Microsoft-Windows-HelloForBusiness

180 events across 2 channels

Event IDTitleChannel
3045Windows Hello processing started.Operational
3052The key pre-generation pool received a request for a new key.Debug
3052The key pre-generation pool received a request for a new key.Operational
3053The key pre-generation pool needs to pre-generate a key.Debug
3053The key pre-generation pool needs to pre-generate a key.Operational
3054Windows Hello for Business prerequisites check started.Debug
3054Windows Hello for Business prerequisites check started.Operational
3055Windows Hello container provisioning started.Operational
3060Windows Hello is creating a PIN recovery key for user .Operational
3060Windows Hello is creating a PIN recovery key for user %1.Debug
3065The cloud experience host started.Operational
3066Windows Hello sign-in certificate enrollment started.Operational
3130Windows Hello PIN Recovery is attempting to change user's PIN.Debug
3130Windows Hello PIN Recovery is attempting to change user's PIN.Operational
3225Windows Hello key creation started.Operational
3510Windows Hello key registration started.Operational
3520Attempting multi-factor unlock using provider %1.Operational
3525AD/Azure AD plugin request started.Operational
3555Windows Hello container creation started.Operational
3601Windows Hello container deletion started in response to a policy change.Operational
3611Windows Hello container deletion started.Operational
5000TPM Manufacturer: %1 Version: %2 Firmware Version: %3 Is Ready: %4.Operational
5001A user signed into the device with the following information: Username: %1 User …Operational
5002A user is signing into the device with the following gesture information: Type: …Operational
5003Windows Hello for Business Policy Enforcement Information for the user %1: Use …Operational
5004Windows Hello for Business Enabled Policy successfully enforced for the user %1: …Operational
5005Operational
5005Enforcing the following Windows Hello for Business Enable Policies for the user …Debug
5050The key pre-generation pool received a request.Debug
5050The key pre-generation pool received a request.Operational
5055Windows Hello is validating that the device can satisfy all applicable policies.Operational
5060Windows Hello is checking the PIN recovery policy.Debug
5060Windows Hello is checking the PIN recovery policy.Operational
5061Windows Hello is downloading the public encryption key from the PIN recovery …Debug
5061Windows Hello is downloading the public encryption key from the PIN recovery …Operational
5062Windows Hello found a PIN recovery key for user .Operational
5062Windows Hello found a PIN recovery key for user %1.Debug
5063Windows Hello is updating the PIN recovery key for user .Operational
5063Windows Hello is updating the PIN recovery key for user %1.Debug
5064Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery …Debug
5064Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery …Operational
5204Windows Hello for Business certificate enrollment configurations: Certificate …Operational
5204Windows Hello for Business certificate enrollment configurations: Certificate …Debug
5205Windows Hello for Business On-Premise authentication configurations: Certificate …Operational
5225Creating a %1 Windows Hello key with result %2.Operational
5520Multi-factor unlock policy is not configured on this device.Operational
5555Windows Hello is validating that the device can satisfy all applicable policies.Operational
5601Windows Hello detected and ignored a policy change to delete the container at …Operational
5602Windows Hello was unable to check if there was a policy change that would …Operational
5641Windows Hello successfully updated a %1 %2 key from the Windows Hello container.Operational
5701Windows Hello read following protector properties from disk: PIN protector = %1, …Operational
5702Windows Hello wrote following protector properties to disk: PIN protector = %1, …Operational
6010A key credential was unavailable for use by an application because it did not …Operational
6045Windows Hello processing stopped with warning %1.Operational
6055Windows Hello container provisioning stopped with warning %1.Operational
6065The cloud experience host scenario stopped with warning %1.Operational
6066Windows Hello sign-in certificate enrollment was unable to enroll for a logon …Operational
6209Windows Hello for Business was unable to evaluate the presence of a certificate …Debug
6209Windows Hello for Business was unable to evaluate the presence of a certificate …Operational
6210Windows Hello for Business was unable to detect whether the user is running in a …Debug
6210Windows Hello for Business was unable to detect whether the user is running in a …Operational
6441Windows Hello for Business certificate trust and cloud trust policies are both …Operational
6520Provider is not in the acceptable provider list.Operational
6525AD/Azure AD plugin request stopped with warning %1.Operational
6611Windows Hello could not delete the container as no container currently exists …Operational
7001A user failed to sign into the device with the following information: Username: …Operational
7002Failed to load an existing Windows Hello container.Operational
7025The %1 service failed to start.Operational
7030Windows Hello failed to create the sign-in certificate request.Operational
7031Windows Hello failed to install the sign-in certificate.Operational
7032Windows Hello failed to roll back from an unsuccessful sign-in certificate …Operational
7045Windows Hello processing failed with %1.Operational
7052The new key request from the key pre-generation pool failed.Debug
7052The new key request from the key pre-generation pool failed.Operational
7053The key pre-generation pool failed to pre-generate a key.Debug
7053The key pre-generation pool failed to pre-generate a key.Operational
7054Windows Hello for Business prerequisites check failed.Debug
7054Windows Hello for Business prerequisites check failed.Operational
7055Windows Hello container provisioning failed with %1.Operational
7060Windows Hello failed to create a PIN recovery key for user %1.Operational
7065The cloud experience host scenario failed with %1.Operational
7066Windows Hello sign-in certificate enrollment failed.Operational
7067Windows Hello failed to set a certificate property on a Windows Hello key.Operational
7130Windows Hello PIN Recovery failed to change the user's PIN.Operational
7200The device registration prerequisite check failed.Debug
7200The device registration prerequisite check failed.Operational
7201The Primary Account Primary Refresh Token prerequisite check failed.Debug
7201The Primary Account Primary Refresh Token prerequisite check failed.Operational
7202The device failed to meet the Windows Hello for Business hardware requirements.Debug
7202The device failed to meet the Windows Hello for Business hardware requirements.Operational
7203Windows Hello for Business is not enabled.Debug
7203Windows Hello for Business is not enabled.Operational
7204Windows Hello for Business post-logon provisioning is not enabled.Debug
7204Windows Hello for Business post-logon provisioning is not enabled.Operational
7205Windows Hello for Business failed to locate a usable sign-in certificate …Debug
7205Windows Hello for Business failed to locate a usable sign-in certificate …Operational
7206Windows Hello for Business failed to locate a certificate registration …Debug
7206Windows Hello for Business failed to locate a certificate registration …Operational
7207Windows Hello for Business failed to locate an enterprise management client.Debug
7207Windows Hello for Business failed to locate an enterprise management client.Operational
7208Windows Hello for Business failed to locate a sign-in certificate profile.Debug
7208Windows Hello for Business failed to locate a sign-in certificate profile.Operational
7209Windows Hello for Business failed to locate a certificate payload for the …Debug
7209Windows Hello for Business failed to locate a certificate payload for the …Operational
7210Windows Hello for Business detected the user running in a remote desktop …Debug
7210Windows Hello for Business detected the user running in a remote desktop …Operational
7211The Secondary Account Primary Refresh Token prerequisite check failed.Debug
7211The Secondary Account Primary Refresh Token prerequisite check failed.Operational
7225Windows Hello key creation failed with %1.Operational
7226Windows Hello failed to delete the %1 key.Operational
7510Windows Hello key registration failed.Operational
7520Failed to authenticate the user's credential.Operational
7525AD/Azure AD plugin request failed with %1.Operational
7555Windows Hello container creation failed.Operational
7601Windows Hello failed to delete the container in response to a policy change.Operational
7611Windows Hello failed to delete the container.Operational
7621Windows Hello failed to delete the user's Windows Hello certificates.Operational
7631Windows Hello failed to delete the user's biometric enrollments.Operational
7701Windows Hello failed to use secure biometrics protector due to secret encryption …Operational
8002Successfully loaded an existing %3 Windows Hello container.Operational
8025The %1 service started successfully.Operational
8030Windows Hello created the sign-in certificate request successfully.Operational
8031Windows Hello installed the sign-in certificate successfully.Operational
8032Windows Hello successfully rolled back from an unsuccessful sign-in certificate …Operational
8045Windows Hello processing completed successfully.Operational
8052The new key request from the key pre-generation pool completed successfully.Debug
8052The new key request from the key pre-generation pool completed successfully.Operational
8053The key pre-generation pool successfully pre-generated a key.Debug
8053The key pre-generation pool successfully pre-generated a key.Operational
8054Windows Hello for Business prerequisites check completed successfully.Debug
8054Windows Hello for Business prerequisites check completed successfully.Operational
8055Windows Hello container provisioning completed successfully.Operational
8060Windows Hello successfully created a PIN recovery key for user %1.Operational
8065The cloud experience host completed successfully.Operational
8066Windows Hello sign-in certificate enrollment completed successfully.Operational
8067Windows Hello set a certificate property on a Windows Hello key.Operational
8130Windows Hello PIN Recovery successfully changed the user's PIN.Operational
8200The device registration prerequisite check completed successfully.Debug
8200The device registration prerequisite check completed successfully.Operational
8201The Primary Account Primary Refresh Token prerequisite check completed …Debug
8201The Primary Account Primary Refresh Token prerequisite check completed …Operational
8202The device meets Windows Hello for Business hardware requirements.Debug
8202The device meets Windows Hello for Business hardware requirements.Operational
8203Windows Hello for Business is enabled.Debug
8203Windows Hello for Business is enabled.Operational
8204Windows Hello for Business post-logon provisioning is enabled.Debug
8204Windows Hello for Business post-logon provisioning is enabled.Operational
8205Windows Hello for Business successfully located a usable sign-on certificate …Debug
8205Windows Hello for Business successfully located a usable sign-on certificate …Operational
8206Windows Hello for Business successfully located a certificate registration …Debug
8206Windows Hello for Business successfully located a certificate registration …Operational
8207Windows Hello for Business successfully located an enterprise management client.Debug
8207Windows Hello for Business successfully located an enterprise management client.Operational
8208Windows Hello for Business successfully located a sign-in certificate profile.Debug
8208Windows Hello for Business successfully located a sign-in certificate profile.Operational
8209Windows Hello for Business successfully located a certificate payload for the …Debug
8209Windows Hello for Business successfully located a certificate payload for the …Operational
8210Windows Hello for Business successfully completed the remote desktop …Debug
8210Windows Hello for Business successfully completed the remote desktop …Operational
8211The Secondary Account Primary Refresh Token prerequisite check completed …Debug
8211The Secondary Account Primary Refresh Token prerequisite check completed …Operational
8225Windows Hello key creation completed successfully.Operational
8226Windows Hello successfully deleted a %1 %2 key from the Windows Hello container.Operational
8510Windows Hello key registration completed successfully.Operational
8520Successfully authenticated the user's credential.Operational
8525AD/Azure AD plugin request completed successfully.Operational
8555The Windows Hello container creation completed successfully.Operational
8601Windows Hello successfully deleted the container in response to a policy change.Operational
8611Windows Hello successfully deleted the container.Operational
8621Windows Hello successfully deleted the user's Windows Hello certificates.Operational
8631Windows Hello successfully deleted the user's biometric enrollments.Operational
8632Windows Hello for Business successfully added a user entry to the Username/SID …Operational
8633Windows Hello for Business successfully removed a user entry to the Username/SID …Operational
8634Windows Hello for Business found a user entry with a duplicate SID and …Operational
8635Windows Hello for Business found a user entry with a duplicate username and …Operational
8636Windows Hello for Business found a stale SID in the Username/SID cache: …Operational
8637Windows Hello for Business found a stale username in the Username/SID cache: …Operational
8638Windows Hello for Business removed a stale SID from the Username/SID cache: …Operational
8639Windows Hello for Business removed a stale username from the Username/SID cache: …Operational
8640Windows Hello for Business PIN was changed by a user with the following …Operational

Event ID 3045 — Windows Hello processing started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello processing started.
Scenario type: %1

Fields

NameDescription
Scenario_type
HelloScenarioType

Event ID 3052 — The key pre-generation pool received a request for a new key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The key pre-generation pool received a request for a new key.

Event ID 3052 — The key pre-generation pool received a request for a new key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 3053 — The key pre-generation pool needs to pre-generate a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The key pre-generation pool needs to pre-generate a key.

Event ID 3053 — The key pre-generation pool needs to pre-generate a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 3054 — Windows Hello for Business prerequisites check started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business prerequisites check started.

Event ID 3054 — Windows Hello for Business prerequisites check started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
4
Samples
1

Example Event

system:
  provider: Microsoft-Windows-HelloForBusiness
  guid: 906B8A99-63CE-58D7-86AB-10989BBD5567
  event_source_name: ''
  event_id: 3054
  version: 0
  level: 4
  task: 12
  opcode: 10
  keywords: 9223372036854775809
  time_created: '2022-04-07T16:57:32.150039+00:00'
  event_record_id: 16
  correlation: {}
  execution:
    process_id: 4128
    thread_id: 4156
  channel: Microsoft-Windows-HelloForBusiness/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''

References

Event ID 3055 — Windows Hello container provisioning started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello container provisioning started.

Event ID 3060 — Windows Hello is creating a PIN recovery key for user .

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
UserSid

Event ID 3060 — Windows Hello is creating a PIN recovery key for user %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello is creating a PIN recovery key for user %1.

Fields

NameDescription
UserSid

Event ID 3065 — The cloud experience host started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

The cloud experience host started.
Scenario type: %1

Fields

NameDescription
Scenario_type
HelloScenarioType

Event ID 3066 — Windows Hello sign-in certificate enrollment started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello sign-in certificate enrollment started.

Event ID 3130 — Windows Hello PIN Recovery is attempting to change user's PIN.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello PIN Recovery is attempting to change user's PIN. PIN recovery type: %1.

Fields

NameDescription
PinRecoveryEntryType

Event ID 3130 — Windows Hello PIN Recovery is attempting to change user's PIN.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
PinRecoveryEntryType

Event ID 3225 — Windows Hello key creation started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello key creation started.

Event ID 3510 — Windows Hello key registration started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello key registration started.

Event ID 3520 — Attempting multi-factor unlock using provider %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Attempting multi-factor unlock using provider %1. The list of acceptable providers are:
Group A: %2
Group B: %3

Fields

NameDescription
Group_A
Group_B
MultiFactorUnlockProvider
MultiFactorUnlockGroupA
MultiFactorUnlockGroupB

Event ID 3525 — AD/Azure AD plugin request started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

AD/Azure AD plugin request started.

Event ID 3555 — Windows Hello container creation started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello container creation started.

Event ID 3601 — Windows Hello container deletion started in response to a policy change.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello container deletion started in response to a policy change.

Event ID 3611 — Windows Hello container deletion started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello container deletion started from %1.

Fields

NameDescription
CallingAppName

Event ID 5000 — TPM Manufacturer: %1 Version: %2 Firmware Version: %3 Is Ready: %4.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

TPM Manufacturer: %1
Version: %2
Firmware Version: %3
Is Ready: %4

Fields

NameDescription
TPM_Manufacturer
Version
Firmware_Version
Is_Ready
Manufacturer
FirmareVersion
IsReady

Event ID 5001 — A user signed into the device with the following information: Username: %1 User SID: %2 Credential Type: %3 Deployment Type: %4.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

A user signed into the device with the following information:

Username: %1
User SID: %2
Credential Type: %3
Deployment Type: %4

Fields

NameDescription
Username[A user signed into the device with the following information] Username.
User_SID[A user signed into the device with the following information] User SID.
Credential_Type[A user signed into the device with the following information] Credential Type.
Deployment_Type[A user signed into the device with the following information] Deployment Type.
UserName
UserSid
CredentialType
DeploymentType

Event ID 5002 — A user is signing into the device with the following gesture information: Type: %1 Subtype: %2.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

A user is signing into the device with the following gesture information:

Type: %1
Subtype: %2

Fields

NameDescription
Type[A user is signing into the device with the following gesture information] Type.
Subtype[A user is signing into the device with the following gesture information] Subtype.
GestureType
GestureSubtype

Event ID 5003 — Windows Hello for Business Policy Enforcement Information for the user %1: Use Windows Hello for Business Policy State: %2 Use Windows Hello for Bu...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business Policy Enforcement Information for the user %1:

Use Windows Hello for Business Policy State: %2
 Use Windows Hello for Business Policy Source: %3
Deployment Type: %4
Credential Type: %5
PIN Min Length: %6
PIN Max Length: %7
PIN Uppercase: %8
PIN Lowercase: %9
PIN Digits: %10
PIN Special Characters: %11
PIN Allow Sequences: %12
PIN History: %13
PIN Expiration: %14
PIN Recovery Policy State: %15
TPM Required: %16
Hardware Policy: %17
Multifactor Unlock: %18

Fields

NameDescription
UserSid
NgcEnabledPolicyState
EnabledPolicySource
DeploymentType
CredentialType
PinMinLength
PinMaxLength
PinUppercase
PinLowercase
PinDigits
PinSpecial
PinAllowSequences
PinHistory
PinExpiration
PinRecoveryPolicyState
TPMRequired
HardwarePolicy
MultifactorUnlock

Event ID 5004 — Windows Hello for Business Enabled Policy successfully enforced for the user %1: Use Windows Hello for Business Policy State: %2.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business Enabled Policy successfully enforced for the user %1:

Use Windows Hello for Business Policy State: %2

Fields

NameDescription
UserSid
NgcEnabledPolicyState

Event ID 5005 —

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
UserSid
NgcEnabledPolicyState
EnabledPolicySource
DeploymentType

Event ID 5005 — Enforcing the following Windows Hello for Business Enable Policies for the user %1: Use Windows Hello for Business Policy State: %2 Use Windows Hel...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Enforcing the following Windows Hello for Business Enable Policies for the user %1:

Use Windows Hello for Business Policy State: %2
Use Windows Hello for Business Policy Source: %3
Deployment Type: %4

Fields

NameDescription
UserSid
NgcEnabledPolicyState
EnabledPolicySource
DeploymentType

Event ID 5050 — The key pre-generation pool received a request.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The key pre-generation pool received a request.
Result: %1
Number of available keys: %2
Elapsed time: %3 seconds

Fields

NameDescription
Result
NumberOfAvailableKeys
ElapsedTime

Event ID 5050 — The key pre-generation pool received a request.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
Result
NumberOfAvailableKeys
ElapsedTime

Event ID 5055 — Windows Hello is validating that the device can satisfy all applicable policies.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello is validating that the device can satisfy all applicable policies.TPM Supported: {TpmSupport}Hardware Policy: {HardwarePolicy}Exclude TPM 1.2: {IsTpm12Excluded}TPM Version: {TpmVersion}Secure TPM: {IsTpmSecure}Insecure TPM blocked by WHfB policy: {IsInsecureTpmBlockedByWHfBPolicy}Insecure TPM blocked by TPM policy: {IsInsecureTpmBlockedByTpmPolicy}Satisfactory TPM: {IsTpmSatisfactory}TPM FIPS: {IsTpmFIPS}TPM Locked Out: {TpmSupport}0Satisfactory Key Pregeneration Pool: {TpmSupport}1Key Storage Provider: {TpmSupport}2Result: {TpmSupport}3

Fields

NameDescription
TpmSupport
HardwarePolicy
IsTpm12Excluded
TpmVersion
IsTpmSecure
IsInsecureTpmBlockedByWHfBPolicy
IsInsecureTpmBlockedByTpmPolicy
IsTpmSatisfactory
IsTpmFIPS

Event ID 5060 — Windows Hello is checking the PIN recovery policy.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello is checking the PIN recovery policy. The policy is %1 for user %2.

Fields

NameDescription
PinRecoveryPolicyState
UserSid

Event ID 5060 — Windows Hello is checking the PIN recovery policy.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
PinRecoveryPolicyState
UserSid

Event ID 5061 — Windows Hello is downloading the public encryption key from the PIN recovery service.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello is downloading the public encryption key from the PIN recovery service.

Event ID 5061 — Windows Hello is downloading the public encryption key from the PIN recovery service.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 5062 — Windows Hello found a PIN recovery key for user .

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
UserSid

Event ID 5062 — Windows Hello found a PIN recovery key for user %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello found a PIN recovery key for user %1.

Fields

NameDescription
UserSid

Event ID 5063 — Windows Hello is updating the PIN recovery key for user .

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
UserSid

Event ID 5063 — Windows Hello is updating the PIN recovery key for user %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello is updating the PIN recovery key for user %1.

Fields

NameDescription
UserSid

Event ID 5064 — Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery service.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery service.

Event ID 5064 — Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery service.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 5204 — Windows Hello for Business certificate enrollment configurations: Certificate Enrollment Method: .

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
CertificateEnrollmentMethod
CertificateRequired

Event ID 5204 — Windows Hello for Business certificate enrollment configurations: Certificate Enrollment Method: %1 Certificate Required for On-Premise Auth: %2.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business certificate enrollment configurations: 

Certificate Enrollment Method: %1
Certificate Required for On-Premise Auth: %2

Fields

NameDescription
CertificateEnrollmentMethod
CertificateRequired

Event ID 5205 — Windows Hello for Business On-Premise authentication configurations: Certificate Enrollment Method: %1 Certificate Required for On-Premise Auth: %2...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business On-Premise authentication configurations: 

Certificate Enrollment Method: %1
Certificate Required for On-Premise Auth: %2
Use Cloud Trust for On-Premise Auth: %3
Account has Cloud TGT: %4

Fields

NameDescription
CertificateEnrollmentMethod
CertificateRequired
UseCloudTrust
HasCloudTgt

Event ID 5225 — Creating a %1 Windows Hello key with result %2.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Creating a %1 Windows Hello key with result %2.

Fields

NameDescription
KeyProvider
Result

Event ID 5520 — Multi-factor unlock policy is not configured on this device.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
4
Samples
1

Message

Multi-factor unlock policy is not configured on this device.

Example Event

system:
  provider: Microsoft-Windows-HelloForBusiness
  guid: 906B8A99-63CE-58D7-86AB-10989BBD5567
  event_source_name: ''
  event_id: 5520
  version: 0
  level: 4
  task: 15
  opcode: 12
  keywords: 9223372036854775809
  time_created: '2022-04-07T16:55:39.785616+00:00'
  event_record_id: 15
  correlation: {}
  execution:
    process_id: 428
    thread_id: 1500
  channel: Microsoft-Windows-HelloForBusiness/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 5555 — Windows Hello is validating that the device can satisfy all applicable policies.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello is validating that the device can satisfy all applicable policies.

TPM Supported: %1
Hardware Policy: %2
Exclude TPM 1.2: %3
TPM Version: %4
TPM FIPS: %5
TPM Locked Out: %6
Satisfactory Key Pregeneration Pool: %7
Key Storage Provider: %8
Result: %9

Fields

NameDescription
TPM_Supported
Hardware_Policy
Exclude_TPM_12Exclude TPM 1.2.
TPM_Version
TPM_FIPS
TPM_Locked_Out
Satisfactory_Key_Pregeneration_Pool
Key_Storage_Provider
Result
TpmSupport
HardwarePolicy
IsTpm12Excluded
TpmVersion
IsTpmFIPS
IsTpmLockedOut
IsKeyPregenPoolSatisfactory
KeyProvider

Event ID 5601 — Windows Hello detected and ignored a policy change to delete the container at the user's next sign out because the user is configured to have no pa...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello detected and ignored a policy change to delete the container at the user's next sign out because the user is configured to have no password on this device.

Event ID 5602 — Windows Hello was unable to check if there was a policy change that would trigger container deletion.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello was unable to check if there was a policy change that would trigger container deletion.

Event ID 5641 — Windows Hello successfully updated a %1 %2 key from the Windows Hello container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello successfully updated a %1 %2 key from the Windows Hello container.

Key Name: %3

Fields

NameDescription
Key_Name
KeyProvider
KeyType
KeyName

Event ID 5701 — Windows Hello read following protector properties from disk: PIN protector = %1, Bio protector = %2, Secure Bio Protector = %3, Recovery protector ...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello read following protector properties from disk: PIN protector = %1, Bio protector = %2, Secure Bio Protector = %3, Recovery protector = %4, Preboot protector = %5

Fields

NameDescription
Hr
PinProtector
BioProtector
SecureBioProtector
RecoveryProtector
PrebootProtector

Event ID 5702 — Windows Hello wrote following protector properties to disk: PIN protector = %1, Bio protector = %2, Secure Bio Protector = %3, Recovery protector =...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello wrote following protector properties to disk: PIN protector = %1, Bio protector = %2, Secure Bio Protector = %3, Recovery protector = %4, Preboot protector = %5

Fields

NameDescription
Hr
PinProtector
BioProtector
SecureBioProtector
RecoveryProtector
PrebootProtector

Event ID 6010 — A key credential was unavailable for use by an application because it did not meet all the requirements for use.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

A key credential was unavailable for use by an application because it did not meet all the requirements for use.

Key name: %1
Reason: %2

Fields

NameDescription
Key_name
Reason
KeyName
KeyUseCredUnavailableReason

Event ID 6045 — Windows Hello processing stopped with warning %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello processing stopped with warning %1.
Processing time: %2 seconds

Fields

NameDescription
Processing_time
Error
ProcessingTime

Event ID 6055 — Windows Hello container provisioning stopped with warning %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello container provisioning stopped with warning %1.
Processing time: %2 seconds

Fields

NameDescription
Processing_time
Error
ProcessingTime

Event ID 6065 — The cloud experience host scenario stopped with warning %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

The cloud experience host scenario stopped with warning %1.
Processing time: %2 seconds

Fields

NameDescription
Processing_time
Error
ProcessingTime

Event ID 6066 — Windows Hello sign-in certificate enrollment was unable to enroll for a logon certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello sign-in certificate enrollment was unable to enroll for a logon certificate. Automatic certificate enrollment will retry at regular intervals.
Error: %1
Processing time: %2 seconds

Fields

NameDescription
Error
Processing_time
ProcessingTime

Event ID 6209 — Windows Hello for Business was unable to evaluate the presence of a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business was unable to evaluate the presence of a certificate payload for the sign-in certificate.

Event ID 6209 — Windows Hello for Business was unable to evaluate the presence of a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 6210 — Windows Hello for Business was unable to detect whether the user is running in a remote desktop session.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business was unable to detect whether the user is running in a remote desktop session.

Event ID 6210 — Windows Hello for Business was unable to detect whether the user is running in a remote desktop session.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 6441 — Windows Hello for Business certificate trust and cloud trust policies are both enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business certificate trust and cloud trust policies are both enabled.

Certificate trust policy will be enforced.

Event ID 6520 — Provider is not in the acceptable provider list.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Provider is not in the acceptable provider list.

Event ID 6525 — AD/Azure AD plugin request stopped with warning %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

AD/Azure AD plugin request stopped with warning %1.
Processing time: %2 seconds

Fields

NameDescription
Processing_time
Error
ProcessingTime

Event ID 6611 — Windows Hello could not delete the container as no container currently exists for the user.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello could not delete the container as no container currently exists for the user.

Event ID 7001 — A user failed to sign into the device with the following information: Username: %1 User SID: %2 Credential Type: %3 Deployment Type: %4 Software Lo...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

A user failed to sign into the device with the following information:

Username: %1
User SID: %2
Credential Type: %3
Deployment Type: %4
Software Lockout Counter: %5
Authentication Error Status: %6
Authentication Error Substatus: %7

Fields

NameDescription
Username[A user failed to sign into the device with the following information] Username.
User_SID[A user failed to sign into the device with the following information] User SID.
Credential_Type[A user failed to sign into the device with the following information] Credential Type.
Deployment_Type[A user failed to sign into the device with the following information] Deployment Type.
Software_Lockout_Counter[A user failed to sign into the device with the following information] Software Lockout Counter.
Authentication_Error_Status[A user failed to sign into the device with the following information] Authentication Error Status.
Authentication_Error_Substatus[A user failed to sign into the device with the following information] Authentication Error Substatus.
UserName
UserSid
CredentialType
DeploymentType
SoftwareLockoutCounter
AuthenticationErrorStatus
AuthenticationErrorSubStatus

Event ID 7002 — Failed to load an existing Windows Hello container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Failed to load an existing Windows Hello container.

ID: %1
Error: %2

Fields

NameDescription
ID
Error
ContainerId

Event ID 7025 — The %1 service failed to start.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

The %1 service failed to start.
Error: %2.

Fields

NameDescription
Error
ServiceName

Event ID 7030 — Windows Hello failed to create the sign-in certificate request.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to create the sign-in certificate request.
Error: %1

Fields

NameDescription
Error

Event ID 7031 — Windows Hello failed to install the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to install the sign-in certificate.
Error: %1

Fields

NameDescription
Error

Event ID 7032 — Windows Hello failed to roll back from an unsuccessful sign-in certificate enrollment.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to roll back from an unsuccessful sign-in certificate enrollment.
Error: %1

Fields

NameDescription
Error

Event ID 7045 — Windows Hello processing failed with %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello processing failed with %1.
Processing time: %2 seconds

Fields

NameDescription
Processing_time
Error
ProcessingTime

Event ID 7052 — The new key request from the key pre-generation pool failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The new key request from the key pre-generation pool failed.
Error: %1
Processing time: %2 seconds.

Fields

NameDescription
Error
Processing_time
ProcessingTime

Event ID 7052 — The new key request from the key pre-generation pool failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
Error
ProcessingTime

Event ID 7053 — The key pre-generation pool failed to pre-generate a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The key pre-generation pool failed to pre-generate a key.
Error: %1
Processing time: %2 seconds.

Fields

NameDescription
Error
Processing_time
ProcessingTime

Event ID 7053 — The key pre-generation pool failed to pre-generate a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
Error
ProcessingTime

Event ID 7054 — Windows Hello for Business prerequisites check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business prerequisites check failed.

Error: %1

Fields

NameDescription
Error

Event ID 7054 — Windows Hello for Business prerequisites check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
2
Samples
1

Fields

NameDescription
Error

Example Event

system:
  provider: Microsoft-Windows-HelloForBusiness
  guid: 906B8A99-63CE-58D7-86AB-10989BBD5567
  event_source_name: ''
  event_id: 7054
  version: 0
  level: 2
  task: 12
  opcode: 11
  keywords: 9223372036854775809
  time_created: '2022-04-07T16:48:31.714659+00:00'
  event_record_id: 6
  correlation: {}
  execution:
    process_id: 4128
    thread_id: 4228
  channel: Microsoft-Windows-HelloForBusiness/Operational
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
  Error: '0x1'
message: ''

References

Event ID 7055 — Windows Hello container provisioning failed with %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello container provisioning failed with %1.
Processing time: %2 seconds

Fields

NameDescription
Processing_time
Error
ProcessingTime

Event ID 7060 — Windows Hello failed to create a PIN recovery key for user %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to create a PIN recovery key for user %1.
Error: %2 (%3)
Correlation vector: %4
Processing time: %5 seconds.

Fields

NameDescription
Error
Correlation_vector
Processing_time
UserSid
ErrorText
CorrelationVector
ProcessingTime

Event ID 7065 — The cloud experience host scenario failed with %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

The cloud experience host scenario failed with %1.
Processing time: %2 seconds

Fields

NameDescription
Processing_time
Error
ProcessingTime

Event ID 7066 — Windows Hello sign-in certificate enrollment failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello sign-in certificate enrollment failed.
Error: %1
Processing time: %2 seconds

Fields

NameDescription
Error
Processing_time
ProcessingTime

Event ID 7067 — Windows Hello failed to set a certificate property on a Windows Hello key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to set a certificate property on a Windows Hello key.

Error: %1
Key name: %2
Certificate type: %3

Fields

NameDescription
Error
Key_name
Certificate_type
KeyName
CertificateType

Event ID 7130 — Windows Hello PIN Recovery failed to change the user's PIN.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello PIN Recovery failed to change the user's PIN.
Error: %1 (%2)
Correlation vector: %3
Processing time: %4 seconds.

Fields

NameDescription
Error
Correlation_vector
Processing_time
ErrorText
CorrelationVector
ProcessingTime

Event ID 7200 — The device registration prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The device registration prerequisite check failed.

Event ID 7200 — The device registration prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 7201 — The Primary Account Primary Refresh Token prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The Primary Account Primary Refresh Token prerequisite check failed.

Event ID 7201 — The Primary Account Primary Refresh Token prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
2
Samples
1

Example Event

system:
  provider: Microsoft-Windows-HelloForBusiness
  guid: 906B8A99-63CE-58D7-86AB-10989BBD5567
  event_source_name: ''
  event_id: 7201
  version: 0
  level: 2
  task: 12
  opcode: 12
  keywords: 9223372036854775809
  time_created: '2022-04-07T16:48:31.714659+00:00'
  event_record_id: 5
  correlation: {}
  execution:
    process_id: 4128
    thread_id: 4228
  channel: Microsoft-Windows-HelloForBusiness/Operational
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''

References

Event ID 7202 — The device failed to meet the Windows Hello for Business hardware requirements.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The device failed to meet the Windows Hello for Business hardware requirements.

Event ID 7202 — The device failed to meet the Windows Hello for Business hardware requirements.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 7203 — Windows Hello for Business is not enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business is not enabled.

Event ID 7203 — Windows Hello for Business is not enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 7204 — Windows Hello for Business post-logon provisioning is not enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business post-logon provisioning is not enabled.

Event ID 7204 — Windows Hello for Business post-logon provisioning is not enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 7205 — Windows Hello for Business failed to locate a usable sign-in certificate template.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business failed to locate a usable sign-in certificate template.

Error: %1

Fields

NameDescription
Error

Event ID 7205 — Windows Hello for Business failed to locate a usable sign-in certificate template.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
Error

Event ID 7206 — Windows Hello for Business failed to locate a certificate registration authority.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business failed to locate a certificate registration authority.

Event ID 7206 — Windows Hello for Business failed to locate a certificate registration authority.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 7207 — Windows Hello for Business failed to locate an enterprise management client.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business failed to locate an enterprise management client.

Event ID 7207 — Windows Hello for Business failed to locate an enterprise management client.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 7208 — Windows Hello for Business failed to locate a sign-in certificate profile.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business failed to locate a sign-in certificate profile.

Event ID 7208 — Windows Hello for Business failed to locate a sign-in certificate profile.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 7209 — Windows Hello for Business failed to locate a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business failed to locate a certificate payload for the sign-in certificate. The SCEP Request is not available.

Event ID 7209 — Windows Hello for Business failed to locate a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 7210 — Windows Hello for Business detected the user running in a remote desktop session.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business detected the user running in a remote desktop session.

Event ID 7210 — Windows Hello for Business detected the user running in a remote desktop session.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 7211 — The Secondary Account Primary Refresh Token prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The Secondary Account Primary Refresh Token prerequisite check failed.

Event ID 7211 — The Secondary Account Primary Refresh Token prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 7225 — Windows Hello key creation failed with %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello key creation failed with %1.
Processing time: %2 seconds

Fields

NameDescription
Processing_time
Error
ProcessingTime

Event ID 7226 — Windows Hello failed to delete the %1 key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to delete the %1 key.

Key Name: %2
Error: %3

Fields

NameDescription
Key_Name
Error
KeyType
KeyName

Event ID 7510 — Windows Hello key registration failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello key registration failed.

Error: %1

Fields

NameDescription
Error

Event ID 7520 — Failed to authenticate the user's credential.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Failed to authenticate the user's credential.
Error: %1 (%2)
Correlation vector: %3
Processing time: %4 milliseconds.

Fields

NameDescription
Error
Correlation_vector
Processing_time
ErrorText
CorrelationVector
ProcessingTime

Event ID 7525 — AD/Azure AD plugin request failed with %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

AD/Azure AD plugin request failed with %1.
Processing time: %2 seconds

Fields

NameDescription
Processing_time
Error
ProcessingTime

Event ID 7555 — Windows Hello container creation failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello container creation failed.
Error: %1
Processing time: %2 seconds

Fields

NameDescription
Error
Processing_time
ProcessingTime

Event ID 7601 — Windows Hello failed to delete the container in response to a policy change.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to delete the container in response to a policy change.

Error: %1
Processing time: %2 milliseconds.

Fields

NameDescription
Error
Processing_time
ProcessingTime

Event ID 7611 — Windows Hello failed to delete the container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to delete the container.

Error: %1.

Fields

NameDescription
Error

Event ID 7621 — Windows Hello failed to delete the user's Windows Hello certificates.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to delete the user's Windows Hello certificates.

Error: %1.

Fields

NameDescription
Error

Event ID 7631 — Windows Hello failed to delete the user's biometric enrollments.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to delete the user's biometric enrollments.

Error: %1.

Fields

NameDescription
Error

Event ID 7701 — Windows Hello failed to use secure biometrics protector due to secret encryption key loss.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello failed to use secure biometrics protector due to secret encryption key loss.

Event ID 8002 — Successfully loaded an existing %3 Windows Hello container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Successfully loaded an existing %3 Windows Hello container.

ID: %1
Version: %2
Has Cached Logon Key: %4
State: %5

Fields

NameDescription
ContainerId
ContainerVersion
KeyProvider
HasCachedLogonKey
ContainerStatus

Event ID 8025 — The %1 service started successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
16
Samples
1

Message

The %1 service started successfully.

Fields

NameDescription
ServiceName

Example Event

system:
  provider: Microsoft-Windows-HelloForBusiness
  guid: 906B8A99-63CE-58D7-86AB-10989BBD5567
  event_source_name: ''
  event_id: 8025
  version: 0
  level: 16
  task: 6
  opcode: 12
  keywords: 9223372036854775809
  time_created: '2023-11-06T01:43:17.888294+00:00'
  event_record_id: 5
  correlation: {}
  execution:
    process_id: 1444
    thread_id: 14060
  channel: Microsoft-Windows-HelloForBusiness/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-19
event_data:
  ServiceName: Microsoft Passport Container
message: ''

References

Event ID 8030 — Windows Hello created the sign-in certificate request successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello created the sign-in certificate request successfully.

Event ID 8031 — Windows Hello installed the sign-in certificate successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello installed the sign-in certificate successfully.

Event ID 8032 — Windows Hello successfully rolled back from an unsuccessful sign-in certificate enrollment.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello successfully rolled back from an unsuccessful sign-in certificate enrollment.

Event ID 8045 — Windows Hello processing completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello processing completed successfully.
Processing time: %1 seconds

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8052 — The new key request from the key pre-generation pool completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The new key request from the key pre-generation pool completed successfully.
Processing time: %1 seconds.

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8052 — The new key request from the key pre-generation pool completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
ProcessingTime

Event ID 8053 — The key pre-generation pool successfully pre-generated a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The key pre-generation pool successfully pre-generated a key. 
Processing time: %1 seconds.

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8053 — The key pre-generation pool successfully pre-generated a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Fields

NameDescription
ProcessingTime

Event ID 8054 — Windows Hello for Business prerequisites check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business prerequisites check completed successfully.

Event ID 8054 — Windows Hello for Business prerequisites check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
16
Samples
1

Example Event

system:
  provider: Microsoft-Windows-HelloForBusiness
  guid: 906B8A99-63CE-58D7-86AB-10989BBD5567
  event_source_name: ''
  event_id: 8054
  version: 0
  level: 16
  task: 12
  opcode: 11
  keywords: 9223372036854775809
  time_created: '2022-04-07T16:57:32.150051+00:00'
  event_record_id: 18
  correlation: {}
  execution:
    process_id: 4128
    thread_id: 4156
  channel: Microsoft-Windows-HelloForBusiness/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''

References

Event ID 8055 — Windows Hello container provisioning completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello container provisioning completed successfully.
Processing time: %1 seconds
Existing container: %2

Fields

NameDescription
Processing_time
Existing_container
ProcessingTime
UsedExistingContainer

Event ID 8060 — Windows Hello successfully created a PIN recovery key for user %1.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello successfully created a PIN recovery key for user %1.
Processing time: %2 seconds

Fields

NameDescription
Processing_time
UserSid
ProcessingTime

Event ID 8065 — The cloud experience host completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

The cloud experience host completed successfully.
Processing time: %1 seconds

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8066 — Windows Hello sign-in certificate enrollment completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello sign-in certificate enrollment completed successfully.
Processing time: %1 seconds

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8067 — Windows Hello set a certificate property on a Windows Hello key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello set a certificate property on a Windows Hello key.

Key name: %1
Certificate type: %2

Fields

NameDescription
Key_name
Certificate_type
KeyName
CertificateType

Event ID 8130 — Windows Hello PIN Recovery successfully changed the user's PIN.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello PIN Recovery successfully changed the user's PIN.
Processing time: %1 seconds.

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8200 — The device registration prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The device registration prerequisite check completed successfully.

Event ID 8200 — The device registration prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8201 — The Primary Account Primary Refresh Token prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The Primary Account Primary Refresh Token prerequisite check completed successfully.

Event ID 8201 — The Primary Account Primary Refresh Token prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8202 — The device meets Windows Hello for Business hardware requirements.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The device meets Windows Hello for Business hardware requirements.

Event ID 8202 — The device meets Windows Hello for Business hardware requirements.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8203 — Windows Hello for Business is enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business is enabled.

Event ID 8203 — Windows Hello for Business is enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8204 — Windows Hello for Business post-logon provisioning is enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business post-logon provisioning is enabled.

Event ID 8204 — Windows Hello for Business post-logon provisioning is enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8205 — Windows Hello for Business successfully located a usable sign-on certificate template.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business successfully located a usable sign-on certificate template.

Event ID 8205 — Windows Hello for Business successfully located a usable sign-on certificate template.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8206 — Windows Hello for Business successfully located a certificate registration authority.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business successfully located a certificate registration authority.

Event ID 8206 — Windows Hello for Business successfully located a certificate registration authority.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8207 — Windows Hello for Business successfully located an enterprise management client.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business successfully located an enterprise management client.

Event ID 8207 — Windows Hello for Business successfully located an enterprise management client.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8208 — Windows Hello for Business successfully located a sign-in certificate profile.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business successfully located a sign-in certificate profile.

Event ID 8208 — Windows Hello for Business successfully located a sign-in certificate profile.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8209 — Windows Hello for Business successfully located a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business successfully located a certificate payload for the sign-in certificate. The SCEP Request is available.

Event ID 8209 — Windows Hello for Business successfully located a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8210 — Windows Hello for Business successfully completed the remote desktop prerequisite check.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

Windows Hello for Business successfully completed the remote desktop prerequisite check.

Event ID 8210 — Windows Hello for Business successfully completed the remote desktop prerequisite check.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
16
Samples
1

Example Event

system:
  provider: Microsoft-Windows-HelloForBusiness
  guid: 906B8A99-63CE-58D7-86AB-10989BBD5567
  event_source_name: ''
  event_id: 8210
  version: 0
  level: 16
  task: 12
  opcode: 12
  keywords: 9223372036854775809
  time_created: '2022-04-07T16:57:32.150041+00:00'
  event_record_id: 17
  correlation: {}
  execution:
    process_id: 4128
    thread_id: 4156
  channel: Microsoft-Windows-HelloForBusiness/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''

References

Event ID 8211 — The Secondary Account Primary Refresh Token prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug

Message

The Secondary Account Primary Refresh Token prerequisite check completed successfully.

Event ID 8211 — The Secondary Account Primary Refresh Token prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Event ID 8225 — Windows Hello key creation completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello key creation completed successfully.
Processing time: %1 seconds

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8226 — Windows Hello successfully deleted a %1 %2 key from the Windows Hello container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello successfully deleted a %1 %2 key from the Windows Hello container.

Key Name: %3

Fields

NameDescription
Key_Name
KeyProvider
KeyType
KeyName

Event ID 8510 — Windows Hello key registration completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello key registration completed successfully.

Event ID 8520 — Successfully authenticated the user's credential.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Successfully authenticated the user's credential.
Processing time: %1 milliseconds.

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8525 — AD/Azure AD plugin request completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

AD/Azure AD plugin request completed successfully.
Processing time: %1 seconds

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8555 — The Windows Hello container creation completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

The Windows Hello container creation completed successfully.
Processing time: %1 seconds

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8601 — Windows Hello successfully deleted the container in response to a policy change.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello successfully deleted the container in response to a policy change.

Processing time: %1 milliseconds.

Fields

NameDescription
Processing_time
ProcessingTime

Event ID 8611 — Windows Hello successfully deleted the container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello successfully deleted the container.

Event ID 8621 — Windows Hello successfully deleted the user's Windows Hello certificates.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello successfully deleted the user's Windows Hello certificates.

Event ID 8631 — Windows Hello successfully deleted the user's biometric enrollments.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello successfully deleted the user's biometric enrollments.

Event ID 8632 — Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information: Username: %1 User SID: %2 Doma...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information: 

Username: %1
User SID: %2
Domain: %3
User-Entered: %4

Fields

NameDescription
Username[Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information] Username.
User_SID[Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information] User SID.
Domain[Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information] Domain.
UserEntered[Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information] User-Entered.
UserName
UserSid

Event ID 8633 — Windows Hello for Business successfully removed a user entry to the Username/SID cache with the following information: User SID.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business successfully removed a user entry to the Username/SID cache with the following information: 

User SID: %1

Fields

NameDescription
User_SID[Windows Hello for Business successfully removed a user entry to the Username/SID cache with the following information] User SID.
UserSid

Event ID 8634 — Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache: User S...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache: 

User SID: %1
Username: %2
Unused Username: %3

Fields

NameDescription
User_SID[Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache] User SID.
Username[Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache] Username.
Unused_Username[Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache] Unused Username.
UserSid
UserName
UnusedUserName

Event ID 8635 — Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache: Userna...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache: 

Username: %1
User SID: %2
Unused User SID: %3

Fields

NameDescription
Username[Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache] Username.
User_SID[Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache] User SID.
Unused_User_SID[Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache] Unused User SID.
UserName
UserSid
UnusedUserSid

Event ID 8636 — Windows Hello for Business found a stale SID in the Username/SID cache: Username: %1 User SID: %2 Stale User SID: %3.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business found a stale SID in the Username/SID cache: 

Username: %1
User SID: %2
Stale User SID: %3

Fields

NameDescription
Username[Windows Hello for Business found a stale SID in the Username/SID cache] Username.
User_SID[Windows Hello for Business found a stale SID in the Username/SID cache] User SID.
Stale_User_SID[Windows Hello for Business found a stale SID in the Username/SID cache] Stale User SID.
UserName
CurrentlyMostRecentUserSid
StaleUserSid

Event ID 8637 — Windows Hello for Business found a stale username in the Username/SID cache: User SID: %1 Username: %2 Stale Username: %3.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business found a stale username in the Username/SID cache: 

User SID: %1
Username: %2
Stale Username: %3

Fields

NameDescription
User_SID[Windows Hello for Business found a stale username in the Username/SID cache] User SID.
Username[Windows Hello for Business found a stale username in the Username/SID cache] Username.
Stale_Username[Windows Hello for Business found a stale username in the Username/SID cache] Stale Username.
UserSid
CurrentlyMostRecentUserName
StaleUserName

Event ID 8638 — Windows Hello for Business removed a stale SID from the Username/SID cache: Stale User SID.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business removed a stale SID from the Username/SID cache: 

Stale User SID: %1

Fields

NameDescription
Stale_User_SID[Windows Hello for Business removed a stale SID from the Username/SID cache] Stale User SID.
StaleUserSid

Event ID 8639 — Windows Hello for Business removed a stale username from the Username/SID cache: User SID: %1 Stale Username: %2.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business removed a stale username from the Username/SID cache: 

User SID: %1
Stale Username: %2

Fields

NameDescription
User_SID[Windows Hello for Business removed a stale username from the Username/SID cache] User SID.
Stale_Username[Windows Hello for Business removed a stale username from the Username/SID cache] Stale Username.
UserSid
StaleUserName

Event ID 8640 — Windows Hello for Business PIN was changed by a user with the following information: User SID.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message

Windows Hello for Business PIN was changed by a user with the following information: 
User SID: %1

Fields

NameDescription
User_SID[Windows Hello for Business PIN was changed by a user with the following information] User SID.
UserSid