Policy objects

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5312,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:57.225593+00:00",
    "event_record_id": 1158,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DescriptionString": "Local Group Policy\n",
    "GPOInfoList": "<GPO ID=\"Local Group Policy\"><Name>Local Group Policy</Name><Version>2621480</Version><SOM>Local</SOM><FSPath>C:\\Windows\\System32\\GroupPolicy\\Machine</FSPath><Extensions>[{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{D02B1F72-3407-48AE-BA88-E8213C6761F1}][{F3CCC681-B74C-4060-9F26-CD84525DCA2A}{0F3F3735-573D-9804-99E4-AB2A69BA5FD4}]</Extensions></GPO>"
  },
  "message": ""
}

References #

Event ID 5313 — The following Group Policy objects were not applicable because they were filtered out.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

The following Group Policy objects were not applicable because they were filtered out.

Message #

The following Group Policy objects were not applicable because they were filtered out : 

%1

Fields #

NameDescription
DescriptionString UnicodeStringThe following Group Policy objects were not applicable because they were filtered out
GPOInfoList UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5313,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:57.225627+00:00",
    "event_record_id": 1159,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DescriptionString": "None",
    "GPOInfoList": ""
  },
  "message": ""
}

References #

Event ID 5314 — A LinkDescription link was detected.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

A LinkDescription link was detected. The Estimated bandwidth is BandwidthInkbps kbps. The slow link threshold is ThresholdInkbps kbps.

Message #

A %6 link was detected. The Estimated bandwidth is %1 kbps. The slow link threshold is %3 kbps.

Fields #

NameDescription
BandwidthInkbps UInt32
ThresholdInkbps UInt32
PolicyApplicationMode UInt32
ErrorCode UInt32
LinkDescription UnicodeString

Event ID 5315 — Next policy processing for PrincipalSamName will be attempted in NextPolicyApplicationTime NextPolicyApplicationTimeUnit.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Next policy processing for PrincipalSamName will be attempted in NextPolicyApplicationTime NextPolicyApplicationTimeUnit.

Message #

Next policy processing for %1 will be attempted in %2 %3.

Fields #

NameDescription
PrincipalSamName UnicodeString
NextPolicyApplicationTime UInt32
NextPolicyApplicationTimeUnit UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5315,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.580689+00:00",
    "event_record_id": 898,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PrincipalSamName": "SIGMA\\WIN-FPV0DSIC9O6$",
    "NextPolicyApplicationTime": 5,
    "NextPolicyApplicationTimeUnit": "%%4100"
  },
  "message": ""
}

References #

Event ID 5320 — InfoDescription.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Message #

%1

Fields #

NameDescription
InfoDescription UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5320,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T06:25:47.222709+00:00",
    "event_record_id": 419,
    "correlation": {},
    "execution": {
      "process_id": 2412,
      "thread_id": 2548
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "InfoDescription": "%%4166"
  },
  "message": ""
}

References #

Event ID 5321 — InfoDescription Parameter: OperationParameter1.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

InfoDescription Parameter: OperationParameter1.

Message #

%1 Parameter: %2

Fields #

NameDescription
InfoDescription UnicodeString
OperationParameter1 UnicodeString1 Parameter.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5321,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T06:25:47.223028+00:00",
    "event_record_id": 420,
    "correlation": {},
    "execution": {
      "process_id": 2412,
      "thread_id": 2548
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "InfoDescription": "%%4167",
    "OperationParameter1": "9c6b0019-6984-4ded-a867-f9ffb55eb5bf"
  },
  "message": ""
}

References #

Event ID 5322 — Group Policy waited for TimeWaitedAtStartup milliseconds for the network subsystem at computer boot.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy waited for TimeWaitedAtStartup milliseconds for the network subsystem at computer boot.

Message #

Group Policy waited for %3 milliseconds for the network subsystem at computer boot.

Fields #

NameDescription
IsPolicyConfigured Boolean
MaxTimeToWait UInt32
TimeWaitedAtStartup UInt32
PrevAvgWaitTimeout UInt32
NewAvgWaitTimeout UInt32
DidWaitTimeout Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5322,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T16:54:16.476862+00:00",
    "event_record_id": 500,
    "correlation": {},
    "execution": {
      "process_id": 1352,
      "thread_id": 3688
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsPolicyConfigured": false,
    "MaxTimeToWait": 120000,
    "TimeWaitedAtStartup": 35110,
    "PrevAvgWaitTimeout": 60000,
    "NewAvgWaitTimeout": 60000,
    "DidWaitTimeout": true
  },
  "message": ""
}

References #

Event ID 5323 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 5324 — Group Policy received the notification NotificationType from Winlogon for session SessionId.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy received the notification NotificationType from Winlogon for session SessionId.

Message #

Group Policy received the notification %1 from Winlogon for session %2.

Fields #

NameDescription
NotificationType UInt32
SessionId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5324,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T02:02:22.822586+00:00",
    "event_record_id": 1268,
    "correlation": {},
    "execution": {
      "process_id": 21104,
      "thread_id": 14860
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "NotificationType": 0,
    "SessionId": 0
  },
  "message": ""
}

References #

Event ID 5325 — Group Policy received NotificationType notification from Service Control Manager.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy received NotificationType notification from Service Control Manager.

Message #

Group Policy received %1 notification from Service Control Manager.

Fields #

NameDescription
NotificationType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5325,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T22:31:34.541162+00:00",
    "event_record_id": 467,
    "correlation": {},
    "execution": {
      "process_id": 1860,
      "thread_id": 1864
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "NotificationType": 0
  },
  "message": ""
}

References #

Event ID 5326 — Group Policy successfully discovered the Domain Controller in DCDiscoveryTimeInMilliSeconds milliseconds.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy successfully discovered the Domain Controller in DCDiscoveryTimeInMilliSeconds milliseconds.

Message #

Group Policy successfully discovered the Domain Controller in %1 milliseconds.

Fields #

NameDescription
DCDiscoveryTimeInMilliSeconds UInt32
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5326,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.489000+00:00",
    "event_record_id": 877,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DCDiscoveryTimeInMilliSeconds": 0,
    "ErrorCode": 0
  },
  "message": ""
}

References #

Event ID 5327 — Estimated network bandwidth on one of the connections: NetworkBandwidthInKbps kbps.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Estimated network bandwidth on one of the connections: NetworkBandwidthInKbps kbps.

Message #

Estimated network bandwidth on one of the connections: %1 kbps.

Fields #

NameDescription
NetworkBandwidthInKbps UInt32

Event ID 5331 — Service configuration update to standalone was attempted due to the presence of Group Policy client extension UpdateCauseExtensionName that is not part of the operating ...

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Service configuration update to standalone was attempted due to the presence of Group Policy client extension UpdateCauseExtensionName that is not part of the operating system and completed with status ErrorCode.

Message #

Service configuration update to standalone was attempted due to the presence of Group Policy client extension %1 that is not part of the operating system and completed with status %3.

Fields #

NameDescription
UpdateCauseExtensionName UnicodeString
UpdateCauseExtensionId UnicodeString
ErrorCode UInt32

Event ID 5332 — Group Policy waited for TimeWaitedAtStartup milliseconds for the Direct Access CorpNet connectivity at computer boot.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Group Policy waited for TimeWaitedAtStartup milliseconds for the Direct Access CorpNet connectivity at computer boot.

Message #

Group Policy waited for %3 milliseconds for the Direct Access CorpNet connectivity at computer boot.

Fields #

NameDescription
IsPolicyConfigured Boolean
MaxTimeToWait UInt32
TimeWaitedAtStartup UInt32
DidWaitTimeout Boolean

Event ID 5340 — The Group Policy processing mode is PolicyApplicationMode.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

The Group Policy processing mode is PolicyApplicationMode.

Message #

The Group Policy processing mode is %1.

Fields #

NameDescription
PolicyApplicationMode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5340,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:57.141137+00:00",
    "event_record_id": 1153,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyApplicationMode": 0
  },
  "message": ""
}

References #

Event ID 5351 — Group policy session returned to winlogon.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group policy session returned to winlogon.

Message #

Group policy session returned to winlogon.

Fields #

NameDescription
IsMachine Boolean
WinlogonReturnTimeElapsedInMilliseconds UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 5351,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T02:02:22.915005+00:00",
    "event_record_id": 1271,
    "correlation": {},
    "execution": {
      "process_id": 21104,
      "thread_id": 14860
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsMachine": true,
    "WinlogonReturnTimeElapsedInMilliseconds": 0
  },
  "message": ""
}

References #

Event ID 6000 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6001 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6002 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6003 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6004 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6005 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6006 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6007 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6016 — Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds milliseconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds milliseconds.

Message #

Completed %3 Extension Processing in %1 milliseconds.

Fields #

NameDescription
CSEElaspedTimeInMilliSeconds UInt32
ErrorCode UInt32
CSEExtensionName UnicodeString
CSEExtensionId GUID

Event ID 6017 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6018 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6019 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6033 — Skipped CSEExtensionName Extension based on Group Policy client-side processing rules.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Skipped CSEExtensionName Extension based on Group Policy client-side processing rules. Refer to a Resultant Set of Policy report for more information.

Message #

Skipped %1 Extension based on Group Policy client-side processing rules.  Refer to a Resultant Set of Policy report for more information.

Fields #

NameDescription
CSEExtensionName UnicodeString
CSEExtensionID UnicodeString

Event ID 6034 — Group Policy changed from synchronous foreground to asynchronous foreground based on slow link detection.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Group Policy changed from synchronous foreground to asynchronous foreground based on slow link detection.

Message #

Group Policy changed from synchronous foreground to asynchronous foreground based on slow link detection.

Event ID 6035 — CSEExtensionName Extension deferred processing until next synchronous foreground.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

CSEExtensionName Extension deferred processing until next synchronous foreground. Refer to a Resultant Set of Policy report for more information.

Message #

%1 Extension deferred processing until next synchronous foreground.  Refer to a Resultant Set of Policy report for more information.

Fields #

NameDescription
CSEExtensionName UnicodeString
CSEExtensionID UnicodeString

Event ID 6226 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6308 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6309 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6310 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6311 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6312 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6313 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6314 — Group Policy bandwidth estimation failed.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Warning

Description

Group Policy bandwidth estimation failed. Group Policy processing will continue. Assuming LinkDescription link.

Message #

Group Policy bandwidth estimation failed. Group Policy processing will continue. Assuming %6 link.

Fields #

NameDescription
BandwidthInkbps UInt32
ThresholdInkbps UInt32
PolicyApplicationMode UInt32
ErrorCode UInt32
LinkDescription UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 6314,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.507287+00:00",
    "event_record_id": 883,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "BandwidthInkbps": 1,
    "IsSlowLink": false,
    "ThresholdInkbps": 500,
    "PolicyApplicationMode": 0,
    "ErrorCode": 1,
    "LinkDescription": "%%4113"
  },
  "message": ""
}

References #

Event ID 6315 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6320 — Warning: Warning Warning code WarningDescription.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Warning: Warning Warning code WarningDescription.

Message #

Warning: %1 Warning code %2.

Fields #

NameDescription
Warning
WarningDescription UnicodeString
WarningCode UInt32

Event ID 6321 — Warning: Warning Parameter: WarningDescription : Warning code Parameter.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Warning: Warning Parameter: WarningDescription : Warning code Parameter.

Message #

Warning: %1 Parameter: %3 : Warning code %2.

Fields #

NameDescription
Warning
Parameter
WarningDescription UnicodeString
WarningCode UInt32
OperationParameter1 UnicodeString

Event ID 6322 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6323 — Group Policy dependency (DisplayName) did not start.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Group Policy dependency (DisplayName) did not start. As a result, network related features of Group Policy such as bandwidth estimation and response to network changes will not work.

Message #

Group Policy dependency (%1) did not start. As a result, network related features of Group Policy such as bandwidth estimation and response to network changes will not work.

Fields #

NameDescription
DisplayName UnicodeString

Event ID 6324 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6325 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6326 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6327 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6330 — An unfinished invocation of the Group Policy Client Side Extension InfoDescription from a previous instance of the Group Policy Service was detected.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Message #

An unfinished invocation of the Group Policy Client Side Extension %1 from a previous instance of the Group Policy Service was detected.  This may indicate that the extension caused the Group Policy Client Service to terminate unexpectedly.

Fields #

NameDescription
InfoDescription UnicodeString
OperationParameter1 UnicodeString

Event ID 6331 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Fields #

NameDescription
UpdateCauseExtensionName UnicodeString
UpdateCauseExtensionId UnicodeString
ErrorCode UInt32

Event ID 6332 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 6337 — Group Policy network connection is via Direct Access.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Group Policy network connection is via Direct Access.

Message #

Group Policy network connection is via Direct Access.

Event ID 6338 — Group Policy Winlogon status reporting has completed.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy Winlogon status reporting has completed.

Message #

Group Policy Winlogon status reporting has completed.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 6338,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T22:28:54.477711+00:00",
    "event_record_id": 461,
    "correlation": {},
    "execution": {
      "process_id": 1860,
      "thread_id": 2032
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 6339 — Group Policy Winlogon Start Shell handling completed.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational

Description

Group Policy Winlogon Start Shell handling completed.

Message #

Group Policy Winlogon Start Shell handling completed.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 6339,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T22:32:22.754428+00:00",
    "event_record_id": 509,
    "correlation": {},
    "execution": {
      "process_id": 1132,
      "thread_id": 1332
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 6341 — A Group Policy setting was used to override the fast/slow link detection.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

A Group Policy setting was used to override the fast/slow link detection.

Message #

A Group Policy setting was used to override the fast/slow link detection.

Event ID 6342 — The network connection is using a WWAN device for connectivity.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

The network connection is using a WWAN device for connectivity.

Message #

The network connection is using a WWAN device for connectivity.

Event ID 6344 — Group Policy detected a slow link during sync mode processing.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Group Policy detected a slow link during sync mode processing.

Message #

Group Policy detected a slow link during sync mode processing.

Fields #

NameDescription
IsMachine Boolean
SlowlinkThresholdInMilliseconds UInt32
DcResponseTimeInMilliseconds UInt32

Event ID 6345 — The connection to DC timed out during the Group Policy sync mode process.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

The connection to DC timed out during the Group Policy sync mode process.

Message #

The connection to DC timed out during the Group Policy sync mode process.

Fields #

NameDescription
IsMachine Boolean
DcResponseTimeInMilliseconds UInt32

Event ID 6346 — Group Policy switched the sync mode process to async mode.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Group Policy switched the sync mode process to async mode.

Message #

Group Policy switched the sync mode process to async mode.

Fields #

NameDescription
IsMachine Boolean
CSEExtensionName UnicodeString
CSEExtensionID GUID

Event ID 7000 — Computer boot policy processing failed for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Computer boot policy processing failed for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Computer boot policy processing failed for %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Event ID 7001 — User logon policy processing failed for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

User logon policy processing failed for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

User logon policy processing failed for %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Event ID 7002 — Policy processing due to network state change failed for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Policy processing due to network state change failed for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Policy processing due to network state change failed for computer %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Event ID 7003 — Policy processing due to network state change failed for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Policy processing due to network state change failed for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Policy processing due to network state change failed for user %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Event ID 7004 — Manual processing of policy failed for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Manual processing of policy failed for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Manual processing of policy failed for computer %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Event ID 7005 — Manual processing of policy failed for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Manual processing of policy failed for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Manual processing of policy failed for user %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Event ID 7006 — Periodic policy processing failed for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Periodic policy processing failed for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Periodic policy processing failed for computer %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Event ID 7007 — Periodic policy processing failed for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Periodic policy processing failed for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Periodic policy processing failed for user %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Event ID 7016 — Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds milliseconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds milliseconds.

Message #

Completed %3 Extension Processing in %1 milliseconds.

Fields #

NameDescription
CSEElaspedTimeInMilliSeconds UInt32
ErrorCode UInt32
CSEExtensionName UnicodeString
CSEExtensionId GUID

Event ID 7017 — OperationDescription Parameter The call failed after OperationElaspedTimeInMilliSeconds milliseconds.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Error

Message #

%3 
%4
The call failed after %1 milliseconds.

Fields #

NameDescription
OperationElaspedTimeInMilliSeconds UInt32
ErrorCode UInt32
OperationDescription UnicodeString
Parameter UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 7017,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T16:59:24.588821+00:00",
    "event_record_id": 562,
    "correlation": {
      "ActivityID": "178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "OperationElaspedTimeInMilliSeconds": 2000,
    "ErrorCode": 58,
    "OperationDescription": "%%4120",
    "Parameter": "WIN-FPV0DSIC9O6.lab.local"
  },
  "message": ""
}

References #

Event ID 7018 — Script for PrincipalSamName failed in ScriptElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Script for PrincipalSamName failed in ScriptElaspedTimeInSeconds seconds.

Message #

Script for %3 failed in %1 seconds.

Fields #

NameDescription
ScriptElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
ScriptType UInt32

Event ID 7019 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7117 — Group policy session completed with error.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Group policy session completed with error.

Message #

Group policy session completed with error.

Fields #

NameDescription
IsMachine Boolean
ErrorCode UInt32
SessionTimeElapsedInMilliseconds UInt32

Event ID 7126 — Group Policy could not get applicable GPOs from the domain controller.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Group Policy could not get applicable GPOs from the domain controller.

Message #

Group Policy could not get applicable GPOs from the domain controller.

Fields #

NameDescription
IsMachine Boolean
ErrorCode UInt32
GPODownloadTimeElapsedInMilliseconds UInt32

Event ID 7216 — Saved policies to the local datastore with error.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Saved policies to the local datastore with error.

Message #

Saved policies to the local datastore with error.

Fields #

NameDescription
IsMachine Boolean
ErrorCode UInt32
SessionTimeElapsedInMilliseconds UInt32

Event ID 7217 — Loaded policies from the local datastore with error.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Loaded policies from the local datastore with error.

Message #

Loaded policies from the local datastore with error.

Fields #

NameDescription
IsMachine Boolean
ErrorCode UInt32
LoadFromCacheTimeElapsedInMilliseconds UInt32

Event ID 7257 — Downloaded policies with error.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Downloaded policies with error.

Message #

Downloaded policies with error.

Fields #

NameDescription
IsMachine Boolean
ErrorCode UInt32
PolicyDownloadTimeElapsedInMilliseconds UInt32

Event ID 7308 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7309 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7310 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7311 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7312 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7313 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7314 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7315 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7320 — Error: ErrorDescription Error code ErrorCode.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Error

Description

Error: ErrorDescription Error code ErrorCode.

Message #

Error: %1 Error code %2.

Fields #

NameDescription
ErrorDescription UnicodeStringError.
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 7320,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T16:59:24.590503+00:00",
    "event_record_id": 564,
    "correlation": {
      "ActivityID": "178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ErrorDescription": "%%4125",
    "ErrorCode": 50
  },
  "message": ""
}

References #

Event ID 7321 — Error: Error Parameter: ErrorDescription : Error code Parameter.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Error: Error Parameter: ErrorDescription : Error code Parameter.

Message #

Error: %1 Parameter: %3 : Error code %2.

Fields #

NameDescription
Error
Parameter
ErrorDescription UnicodeString
ErrorCode UInt32
OperationParameter1 UnicodeString

Event ID 7322 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7323 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7324 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7325 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7326 — Group Policy failed to discover the Domain Controller details in DCDiscoveryTimeInMilliSeconds milliseconds.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Error

Description

Group Policy failed to discover the Domain Controller details in DCDiscoveryTimeInMilliSeconds milliseconds.

Message #

Group Policy failed to discover the Domain Controller details in %1 milliseconds.

Fields #

NameDescription
DCDiscoveryTimeInMilliSeconds UInt32
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 7326,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T16:59:24.588837+00:00",
    "event_record_id": 563,
    "correlation": {
      "ActivityID": "178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DCDiscoveryTimeInMilliSeconds": 4000,
    "ErrorCode": 58
  },
  "message": ""
}

References #

Event ID 7327 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 7331 — Service configuration update to standalone was attempted due to the presence of Group Policy client extension UpdateCauseExtensionName that is not part of the operating ...

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Service configuration update to standalone was attempted due to the presence of Group Policy client extension UpdateCauseExtensionName that is not part of the operating system and completed with status ErrorCode.

Message #

Service configuration update to standalone was attempted due to the presence of Group Policy client extension %1 that is not part of the operating system and completed with status %3.

Fields #

NameDescription
UpdateCauseExtensionName UnicodeString
UpdateCauseExtensionId UnicodeString
ErrorCode UInt32

Event ID 7332 — Invalid Error Message.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

Invalid Error Message.

Message #

Invalid Error Message.

Event ID 8000 — Completed computer boot policy processing for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Stop

Description

Completed computer boot policy processing for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Completed computer boot policy processing for %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 8000,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 2,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T22:32:17.445743+00:00",
    "event_record_id": 490,
    "correlation": {
      "ActivityID": "70C9A908-A206-406D-8A5D-D1CA7FEE9E13"
    },
    "execution": {
      "process_id": 1132,
      "thread_id": 1348
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyElaspedTimeInSeconds": 0,
    "ErrorCode": 0,
    "PrincipalSamName": "WORKGROUP\\WINDEV2310EVAL$",
    "IsMachine": 1,
    "IsConnectivityFailure": false
  },
  "message": ""
}

References #

Event ID 8001 — Completed user logon policy processing for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Stop

Description

Completed user logon policy processing for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Completed user logon policy processing for %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 8001,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 2,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T22:32:22.302154+00:00",
    "event_record_id": 506,
    "correlation": {
      "ActivityID": "DE67DFB7-B871-42E1-B68C-4175341DA657"
    },
    "execution": {
      "process_id": 1132,
      "thread_id": 3904
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyElaspedTimeInSeconds": 0,
    "ErrorCode": 0,
    "PrincipalSamName": "WINDEV2310EVAL\\User",
    "IsMachine": 0,
    "IsConnectivityFailure": false
  },
  "message": ""
}

References #

Event ID 8002 — Completed policy processing due to network state change for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Completed policy processing due to network state change for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Completed policy processing due to network state change for computer %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Event ID 8003 — Completed policy processing due to network state change for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Opcode
Stop

Description

Completed policy processing due to network state change for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Completed policy processing due to network state change for user %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Event ID 8004 — Completed manual processing of policy for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Stop

Description

Completed manual processing of policy for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Completed manual processing of policy for computer %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 8004,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 2,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:49:58.061228+00:00",
    "event_record_id": 1167,
    "correlation": {
      "ActivityID": "AA63BEC0-3996-4133-A97D-DB5DB9617FF3"
    },
    "execution": {
      "process_id": 8540,
      "thread_id": 9876
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyElaspedTimeInSeconds": 0,
    "ErrorCode": 0,
    "PrincipalSamName": "WORKGROUP\\WINDEV2310EVAL$",
    "IsMachine": 1,
    "IsConnectivityFailure": false
  },
  "message": ""
}

References #

Event ID 8005 — Completed manual processing of policy for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Stop

Description

Completed manual processing of policy for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Completed manual processing of policy for user %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 8005,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 2,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:34:38.174229+00:00",
    "event_record_id": 864,
    "correlation": {
      "ActivityID": "DCA9073D-A053-4D86-A71A-A22443FB751F"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 1684
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyElaspedTimeInSeconds": 0,
    "ErrorCode": 0,
    "PrincipalSamName": "SIGMA\\Administrator",
    "IsMachine": 0,
    "IsConnectivityFailure": false
  },
  "message": ""
}

References #

Event ID 8006 — Completed periodic policy processing for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

#
Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Stop

Description

Completed periodic policy processing for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Completed periodic policy processing for computer %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 8006,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 2,
    "keywords": 4611686018427387904,
    "time_created": "2022-04-07T17:39:37.570483+00:00",
    "event_record_id": 897,
    "correlation": {
      "ActivityID": "2CF6CF52-0A34-47C3-987B-53FCBD5B6234"
    },
    "execution": {
      "process_id": 1352,
      "thread_id": 4040
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyElaspedTimeInSeconds": 0,
    "ErrorCode": 0,
    "PrincipalSamName": "SIGMA\\WIN-FPV0DSIC9O6$",
    "IsMachine": 1,
    "IsConnectivityFailure": false
  },
  "message": ""
}

References #

Event ID 8007 — Completed periodic policy processing for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational
Level
Informational
Opcode
Stop

Description

Completed periodic policy processing for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.

Message #

Completed periodic policy processing for user %3 in %1 seconds.

Fields #

NameDescription
PolicyElaspedTimeInSeconds UInt32
ErrorCode UInt32
PrincipalSamName UnicodeString
IsMachine UInt32
IsConnectivityFailure Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-GroupPolicy",
    "guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
    "event_source_name": "",
    "event_id": 8007,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 2,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-14T01:40:41.669270+00:00",
    "event_record_id": 179708,
    "correlation": {
      "ActivityID": "261F3C8C-5577-42F1-99D9-89D7A88E5B00"
    },
    "execution": {
      "process_id": 1112,
      "thread_id": 6604
    },
    "channel": "Microsoft-Windows-GroupPolicy/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PolicyElaspedTimeInSeconds": 0,
    "ErrorCode": 0,
    "PrincipalSamName": "ludus\\domainadmin",
    "IsMachine": 0,
    "IsConnectivityFailure": false
  },
  "message": ""
}

Event ID 8016 — CSEExtensionName Extension (CSEExtensionId) requests a sync mode process.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

CSEExtensionName Extension (CSEExtensionId) requests a sync mode process.

Message #

%1 Extension (%2) requests a sync mode process.

Fields #

NameDescription
CSEExtensionName UnicodeString
CSEExtensionId GUID

Event ID 9001 — This machine is configured to retrieve Group Policy files from a file share in an insecure way.

Provider
Microsoft-Windows-GroupPolicy
Channel
Operational

Description

This machine is configured to retrieve Group Policy files from a file share in an insecure way.

Message #

This machine is configured to retrieve Group Policy files from a file share in an insecure way.

UNC Path: %1
Mutual Authentication Enforced: %2
Integrity Enforced: %3

Guidance: The UNC path contains logon scripts and/or files that control system security policies. Microsoft recommends configuring Windows to require both mutual authentication and integrity when accessing files on this UNC path.

For details on configuring Windows machines to require additional security when accessing specific UNC paths, visit http://support.microsoft.com/kb/3000483.

Fields #

NameDescription
UNC_Path UnicodeStringUNC Path. Contains logon scripts and/or files that control system security policies.
Mutual_Authentication_Enforced Boolean
Integrity_Enforced Boolean
UncPath UnicodeString
MutualAuthenticationEnforced Boolean
IntegrityEnforced Boolean