Microsoft-Windows-HelloForBusiness

180 events across 2 channels

Event IDTitleChannel
3045Windows Hello processing started.Operational
3052The key pre-generation pool received a request for a new key.Debug
3052The key pre-generation pool received a request for a new key.Operational
3053The key pre-generation pool needs to pre-generate a key.Debug
3053The key pre-generation pool needs to pre-generate a key.Operational
3054Windows Hello for Business prerequisites check started.Debug
3054Windows Hello for Business prerequisites check started.Operational
3055Windows Hello container provisioning started.Operational
3060Windows Hello is creating a PIN recovery key for user UserSid.Debug
3060Windows Hello is creating a PIN recovery key for user .Operational
3065The cloud experience host started.Operational
3066Windows Hello sign-in certificate enrollment started.Operational
3130Windows Hello PIN Recovery is attempting to change user's PIN.Debug
3130Windows Hello PIN Recovery is attempting to change user's PIN.Operational
3225Windows Hello key creation started.Operational
3510Windows Hello key registration started.Operational
3520Attempting multi-factor unlock using provider Group_A.Operational
3525AD/Azure AD plugin request started.Operational
3555Windows Hello container creation started.Operational
3601Windows Hello container deletion started in response to a policy change.Operational
3611Windows Hello container deletion started from CallingAppName.Operational
5000TPM Manufacturer: TPM_Manufacturer.Operational
5001A user signed into the device with the following information.Operational
5002A user is signing into the device with the following gesture information.Operational
5003Windows Hello for Business Policy Enforcement Information for the user UserSid.Operational
5004Windows Hello for Business Enabled Policy successfully enforced for the user …Operational
5005Enforcing the following Windows Hello for Business Enable Policies for the user …Debug
5005Operational
5050The key pre-generation pool received a request.Debug
5050The key pre-generation pool received a request.Operational
5055Windows Hello is validating that the device can satisfy all applicable policies.Operational
5060Windows Hello is checking the PIN recovery policy.Debug
5060Windows Hello is checking the PIN recovery policy.Operational
5061Windows Hello is downloading the public encryption key from the PIN recovery …Debug
5061Windows Hello is downloading the public encryption key from the PIN recovery …Operational
5062Windows Hello found a PIN recovery key for user UserSid.Debug
5062Windows Hello found a PIN recovery key for user .Operational
5063Windows Hello is updating the PIN recovery key for user UserSid.Debug
5063Windows Hello is updating the PIN recovery key for user .Operational
5064Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery …Debug
5064Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery …Operational
5204Windows Hello for Business certificate enrollment configurations.Debug
5204Windows Hello for Business certificate enrollment configurations.Operational
5205Windows Hello for Business On-Premise authentication configurations.Operational
5225Creating a KeyProvider Windows Hello key with result Result.Operational
5520Multi-factor unlock policy is not configured on this device.Operational
5555Windows Hello is validating that the device can satisfy all applicable policies.Operational
5601Windows Hello detected and ignored a policy change to delete the container at …Operational
5602Windows Hello was unable to check if there was a policy change that would …Operational
5641Windows Hello successfully updated a Key_Name KeyProvider key from the Windows …Operational
5701Windows Hello read following protector properties from disk: PIN protector = Hr, …Operational
5702Windows Hello wrote following protector properties to disk: PIN protector = Hr, …Operational
6010A key credential was unavailable for use by an application because it did not …Operational
6045Windows Hello processing stopped with warning Processing_time.Operational
6055Windows Hello container provisioning stopped with warning Processing_time.Operational
6065The cloud experience host scenario stopped with warning Processing_time.Operational
6066Windows Hello sign-in certificate enrollment was unable to enroll for a logon …Operational
6209Windows Hello for Business was unable to evaluate the presence of a certificate …Debug
6209Windows Hello for Business was unable to evaluate the presence of a certificate …Operational
6210Windows Hello for Business was unable to detect whether the user is running in a …Debug
6210Windows Hello for Business was unable to detect whether the user is running in a …Operational
6441Windows Hello for Business certificate trust and cloud trust policies are both …Operational
6520Provider is not in the acceptable provider list.Operational
6525AD/Azure AD plugin request stopped with warning Processing_time.Operational
6611Windows Hello could not delete the container as no container currently exists …Operational
7001A user failed to sign into the device with the following information.Operational
7002Failed to load an existing Windows Hello container.Operational
7025The Error service failed to start.Operational
7030Windows Hello failed to create the sign-in certificate request.Operational
7031Windows Hello failed to install the sign-in certificate.Operational
7032Windows Hello failed to roll back from an unsuccessful sign-in certificate …Operational
7045Windows Hello processing failed with Processing_time.Operational
7052The new key request from the key pre-generation pool failed.Debug
7052The new key request from the key pre-generation pool failed.Operational
7053The key pre-generation pool failed to pre-generate a key.Debug
7053The key pre-generation pool failed to pre-generate a key.Operational
7054Windows Hello for Business prerequisites check failed.Debug
7054Windows Hello for Business prerequisites check failed.Operational
7055Windows Hello container provisioning failed with Processing_time.Operational
7060Windows Hello failed to create a PIN recovery key for user Error.Operational
7065The cloud experience host scenario failed with Processing_time.Operational
7066Windows Hello sign-in certificate enrollment failed.Operational
7067Windows Hello failed to set a certificate property on a Windows Hello key.Operational
7130Windows Hello PIN Recovery failed to change the user's PIN.Operational
7200The device registration prerequisite check failed.Debug
7200The device registration prerequisite check failed.Operational
7201The Primary Account Primary Refresh Token prerequisite check failed.Debug
7201The Primary Account Primary Refresh Token prerequisite check failed.Operational
7202The device failed to meet the Windows Hello for Business hardware requirements.Debug
7202The device failed to meet the Windows Hello for Business hardware requirements.Operational
7203Windows Hello for Business is not enabled.Debug
7203Windows Hello for Business is not enabled.Operational
7204Windows Hello for Business post-logon provisioning is not enabled.Debug
7204Windows Hello for Business post-logon provisioning is not enabled.Operational
7205Windows Hello for Business failed to locate a usable sign-in certificate …Debug
7205Windows Hello for Business failed to locate a usable sign-in certificate …Operational
7206Windows Hello for Business failed to locate a certificate registration …Debug
7206Windows Hello for Business failed to locate a certificate registration …Operational
7207Windows Hello for Business failed to locate an enterprise management client.Debug
7207Windows Hello for Business failed to locate an enterprise management client.Operational
7208Windows Hello for Business failed to locate a sign-in certificate profile.Debug
7208Windows Hello for Business failed to locate a sign-in certificate profile.Operational
7209Windows Hello for Business failed to locate a certificate payload for the …Debug
7209Windows Hello for Business failed to locate a certificate payload for the …Operational
7210Windows Hello for Business detected the user running in a remote desktop …Debug
7210Windows Hello for Business detected the user running in a remote desktop …Operational
7211The Secondary Account Primary Refresh Token prerequisite check failed.Debug
7211The Secondary Account Primary Refresh Token prerequisite check failed.Operational
7225Windows Hello key creation failed with Processing_time.Operational
7226Windows Hello failed to delete the Key_Name key.Operational
7510Windows Hello key registration failed.Operational
7520Failed to authenticate the user's credential.Operational
7525AD/Azure AD plugin request failed with Processing_time.Operational
7555Windows Hello container creation failed.Operational
7601Windows Hello failed to delete the container in response to a policy change.Operational
7611Windows Hello failed to delete the container.Operational
7621Windows Hello failed to delete the user's Windows Hello certificates.Operational
7631Windows Hello failed to delete the user's biometric enrollments.Operational
7701Windows Hello failed to use secure biometrics protector due to secret encryption …Operational
8002Successfully loaded an existing KeyProvider Windows Hello container.Operational
8025The ServiceName service started successfully.Operational
8030Windows Hello created the sign-in certificate request successfully.Operational
8031Windows Hello installed the sign-in certificate successfully.Operational
8032Windows Hello successfully rolled back from an unsuccessful sign-in certificate …Operational
8045Windows Hello processing completed successfully.Operational
8052The new key request from the key pre-generation pool completed successfully.Debug
8052The new key request from the key pre-generation pool completed successfully.Operational
8053The key pre-generation pool successfully pre-generated a key.Debug
8053The key pre-generation pool successfully pre-generated a key.Operational
8054Windows Hello for Business prerequisites check completed successfully.Debug
8054Windows Hello for Business prerequisites check completed successfully.Operational
8055Windows Hello container provisioning completed successfully.Operational
8060Windows Hello successfully created a PIN recovery key for user Processing_time.Operational
8065The cloud experience host completed successfully.Operational
8066Windows Hello sign-in certificate enrollment completed successfully.Operational
8067Windows Hello set a certificate property on a Windows Hello key.Operational
8130Windows Hello PIN Recovery successfully changed the user's PIN.Operational
8200The device registration prerequisite check completed successfully.Debug
8200The device registration prerequisite check completed successfully.Operational
8201The Primary Account Primary Refresh Token prerequisite check completed …Debug
8201The Primary Account Primary Refresh Token prerequisite check completed …Operational
8202The device meets Windows Hello for Business hardware requirements.Debug
8202The device meets Windows Hello for Business hardware requirements.Operational
8203Windows Hello for Business is enabled.Debug
8203Windows Hello for Business is enabled.Operational
8204Windows Hello for Business post-logon provisioning is enabled.Debug
8204Windows Hello for Business post-logon provisioning is enabled.Operational
8205Windows Hello for Business successfully located a usable sign-on certificate …Debug
8205Windows Hello for Business successfully located a usable sign-on certificate …Operational
8206Windows Hello for Business successfully located a certificate registration …Debug
8206Windows Hello for Business successfully located a certificate registration …Operational
8207Windows Hello for Business successfully located an enterprise management client.Debug
8207Windows Hello for Business successfully located an enterprise management client.Operational
8208Windows Hello for Business successfully located a sign-in certificate profile.Debug
8208Windows Hello for Business successfully located a sign-in certificate profile.Operational
8209Windows Hello for Business successfully located a certificate payload for the …Debug
8209Windows Hello for Business successfully located a certificate payload for the …Operational
8210Windows Hello for Business successfully completed the remote desktop …Debug
8210Windows Hello for Business successfully completed the remote desktop …Operational
8211The Secondary Account Primary Refresh Token prerequisite check completed …Debug
8211The Secondary Account Primary Refresh Token prerequisite check completed …Operational
8225Windows Hello key creation completed successfully.Operational
8226Windows Hello successfully deleted a Key_Name KeyProvider key from the Windows …Operational
8510Windows Hello key registration completed successfully.Operational
8520Successfully authenticated the user's credential.Operational
8525AD/Azure AD plugin request completed successfully.Operational
8555The Windows Hello container creation completed successfully.Operational
8601Windows Hello successfully deleted the container in response to a policy change.Operational
8611Windows Hello successfully deleted the container.Operational
8621Windows Hello successfully deleted the user's Windows Hello certificates.Operational
8631Windows Hello successfully deleted the user's biometric enrollments.Operational
8632Windows Hello for Business successfully added a user entry to the Username/SID …Operational
8633Windows Hello for Business successfully removed a user entry to the Username/SID …Operational
8634Windows Hello for Business found a user entry with a duplicate SID and …Operational
8635Windows Hello for Business found a user entry with a duplicate username and …Operational
8636Windows Hello for Business found a stale SID in the Username/SID cache.Operational
8637Windows Hello for Business found a stale username in the Username/SID cache.Operational
8638Windows Hello for Business removed a stale SID from the Username/SID cache: …Operational
8639Windows Hello for Business removed a stale username from the Username/SID cache.Operational
8640Windows Hello for Business PIN was changed by a user with the following …Operational

Event ID 3045 — Windows Hello processing started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
HelloProvisioning
Opcode
Start

Description

Windows Hello processing started.

Message #

Windows Hello processing started.
Scenario type: %1

Fields #

NameDescription
Scenario_type UInt32
HelloScenarioType UInt32

Event ID 3052 — The key pre-generation pool received a request for a new key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
KeyCreation
Opcode
Start

Description

The key pre-generation pool received a request for a new key.

Message #

The key pre-generation pool received a request for a new key.

Event ID 3052 — The key pre-generation pool received a request for a new key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyCreation
Opcode
Start

Description

The key pre-generation pool received a request for a new key.

Event ID 3053 — The key pre-generation pool needs to pre-generate a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
KeyCreation
Opcode
Start

Description

The key pre-generation pool needs to pre-generate a key.

Message #

The key pre-generation pool needs to pre-generate a key.

Event ID 3053 — The key pre-generation pool needs to pre-generate a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyCreation
Opcode
Start

Description

The key pre-generation pool needs to pre-generate a key.

Event ID 3054 — Windows Hello for Business prerequisites check started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Start

Description

Windows Hello for Business prerequisites check started.

Message #

Windows Hello for Business prerequisites check started.

Event ID 3054 — Windows Hello for Business prerequisites check started.

#
Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
Informational
Task
PrerequisitesCheck
Opcode
Start

Description

Windows Hello for Business prerequisites check started.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HelloForBusiness",
    "guid": "906B8A99-63CE-58D7-86AB-10989BBD5567",
    "event_source_name": "",
    "event_id": 3054,
    "version": 0,
    "level": 4,
    "task": 12,
    "opcode": 10,
    "keywords": 9223372036854775809,
    "time_created": "2022-04-07T16:57:32.150039+00:00",
    "event_record_id": 16,
    "correlation": {},
    "execution": {
      "process_id": 4128,
      "thread_id": 4156
    },
    "channel": "Microsoft-Windows-HelloForBusiness/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 3055 — Windows Hello container provisioning started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerCreation
Opcode
Start

Description

Windows Hello container provisioning started.

Message #

Windows Hello container provisioning started.

Event ID 3060 — Windows Hello is creating a PIN recovery key for user UserSid.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PINRecovery
Opcode
Start

Description

Windows Hello is creating a PIN recovery key for user UserSid.

Message #

Windows Hello is creating a PIN recovery key for user %1.

Fields #

NameDescription
UserSid SID

Event ID 3060 — Windows Hello is creating a PIN recovery key for user .

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PINRecovery
Opcode
Start

Description

Windows Hello is creating a PIN recovery key for user .

Fields #

NameDescription
UserSid SID

Event ID 3065 — The cloud experience host started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
HelloProvisioning
Opcode
Start

Description

The cloud experience host started.

Message #

The cloud experience host started.
Scenario type: %1

Fields #

NameDescription
Scenario_type UInt32
HelloScenarioType UInt32

Event ID 3066 — Windows Hello sign-in certificate enrollment started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
CertificateEnrollment
Opcode
Start

Description

Windows Hello sign-in certificate enrollment started.

Message #

Windows Hello sign-in certificate enrollment started.

Event ID 3130 — Windows Hello PIN Recovery is attempting to change user's PIN.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PINRecovery
Opcode
Start

Description

Windows Hello PIN Recovery is attempting to change user's PIN. PIN recovery type: PinRecoveryEntryType.

Message #

Windows Hello PIN Recovery is attempting to change user's PIN. PIN recovery type: %1.

Fields #

NameDescription
PinRecoveryEntryType UInt32

Event ID 3130 — Windows Hello PIN Recovery is attempting to change user's PIN.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PINRecovery
Opcode
Start

Description

Windows Hello PIN Recovery is attempting to change user's PIN. PIN recovery type: .

Fields #

NameDescription
PinRecoveryEntryType UInt32

Event ID 3225 — Windows Hello key creation started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyCreation
Opcode
Start

Description

Windows Hello key creation started.

Message #

Windows Hello key creation started.

Event ID 3510 — Windows Hello key registration started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyRegistration
Opcode
Start

Description

Windows Hello key registration started.

Message #

Windows Hello key registration started.

Event ID 3520 — Attempting multi-factor unlock using provider Group_A.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Multi_FactorUnlock
Opcode
Start

Description

Attempting multi-factor unlock using provider Group_A. The list of acceptable providers are.

Message #

Attempting multi-factor unlock using provider %1. The list of acceptable providers are:
Group A: %2
Group B: %3

Fields #

NameDescription
Group_A
Group_B
MultiFactorUnlockProvider UnicodeString
MultiFactorUnlockGroupA UnicodeString
MultiFactorUnlockGroupB UnicodeString

Event ID 3525 — AD/Azure AD plugin request started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
HelloProvisioning
Opcode
Start

Description

AD/Azure AD plugin request started.

Message #

AD/Azure AD plugin request started.

Event ID 3555 — Windows Hello container creation started.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerCreation
Opcode
Start

Description

Windows Hello container creation started.

Message #

Windows Hello container creation started.

Event ID 3601 — Windows Hello container deletion started in response to a policy change.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerDeletion
Opcode
Start

Description

Windows Hello container deletion started in response to a policy change.

Message #

Windows Hello container deletion started in response to a policy change.

Event ID 3611 — Windows Hello container deletion started from CallingAppName.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerDeletion
Opcode
Start

Description

Windows Hello container deletion started from CallingAppName.

Message #

Windows Hello container deletion started from %1.

Fields #

NameDescription
CallingAppName UnicodeString

Event ID 5000 — TPM Manufacturer: TPM_Manufacturer.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Opcode
Informational

Description

TPM Manufacturer: TPM_Manufacturer.

Message #

TPM Manufacturer: %1
Version: %2
Firmware Version: %3
Is Ready: %4

Fields #

NameDescription
TPM_Manufacturer UnicodeString
Version UnicodeString
Firmware_Version UnicodeString
Is_Ready Boolean
Manufacturer UnicodeString
FirmareVersion UnicodeString
IsReady Boolean

Event ID 5001 — A user signed into the device with the following information.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Opcode
Informational

Description

A user signed into the device with the following information.

Message #

A user signed into the device with the following information:

Username: %1
User SID: %2
Credential Type: %3
Deployment Type: %4

Fields #

NameDescription
Username UnicodeString[A user signed into the device with the following information] Username.
User_SID SID[A user signed into the device with the following information] User SID.
Credential_Type UInt32[A user signed into the device with the following information] Credential Type.
Deployment_Type UInt32[A user signed into the device with the following information] Deployment Type.
UserName UnicodeString
UserSid SID
CredentialType UInt32
Known values
%%8096
Default credentials
%%8097
Credentials manager
%%8098
Fresh credentials
DeploymentType UInt32

Event ID 5002 — A user is signing into the device with the following gesture information.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Opcode
Informational

Description

A user is signing into the device with the following gesture information.

Message #

A user is signing into the device with the following gesture information:

Type: %1
Subtype: %2

Fields #

NameDescription
Type HexInt32[A user is signing into the device with the following gesture information] Type.
Subtype UInt32[A user is signing into the device with the following gesture information] Subtype.
GestureType HexInt32
GestureSubtype UInt32

Event ID 5003 — Windows Hello for Business Policy Enforcement Information for the user UserSid.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PolicyEnforcement
Opcode
Informational

Description

Windows Hello for Business Policy Enforcement Information for the user UserSid.

Message #

Windows Hello for Business Policy Enforcement Information for the user %1:

Use Windows Hello for Business Policy State: %2
 Use Windows Hello for Business Policy Source: %3
Deployment Type: %4
Credential Type: %5
PIN Min Length: %6
PIN Max Length: %7
PIN Uppercase: %8
PIN Lowercase: %9
PIN Digits: %10
PIN Special Characters: %11
PIN Allow Sequences: %12
PIN History: %13
PIN Expiration: %14
PIN Recovery Policy State: %15
TPM Required: %16
Hardware Policy: %17
Multifactor Unlock: %18

Fields #

NameDescription
UserSid SID
NgcEnabledPolicyState UInt32
EnabledPolicySource UInt32
DeploymentType UInt32
CredentialType UInt32
Known values
%%8096
Default credentials
%%8097
Credentials manager
%%8098
Fresh credentials
PinMinLength UInt32
PinMaxLength UInt32
PinUppercase UInt32
PinLowercase UInt32
PinDigits UInt32
PinSpecial UInt32
PinAllowSequences Boolean
PinHistory Boolean
PinExpiration Boolean
PinRecoveryPolicyState UInt32
TPMRequired Boolean
HardwarePolicy UInt32
MultifactorUnlock Boolean

Event ID 5004 — Windows Hello for Business Enabled Policy successfully enforced for the user UserSid.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PolicyEnforcement
Opcode
Informational

Description

Windows Hello for Business Enabled Policy successfully enforced for the user UserSid.

Message #

Windows Hello for Business Enabled Policy successfully enforced for the user %1:

Use Windows Hello for Business Policy State: %2

Fields #

NameDescription
UserSid SID
NgcEnabledPolicyState UInt32

Event ID 5005 — Enforcing the following Windows Hello for Business Enable Policies for the user UserSid.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PolicyEnforcement
Opcode
Informational

Description

Enforcing the following Windows Hello for Business Enable Policies for the user UserSid.

Message #

Enforcing the following Windows Hello for Business Enable Policies for the user %1:

Use Windows Hello for Business Policy State: %2
Use Windows Hello for Business Policy Source: %3
Deployment Type: %4

Fields #

NameDescription
UserSid SID
NgcEnabledPolicyState UInt32
EnabledPolicySource UInt32
DeploymentType UInt32

Event ID 5005 —

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PolicyEnforcement
Opcode
Informational

Description

Enforcing the following Windows Hello for Business Enable Policies for the user.

Fields #

NameDescription
UserSid SID
NgcEnabledPolicyState UInt32
EnabledPolicySource UInt32
DeploymentType UInt32

Event ID 5050 — The key pre-generation pool received a request.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
KeyCreation
Opcode
Informational

Description

The key pre-generation pool received a request.

Message #

The key pre-generation pool received a request.
Result: %1
Number of available keys: %2
Elapsed time: %3 seconds

Fields #

NameDescription
Result HexInt32
NumberOfAvailableKeys UInt32
ElapsedTime UInt32

Event ID 5050 — The key pre-generation pool received a request.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyCreation
Opcode
Informational

Description

The key pre-generation pool received a request.

Fields #

NameDescription
Result HexInt32
NumberOfAvailableKeys UInt32
ElapsedTime UInt32

Event ID 5055 — Windows Hello is validating that the device can satisfy all applicable policies.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational

Message #

Windows Hello is validating that the device can satisfy all applicable policies.TPM Supported: {TpmSupport}Hardware Policy: {HardwarePolicy}Exclude TPM 1.2: {IsTpm12Excluded}TPM Version: {TpmVersion}Secure TPM: {IsTpmSecure}Insecure TPM blocked by WHfB policy: {IsInsecureTpmBlockedByWHfBPolicy}Insecure TPM blocked by TPM policy: {IsInsecureTpmBlockedByTpmPolicy}Satisfactory TPM: {IsTpmSatisfactory}TPM FIPS: {IsTpmFIPS}TPM Locked Out: {TpmSupport}0Satisfactory Key Pregeneration Pool: {TpmSupport}1Key Storage Provider: {TpmSupport}2Result: {TpmSupport}3

Fields #

NameDescription
TpmSupport
HardwarePolicy
IsTpm12Excluded
TpmVersion
IsTpmSecure
IsInsecureTpmBlockedByWHfBPolicy
IsInsecureTpmBlockedByTpmPolicy
IsTpmSatisfactory
IsTpmFIPS

Event ID 5060 — Windows Hello is checking the PIN recovery policy.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PINRecovery
Opcode
Informational

Description

Windows Hello is checking the PIN recovery policy. The policy is PinRecoveryPolicyState for user UserSid.

Message #

Windows Hello is checking the PIN recovery policy. The policy is %1 for user %2.

Fields #

NameDescription
PinRecoveryPolicyState UInt32
UserSid SID

Event ID 5060 — Windows Hello is checking the PIN recovery policy.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PINRecovery
Opcode
Informational

Description

Windows Hello is checking the PIN recovery policy. The policy is for user .

Fields #

NameDescription
PinRecoveryPolicyState UInt32
UserSid SID

Event ID 5061 — Windows Hello is downloading the public encryption key from the PIN recovery service.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PINRecovery
Opcode
Informational

Description

Windows Hello is downloading the public encryption key from the PIN recovery service.

Message #

Windows Hello is downloading the public encryption key from the PIN recovery service.

Event ID 5061 — Windows Hello is downloading the public encryption key from the PIN recovery service.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PINRecovery
Opcode
Informational

Description

Windows Hello is downloading the public encryption key from the PIN recovery service.

Event ID 5062 — Windows Hello found a PIN recovery key for user UserSid.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PINRecovery
Opcode
Informational

Description

Windows Hello found a PIN recovery key for user UserSid.

Message #

Windows Hello found a PIN recovery key for user %1.

Fields #

NameDescription
UserSid SID

Event ID 5062 — Windows Hello found a PIN recovery key for user .

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PINRecovery
Opcode
Informational

Description

Windows Hello found a PIN recovery key for user .

Fields #

NameDescription
UserSid SID

Event ID 5063 — Windows Hello is updating the PIN recovery key for user UserSid.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PINRecovery
Opcode
Informational

Description

Windows Hello is updating the PIN recovery key for user UserSid.

Message #

Windows Hello is updating the PIN recovery key for user %1.

Fields #

NameDescription
UserSid SID

Event ID 5063 — Windows Hello is updating the PIN recovery key for user .

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PINRecovery
Opcode
Informational

Description

Windows Hello is updating the PIN recovery key for user .

Fields #

NameDescription
UserSid SID

Event ID 5064 — Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery service.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PINRecovery
Opcode
Informational

Description

Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery service.

Message #

Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery service.

Event ID 5064 — Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery service.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PINRecovery
Opcode
Informational

Description

Windows Hello is uploading the encrypted PIN recovery key to the PIN recovery service.

Event ID 5204 — Windows Hello for Business certificate enrollment configurations.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business certificate enrollment configurations.

Message #

Windows Hello for Business certificate enrollment configurations: 

Certificate Enrollment Method: %1
Certificate Required for On-Premise Auth: %2

Fields #

NameDescription
CertificateEnrollmentMethod UInt32
CertificateRequired Boolean

Event ID 5204 — Windows Hello for Business certificate enrollment configurations.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business certificate enrollment configurations.

Fields #

NameDescription
CertificateEnrollmentMethod UInt32
CertificateRequired Boolean

Event ID 5205 — Windows Hello for Business On-Premise authentication configurations.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
Informational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business On-Premise authentication configurations.

Message #

Windows Hello for Business On-Premise authentication configurations: 

Certificate Enrollment Method: %1
Certificate Required for On-Premise Auth: %2
Use Cloud Trust for On-Premise Auth: %3
Account has Cloud TGT: %4

Fields #

NameDescription
CertificateEnrollmentMethod UInt32
CertificateRequired Boolean
UseCloudTrust Boolean
HasCloudTgt Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HelloForBusiness",
    "guid": "906B8A99-63CE-58D7-86AB-10989BBD5567",
    "event_source_name": "",
    "event_id": 5205,
    "version": 0,
    "level": 4,
    "task": 12,
    "opcode": 12,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-09T00:59:27.820700+00:00",
    "event_record_id": 19,
    "correlation": {},
    "execution": {
      "process_id": 9652,
      "thread_id": 9984
    },
    "channel": "Microsoft-Windows-HelloForBusiness/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "CertificateEnrollmentMethod": 0,
    "CertificateRequired": false,
    "UseCloudTrust": false,
    "HasCloudTgt": false
  },
  "message": ""
}

Event ID 5225 — Creating a KeyProvider Windows Hello key with result Result.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyCreation
Opcode
Informational

Description

Creating a KeyProvider Windows Hello key with result Result.

Message #

Creating a %1 Windows Hello key with result %2.

Fields #

NameDescription
KeyProvider UInt32
Result HexInt32

Event ID 5520 — Multi-factor unlock policy is not configured on this device.

#
Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
Informational
Task
Multi_FactorUnlock
Opcode
Informational

Description

Multi-factor unlock policy is not configured on this device.

Message #

Multi-factor unlock policy is not configured on this device.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HelloForBusiness",
    "guid": "906B8A99-63CE-58D7-86AB-10989BBD5567",
    "event_source_name": "",
    "event_id": 5520,
    "version": 0,
    "level": 4,
    "task": 15,
    "opcode": 12,
    "keywords": 9223372036854775809,
    "time_created": "2022-04-07T16:55:39.785616+00:00",
    "event_record_id": 15,
    "correlation": {},
    "execution": {
      "process_id": 428,
      "thread_id": 1500
    },
    "channel": "Microsoft-Windows-HelloForBusiness/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 5555 — Windows Hello is validating that the device can satisfy all applicable policies.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerCreation
Opcode
Informational

Description

Windows Hello is validating that the device can satisfy all applicable policies.

Message #

Windows Hello is validating that the device can satisfy all applicable policies.

TPM Supported: %1
Hardware Policy: %2
Exclude TPM 1.2: %3
TPM Version: %4
TPM FIPS: %5
TPM Locked Out: %6
Satisfactory Key Pregeneration Pool: %7
Key Storage Provider: %8
Result: %9

Fields #

NameDescription
TPM_Supported UInt32
Hardware_Policy UInt32
Exclude_TPM_12 BooleanExclude TPM 1.2.
TPM_Version UInt32
TPM_FIPS Boolean
TPM_Locked_Out Boolean
Satisfactory_Key_Pregeneration_Pool Boolean
Key_Storage_Provider UInt32
Result HexInt32
TpmSupport UInt32
HardwarePolicy UInt32
IsTpm12Excluded Boolean
TpmVersion UInt32
IsTpmFIPS Boolean
IsTpmLockedOut Boolean
IsKeyPregenPoolSatisfactory Boolean
KeyProvider UInt32

Event ID 5601 — Windows Hello detected and ignored a policy change to delete the container at the user's next sign out because the user is configured to have no pa...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerDeletion
Opcode
Informational

Description

Windows Hello detected and ignored a policy change to delete the container at the user's next sign out because the user is configured to have no password on this device.

Message #

Windows Hello detected and ignored a policy change to delete the container at the user's next sign out because the user is configured to have no password on this device.

Event ID 5602 — Windows Hello was unable to check if there was a policy change that would trigger container deletion.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerDeletion
Opcode
Informational

Description

Windows Hello was unable to check if there was a policy change that would trigger container deletion.

Message #

Windows Hello was unable to check if there was a policy change that would trigger container deletion.

Event ID 5641 — Windows Hello successfully updated a Key_Name KeyProvider key from the Windows Hello container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyUpdate
Opcode
Informational

Description

Windows Hello successfully updated a Key_Name KeyProvider key from the Windows Hello container.

Message #

Windows Hello successfully updated a %1 %2 key from the Windows Hello container.

Key Name: %3

Fields #

NameDescription
Key_Name
KeyProvider UInt32
KeyType UInt32
Known values
%%2499
Machine key
%%2500
User key
KeyName UnicodeString

Event ID 5701 — Windows Hello read following protector properties from disk: PIN protector = Hr, Bio protector = PinProtector, Secure Bio Protector = BioProtector, Recovery protector ...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ProtectorDiskIO
Opcode
Informational

Description

Windows Hello read following protector properties from disk: PIN protector = Hr, Bio protector = PinProtector, Secure Bio Protector = BioProtector, Recovery protector = SecureBioProtector, Preboot protector = RecoveryProtector.

Message #

Windows Hello read following protector properties from disk: PIN protector = %1, Bio protector = %2, Secure Bio Protector = %3, Recovery protector = %4, Preboot protector = %5

Fields #

NameDescription
Hr HexInt32
PinProtector Boolean
BioProtector Boolean
SecureBioProtector Boolean
RecoveryProtector Boolean
PrebootProtector Boolean

Event ID 5702 — Windows Hello wrote following protector properties to disk: PIN protector = Hr, Bio protector = PinProtector, Secure Bio Protector = BioProtector, Recovery protector =...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ProtectorDiskIO
Opcode
Informational

Description

Windows Hello wrote following protector properties to disk: PIN protector = Hr, Bio protector = PinProtector, Secure Bio Protector = BioProtector, Recovery protector = SecureBioProtector, Preboot protector = RecoveryProtector.

Message #

Windows Hello wrote following protector properties to disk: PIN protector = %1, Bio protector = %2, Secure Bio Protector = %3, Recovery protector = %4, Preboot protector = %5

Fields #

NameDescription
Hr HexInt32
PinProtector Boolean
BioProtector Boolean
SecureBioProtector Boolean
RecoveryProtector Boolean
PrebootProtector Boolean

Event ID 6010 — A key credential was unavailable for use by an application because it did not meet all the requirements for use.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyUse
Opcode
Informational

Description

A key credential was unavailable for use by an application because it did not meet all the requirements for use.

Message #

A key credential was unavailable for use by an application because it did not meet all the requirements for use.

Key name: %1
Reason: %2

Fields #

NameDescription
Key_name UnicodeString
Reason UInt32
KeyName UnicodeString
KeyUseCredUnavailableReason UInt32

Event ID 6045 — Windows Hello processing stopped with warning Processing_time.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
HelloProvisioning
Opcode
Stop

Description

Windows Hello processing stopped with warning Processing_time.

Message #

Windows Hello processing stopped with warning %1.
Processing time: %2 seconds

Fields #

NameDescription
Processing_time
Error HexInt32
ProcessingTime UInt32

Event ID 6055 — Windows Hello container provisioning stopped with warning Processing_time.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerCreation
Opcode
Stop

Description

Windows Hello container provisioning stopped with warning Processing_time.

Message #

Windows Hello container provisioning stopped with warning %1.
Processing time: %2 seconds

Fields #

NameDescription
Processing_time
Error HexInt32
ProcessingTime UInt32

Event ID 6065 — The cloud experience host scenario stopped with warning Processing_time.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
HelloProvisioning
Opcode
Stop

Description

The cloud experience host scenario stopped with warning Processing_time.

Message #

The cloud experience host scenario stopped with warning %1.
Processing time: %2 seconds

Fields #

NameDescription
Processing_time
Error UnicodeString
ProcessingTime UInt32

Event ID 6066 — Windows Hello sign-in certificate enrollment was unable to enroll for a logon certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
CertificateEnrollment
Opcode
Stop

Description

Windows Hello sign-in certificate enrollment was unable to enroll for a logon certificate. Automatic certificate enrollment will retry at regular intervals.

Message #

Windows Hello sign-in certificate enrollment was unable to enroll for a logon certificate. Automatic certificate enrollment will retry at regular intervals.
Error: %1
Processing time: %2 seconds

Fields #

NameDescription
Error HexInt32
Processing_time UInt32
ProcessingTime UInt32

Event ID 6209 — Windows Hello for Business was unable to evaluate the presence of a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business was unable to evaluate the presence of a certificate payload for the sign-in certificate.

Message #

Windows Hello for Business was unable to evaluate the presence of a certificate payload for the sign-in certificate.

Event ID 6209 — Windows Hello for Business was unable to evaluate the presence of a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business was unable to evaluate the presence of a certificate payload for the sign-in certificate.

Event ID 6210 — Windows Hello for Business was unable to detect whether the user is running in a remote desktop session.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business was unable to detect whether the user is running in a remote desktop session.

Message #

Windows Hello for Business was unable to detect whether the user is running in a remote desktop session.

Event ID 6210 — Windows Hello for Business was unable to detect whether the user is running in a remote desktop session.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business was unable to detect whether the user is running in a remote desktop session.

Event ID 6441 — Windows Hello for Business certificate trust and cloud trust policies are both enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
QueryPolicy
Opcode
Informational

Description

Windows Hello for Business certificate trust and cloud trust policies are both enabled.

Message #

Windows Hello for Business certificate trust and cloud trust policies are both enabled.

Certificate trust policy will be enforced.

Event ID 6520 — Provider is not in the acceptable provider list.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Multi_FactorUnlock
Opcode
Stop

Description

Provider is not in the acceptable provider list.

Message #

Provider is not in the acceptable provider list.

Event ID 6525 — AD/Azure AD plugin request stopped with warning Processing_time.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
HelloProvisioning
Opcode
Stop

Description

AD/Azure AD plugin request stopped with warning Processing_time.

Message #

AD/Azure AD plugin request stopped with warning %1.
Processing time: %2 seconds

Fields #

NameDescription
Processing_time
Error HexInt32
ProcessingTime UInt32

Event ID 6611 — Windows Hello could not delete the container as no container currently exists for the user.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerDeletion
Opcode
Stop

Description

Windows Hello could not delete the container as no container currently exists for the user.

Message #

Windows Hello could not delete the container as no container currently exists for the user.

Event ID 7001 — A user failed to sign into the device with the following information.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Opcode
Informational

Description

A user failed to sign into the device with the following information.

Message #

A user failed to sign into the device with the following information:

Username: %1
User SID: %2
Credential Type: %3
Deployment Type: %4
Software Lockout Counter: %5
Authentication Error Status: %6
Authentication Error Substatus: %7

Fields #

NameDescription
Username UnicodeString[A user failed to sign into the device with the following information] Username.
User_SID SID[A user failed to sign into the device with the following information] User SID.
Credential_Type UInt32[A user failed to sign into the device with the following information] Credential Type.
Deployment_Type UInt32[A user failed to sign into the device with the following information] Deployment Type.
Software_Lockout_Counter UInt32[A user failed to sign into the device with the following information] Software Lockout Counter.
Authentication_Error_Status HexInt32[A user failed to sign into the device with the following information] Authentication Error Status.
Authentication_Error_Substatus HexInt32[A user failed to sign into the device with the following information] Authentication Error Substatus.
UserName UnicodeString
UserSid SID
CredentialType UInt32
Known values
%%8096
Default credentials
%%8097
Credentials manager
%%8098
Fresh credentials
DeploymentType UInt32
SoftwareLockoutCounter UInt32
AuthenticationErrorStatus HexInt32
AuthenticationErrorSubStatus HexInt32

Event ID 7002 — Failed to load an existing Windows Hello container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerLoad
Opcode
Informational

Description

Failed to load an existing Windows Hello container.

Message #

Failed to load an existing Windows Hello container.

ID: %1
Error: %2

Fields #

NameDescription
ID GUID
Error HexInt32
ContainerId GUID

Event ID 7025 — The Error service failed to start.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ServiceStart
Opcode
Informational

Description

The Error service failed to start.

Message #

The %1 service failed to start.
Error: %2.

Fields #

NameDescription
Error HexInt32
ServiceName UnicodeString

Event ID 7030 — Windows Hello failed to create the sign-in certificate request.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Opcode
Informational

Description

Windows Hello failed to create the sign-in certificate request.

Message #

Windows Hello failed to create the sign-in certificate request.
Error: %1

Fields #

NameDescription
Error HexInt32

Event ID 7031 — Windows Hello failed to install the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Opcode
Informational

Description

Windows Hello failed to install the sign-in certificate.

Message #

Windows Hello failed to install the sign-in certificate.
Error: %1

Fields #

NameDescription
Error HexInt32

Event ID 7032 — Windows Hello failed to roll back from an unsuccessful sign-in certificate enrollment.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Opcode
Informational

Description

Windows Hello failed to roll back from an unsuccessful sign-in certificate enrollment.

Message #

Windows Hello failed to roll back from an unsuccessful sign-in certificate enrollment.
Error: %1

Fields #

NameDescription
Error HexInt32

Event ID 7045 — Windows Hello processing failed with Processing_time.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
HelloProvisioning
Opcode
Stop

Description

Windows Hello processing failed with Processing_time.

Message #

Windows Hello processing failed with %1.
Processing time: %2 seconds

Fields #

NameDescription
Processing_time
Error HexInt32
ProcessingTime UInt32

Event ID 7052 — The new key request from the key pre-generation pool failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
KeyCreation
Opcode
Stop

Description

The new key request from the key pre-generation pool failed.

Message #

The new key request from the key pre-generation pool failed.
Error: %1
Processing time: %2 seconds.

Fields #

NameDescription
Error HexInt32
Processing_time UInt32
ProcessingTime UInt32

Event ID 7052 — The new key request from the key pre-generation pool failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyCreation
Opcode
Stop

Description

The new key request from the key pre-generation pool failed.

Fields #

NameDescription
Error HexInt32
ProcessingTime UInt32

Event ID 7053 — The key pre-generation pool failed to pre-generate a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
KeyCreation
Opcode
Stop

Description

The key pre-generation pool failed to pre-generate a key.

Message #

The key pre-generation pool failed to pre-generate a key.
Error: %1
Processing time: %2 seconds.

Fields #

NameDescription
Error HexInt32
Processing_time UInt32
ProcessingTime UInt32

Event ID 7053 — The key pre-generation pool failed to pre-generate a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyCreation
Opcode
Stop

Description

The key pre-generation pool failed to pre-generate a key.

Fields #

NameDescription
Error HexInt32
ProcessingTime UInt32

Event ID 7054 — Windows Hello for Business prerequisites check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Stop

Description

Windows Hello for Business prerequisites check failed.

Message #

Windows Hello for Business prerequisites check failed.

Error: %1

Fields #

NameDescription
Error HexInt32

Event ID 7054 — Windows Hello for Business prerequisites check failed.

#
Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
Error
Task
PrerequisitesCheck
Opcode
Stop

Description

Windows Hello for Business prerequisites check failed.

Fields #

NameDescription
Error HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HelloForBusiness",
    "guid": "906B8A99-63CE-58D7-86AB-10989BBD5567",
    "event_source_name": "",
    "event_id": 7054,
    "version": 0,
    "level": 2,
    "task": 12,
    "opcode": 11,
    "keywords": 9223372036854775809,
    "time_created": "2022-04-07T16:48:31.714659+00:00",
    "event_record_id": 6,
    "correlation": {},
    "execution": {
      "process_id": 4128,
      "thread_id": 4228
    },
    "channel": "Microsoft-Windows-HelloForBusiness/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "Error": "0x1"
  },
  "message": ""
}

References #

Event ID 7055 — Windows Hello container provisioning failed with Processing_time.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerCreation
Opcode
Stop

Description

Windows Hello container provisioning failed with Processing_time.

Message #

Windows Hello container provisioning failed with %1.
Processing time: %2 seconds

Fields #

NameDescription
Processing_time
Error HexInt32
ProcessingTime UInt32

Event ID 7060 — Windows Hello failed to create a PIN recovery key for user Error.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PINRecovery
Opcode
Stop

Description

Windows Hello failed to create a PIN recovery key for user Error.

Message #

Windows Hello failed to create a PIN recovery key for user %1.
Error: %2 (%3)
Correlation vector: %4
Processing time: %5 seconds.

Fields #

NameDescription
Error HexInt32
Correlation_vector
Processing_time
UserSid SID
ErrorText UnicodeString
CorrelationVector AnsiString
ProcessingTime UInt32

Event ID 7065 — The cloud experience host scenario failed with Processing_time.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
HelloProvisioning
Opcode
Stop

Description

The cloud experience host scenario failed with Processing_time.

Message #

The cloud experience host scenario failed with %1.
Processing time: %2 seconds

Fields #

NameDescription
Processing_time
Error UnicodeString
ProcessingTime UInt32

Event ID 7066 — Windows Hello sign-in certificate enrollment failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
CertificateEnrollment
Opcode
Stop

Description

Windows Hello sign-in certificate enrollment failed.

Message #

Windows Hello sign-in certificate enrollment failed.
Error: %1
Processing time: %2 seconds

Fields #

NameDescription
Error HexInt32
Processing_time UInt32
ProcessingTime UInt32

Event ID 7067 — Windows Hello failed to set a certificate property on a Windows Hello key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
CertificateEnrollment
Opcode
Informational

Description

Windows Hello failed to set a certificate property on a Windows Hello key.

Message #

Windows Hello failed to set a certificate property on a Windows Hello key.

Error: %1
Key name: %2
Certificate type: %3

Fields #

NameDescription
Error HexInt32
Key_name UnicodeString
Certificate_type UInt32
KeyName UnicodeString
CertificateType UInt32

Event ID 7130 — Windows Hello PIN Recovery failed to change the user's PIN.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PINRecovery
Opcode
Stop

Description

Windows Hello PIN Recovery failed to change the user's PIN.

Message #

Windows Hello PIN Recovery failed to change the user's PIN.
Error: %1 (%2)
Correlation vector: %3
Processing time: %4 seconds.

Fields #

NameDescription
Error HexInt32
Correlation_vector
Processing_time
ErrorText UnicodeString
CorrelationVector AnsiString
ProcessingTime UInt32

Event ID 7200 — The device registration prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

The device registration prerequisite check failed.

Message #

The device registration prerequisite check failed.

Event ID 7200 — The device registration prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

The device registration prerequisite check failed.

Event ID 7201 — The Primary Account Primary Refresh Token prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

The Primary Account Primary Refresh Token prerequisite check failed.

Message #

The Primary Account Primary Refresh Token prerequisite check failed.

Event ID 7201 — The Primary Account Primary Refresh Token prerequisite check failed.

#
Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
Error
Task
PrerequisitesCheck
Opcode
Informational

Description

The Primary Account Primary Refresh Token prerequisite check failed.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HelloForBusiness",
    "guid": "906B8A99-63CE-58D7-86AB-10989BBD5567",
    "event_source_name": "",
    "event_id": 7201,
    "version": 0,
    "level": 2,
    "task": 12,
    "opcode": 12,
    "keywords": 9223372036854775809,
    "time_created": "2022-04-07T16:48:31.714659+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 4128,
      "thread_id": 4228
    },
    "channel": "Microsoft-Windows-HelloForBusiness/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 7202 — The device failed to meet the Windows Hello for Business hardware requirements.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

The device failed to meet the Windows Hello for Business hardware requirements.

Message #

The device failed to meet the Windows Hello for Business hardware requirements.

Event ID 7202 — The device failed to meet the Windows Hello for Business hardware requirements.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

The device failed to meet the Windows Hello for Business hardware requirements.

Event ID 7203 — Windows Hello for Business is not enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business is not enabled.

Message #

Windows Hello for Business is not enabled.

Event ID 7203 — Windows Hello for Business is not enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business is not enabled.

Event ID 7204 — Windows Hello for Business post-logon provisioning is not enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business post-logon provisioning is not enabled.

Message #

Windows Hello for Business post-logon provisioning is not enabled.

Event ID 7204 — Windows Hello for Business post-logon provisioning is not enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business post-logon provisioning is not enabled.

Event ID 7205 — Windows Hello for Business failed to locate a usable sign-in certificate template.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business failed to locate a usable sign-in certificate template.

Message #

Windows Hello for Business failed to locate a usable sign-in certificate template.

Error: %1

Fields #

NameDescription
Error HexInt32

Event ID 7205 — Windows Hello for Business failed to locate a usable sign-in certificate template.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business failed to locate a usable sign-in certificate template.

Fields #

NameDescription
Error HexInt32

Event ID 7206 — Windows Hello for Business failed to locate a certificate registration authority.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business failed to locate a certificate registration authority.

Message #

Windows Hello for Business failed to locate a certificate registration authority.

Event ID 7206 — Windows Hello for Business failed to locate a certificate registration authority.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business failed to locate a certificate registration authority.

Event ID 7207 — Windows Hello for Business failed to locate an enterprise management client.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business failed to locate an enterprise management client.

Message #

Windows Hello for Business failed to locate an enterprise management client.

Event ID 7207 — Windows Hello for Business failed to locate an enterprise management client.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business failed to locate an enterprise management client.

Event ID 7208 — Windows Hello for Business failed to locate a sign-in certificate profile.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business failed to locate a sign-in certificate profile.

Message #

Windows Hello for Business failed to locate a sign-in certificate profile.

Event ID 7208 — Windows Hello for Business failed to locate a sign-in certificate profile.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business failed to locate a sign-in certificate profile.

Event ID 7209 — Windows Hello for Business failed to locate a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business failed to locate a certificate payload for the sign-in certificate. The SCEP Request is not available.

Message #

Windows Hello for Business failed to locate a certificate payload for the sign-in certificate. The SCEP Request is not available.

Event ID 7209 — Windows Hello for Business failed to locate a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business failed to locate a certificate payload for the sign-in certificate. The SCEP Request is not available.

Event ID 7210 — Windows Hello for Business detected the user running in a remote desktop session.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business detected the user running in a remote desktop session.

Message #

Windows Hello for Business detected the user running in a remote desktop session.

Event ID 7210 — Windows Hello for Business detected the user running in a remote desktop session.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
Error
Task
PrerequisitesCheck
Opcode
Informational

Description

Windows Hello for Business detected the user running in a remote desktop session.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HelloForBusiness",
    "guid": "906B8A99-63CE-58D7-86AB-10989BBD5567",
    "event_source_name": "",
    "event_id": 7210,
    "version": 0,
    "level": 2,
    "task": 12,
    "opcode": 12,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T04:58:41.296416+00:00",
    "event_record_id": 45,
    "correlation": {},
    "execution": {
      "process_id": 3604,
      "thread_id": 7852
    },
    "channel": "Microsoft-Windows-HelloForBusiness/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 7211 — The Secondary Account Primary Refresh Token prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
PrerequisitesCheck
Opcode
Informational

Description

The Secondary Account Primary Refresh Token prerequisite check failed.

Message #

The Secondary Account Primary Refresh Token prerequisite check failed.

Event ID 7211 — The Secondary Account Primary Refresh Token prerequisite check failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PrerequisitesCheck
Opcode
Informational

Description

The Secondary Account Primary Refresh Token prerequisite check failed.

Event ID 7225 — Windows Hello key creation failed with Processing_time.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyCreation
Opcode
Stop

Description

Windows Hello key creation failed with Processing_time.

Message #

Windows Hello key creation failed with %1.
Processing time: %2 seconds

Fields #

NameDescription
Processing_time
Error HexInt32
ProcessingTime UInt32

Event ID 7226 — Windows Hello failed to delete the Key_Name key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyDeletion
Opcode
Informational

Description

Windows Hello failed to delete the Key_Name key.

Message #

Windows Hello failed to delete the %1 key.

Key Name: %2
Error: %3

Fields #

NameDescription
Key_Name
Error HexInt32
KeyType UInt32
Known values
%%2499
Machine key
%%2500
User key
KeyName UnicodeString

Event ID 7510 — Windows Hello key registration failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
KeyRegistration
Opcode
Stop

Description

Windows Hello key registration failed.

Message #

Windows Hello key registration failed.

Error: %1

Fields #

NameDescription
Error HexInt32

Event ID 7520 — Failed to authenticate the user's credential.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Multi_FactorUnlock
Opcode
Stop

Description

Failed to authenticate the user's credential.

Message #

Failed to authenticate the user's credential.
Error: %1 (%2)
Correlation vector: %3
Processing time: %4 milliseconds.

Fields #

NameDescription
Error HexInt32
Correlation_vector
Processing_time
ErrorText UnicodeString
CorrelationVector AnsiString
ProcessingTime UInt32

Event ID 7525 — AD/Azure AD plugin request failed with Processing_time.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
HelloProvisioning
Opcode
Stop

Description

AD/Azure AD plugin request failed with Processing_time.

Message #

AD/Azure AD plugin request failed with %1.
Processing time: %2 seconds

Fields #

NameDescription
Processing_time
Error HexInt32
ProcessingTime UInt32

Event ID 7555 — Windows Hello container creation failed.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerCreation
Opcode
Stop

Description

Windows Hello container creation failed.

Message #

Windows Hello container creation failed.
Error: %1
Processing time: %2 seconds

Fields #

NameDescription
Error HexInt32
Processing_time UInt32
ProcessingTime UInt32

Event ID 7601 — Windows Hello failed to delete the container in response to a policy change.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerDeletion
Opcode
Stop

Description

Windows Hello failed to delete the container in response to a policy change.

Message #

Windows Hello failed to delete the container in response to a policy change.

Error: %1
Processing time: %2 milliseconds.

Fields #

NameDescription
Error HexInt32
Processing_time UInt32
ProcessingTime UInt32

Event ID 7611 — Windows Hello failed to delete the container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ContainerDeletion
Opcode
Stop

Description

Windows Hello failed to delete the container.

Message #

Windows Hello failed to delete the container.

Error: %1.

Fields #

NameDescription
Error HexInt32

Event ID 7621 — Windows Hello failed to delete the user's Windows Hello certificates.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
CertificateEnrollment
Opcode
Informational

Description

Windows Hello failed to delete the user's Windows Hello certificates.

Message #

Windows Hello failed to delete the user's Windows Hello certificates.

Error: %1.

Fields #

NameDescription
Error HexInt32

Event ID 7631 — Windows Hello failed to delete the user's biometric enrollments.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
BiometricEnrollment
Opcode
Informational

Description

Windows Hello failed to delete the user's biometric enrollments.

Message #

Windows Hello failed to delete the user's biometric enrollments.

Error: %1.

Fields #

NameDescription
Error HexInt32

Event ID 7701 — Windows Hello failed to use secure biometrics protector due to secret encryption key loss.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
ProtectorUse
Opcode
Informational

Description

Windows Hello failed to use secure biometrics protector due to secret encryption key loss.

Message #

Windows Hello failed to use secure biometrics protector due to secret encryption key loss.

Event ID 8002 — Successfully loaded an existing KeyProvider Windows Hello container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Container Load
Opcode
Informational

Description

Successfully loaded an existing KeyProvider Windows Hello container.

Message #

Successfully loaded an existing %3 Windows Hello container.

ID: %1
Version: %2
Has Cached Logon Key: %4
State: %5

Fields #

NameDescription
ContainerId GUID
ContainerVersion UInt32
KeyProvider UInt32
HasCachedLogonKey Boolean
ContainerStatus UInt32

Event ID 8025 — The ServiceName service started successfully.

#
Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
16
Task
Service Start
Opcode
Informational

Description

The ServiceName service started successfully.

Message #

The %1 service started successfully.

Fields #

NameDescription
ServiceName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HelloForBusiness",
    "guid": "906B8A99-63CE-58D7-86AB-10989BBD5567",
    "event_source_name": "",
    "event_id": 8025,
    "version": 0,
    "level": 16,
    "task": 6,
    "opcode": 12,
    "keywords": 9223372036854775809,
    "time_created": "2023-11-06T01:43:17.888294+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 1444,
      "thread_id": 14060
    },
    "channel": "Microsoft-Windows-HelloForBusiness/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "ServiceName": "Microsoft Passport Container"
  },
  "message": ""
}

References #

Event ID 8030 — Windows Hello created the sign-in certificate request successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Opcode
Informational

Description

Windows Hello created the sign-in certificate request successfully.

Message #

Windows Hello created the sign-in certificate request successfully.

Event ID 8031 — Windows Hello installed the sign-in certificate successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Opcode
Informational

Description

Windows Hello installed the sign-in certificate successfully.

Message #

Windows Hello installed the sign-in certificate successfully.

Event ID 8032 — Windows Hello successfully rolled back from an unsuccessful sign-in certificate enrollment.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Opcode
Informational

Description

Windows Hello successfully rolled back from an unsuccessful sign-in certificate enrollment.

Message #

Windows Hello successfully rolled back from an unsuccessful sign-in certificate enrollment.

Event ID 8045 — Windows Hello processing completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Hello Provisioning
Opcode
Stop

Description

Windows Hello processing completed successfully.

Message #

Windows Hello processing completed successfully.
Processing time: %1 seconds

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8052 — The new key request from the key pre-generation pool completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Key Creation
Opcode
Stop

Description

The new key request from the key pre-generation pool completed successfully.

Message #

The new key request from the key pre-generation pool completed successfully.
Processing time: %1 seconds.

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8052 — The new key request from the key pre-generation pool completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Key Creation
Opcode
Stop

Description

The new key request from the key pre-generation pool completed successfully.

Fields #

NameDescription
ProcessingTime UInt32

Event ID 8053 — The key pre-generation pool successfully pre-generated a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Key Creation
Opcode
Stop

Description

The key pre-generation pool successfully pre-generated a key.

Message #

The key pre-generation pool successfully pre-generated a key. 
Processing time: %1 seconds.

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8053 — The key pre-generation pool successfully pre-generated a key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Key Creation
Opcode
Stop

Description

The key pre-generation pool successfully pre-generated a key.

Fields #

NameDescription
ProcessingTime UInt32

Event ID 8054 — Windows Hello for Business prerequisites check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Stop

Description

Windows Hello for Business prerequisites check completed successfully.

Message #

Windows Hello for Business prerequisites check completed successfully.

Event ID 8054 — Windows Hello for Business prerequisites check completed successfully.

#
Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
16
Task
Prerequisites Check
Opcode
Stop

Description

Windows Hello for Business prerequisites check completed successfully.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HelloForBusiness",
    "guid": "906B8A99-63CE-58D7-86AB-10989BBD5567",
    "event_source_name": "",
    "event_id": 8054,
    "version": 0,
    "level": 16,
    "task": 12,
    "opcode": 11,
    "keywords": 9223372036854775809,
    "time_created": "2022-04-07T16:57:32.150051+00:00",
    "event_record_id": 18,
    "correlation": {},
    "execution": {
      "process_id": 4128,
      "thread_id": 4156
    },
    "channel": "Microsoft-Windows-HelloForBusiness/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 8055 — Windows Hello container provisioning completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Container Creation
Opcode
Stop

Description

Windows Hello container provisioning completed successfully.

Message #

Windows Hello container provisioning completed successfully.
Processing time: %1 seconds
Existing container: %2

Fields #

NameDescription
Processing_time UInt32
Existing_container Boolean
ProcessingTime UInt32
UsedExistingContainer Boolean

Event ID 8060 — Windows Hello successfully created a PIN recovery key for user Processing_time.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PIN Recovery
Opcode
Stop

Description

Windows Hello successfully created a PIN recovery key for user Processing_time.

Message #

Windows Hello successfully created a PIN recovery key for user %1.
Processing time: %2 seconds

Fields #

NameDescription
Processing_time
UserSid SID
ProcessingTime UInt32

Event ID 8065 — The cloud experience host completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Hello Provisioning
Opcode
Stop

Description

The cloud experience host completed successfully.

Message #

The cloud experience host completed successfully.
Processing time: %1 seconds

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8066 — Windows Hello sign-in certificate enrollment completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Certificate Enrollment
Opcode
Stop

Description

Windows Hello sign-in certificate enrollment completed successfully.

Message #

Windows Hello sign-in certificate enrollment completed successfully.
Processing time: %1 seconds

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8067 — Windows Hello set a certificate property on a Windows Hello key.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Certificate Enrollment
Opcode
Informational

Description

Windows Hello set a certificate property on a Windows Hello key.

Message #

Windows Hello set a certificate property on a Windows Hello key.

Key name: %1
Certificate type: %2

Fields #

NameDescription
Key_name UnicodeString
Certificate_type UInt32
KeyName UnicodeString
CertificateType UInt32

Event ID 8130 — Windows Hello PIN Recovery successfully changed the user's PIN.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PIN Recovery
Opcode
Stop

Description

Windows Hello PIN Recovery successfully changed the user's PIN.

Message #

Windows Hello PIN Recovery successfully changed the user's PIN.
Processing time: %1 seconds.

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8200 — The device registration prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

The device registration prerequisite check completed successfully.

Message #

The device registration prerequisite check completed successfully.

Event ID 8200 — The device registration prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

The device registration prerequisite check completed successfully.

Event ID 8201 — The Primary Account Primary Refresh Token prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

The Primary Account Primary Refresh Token prerequisite check completed successfully.

Message #

The Primary Account Primary Refresh Token prerequisite check completed successfully.

Event ID 8201 — The Primary Account Primary Refresh Token prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

The Primary Account Primary Refresh Token prerequisite check completed successfully.

Event ID 8202 — The device meets Windows Hello for Business hardware requirements.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

The device meets Windows Hello for Business hardware requirements.

Message #

The device meets Windows Hello for Business hardware requirements.

Event ID 8202 — The device meets Windows Hello for Business hardware requirements.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

The device meets Windows Hello for Business hardware requirements.

Event ID 8203 — Windows Hello for Business is enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business is enabled.

Message #

Windows Hello for Business is enabled.

Event ID 8203 — Windows Hello for Business is enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business is enabled.

Event ID 8204 — Windows Hello for Business post-logon provisioning is enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business post-logon provisioning is enabled.

Message #

Windows Hello for Business post-logon provisioning is enabled.

Event ID 8204 — Windows Hello for Business post-logon provisioning is enabled.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business post-logon provisioning is enabled.

Event ID 8205 — Windows Hello for Business successfully located a usable sign-on certificate template.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully located a usable sign-on certificate template.

Message #

Windows Hello for Business successfully located a usable sign-on certificate template.

Event ID 8205 — Windows Hello for Business successfully located a usable sign-on certificate template.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully located a usable sign-on certificate template.

Event ID 8206 — Windows Hello for Business successfully located a certificate registration authority.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully located a certificate registration authority.

Message #

Windows Hello for Business successfully located a certificate registration authority.

Event ID 8206 — Windows Hello for Business successfully located a certificate registration authority.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully located a certificate registration authority.

Event ID 8207 — Windows Hello for Business successfully located an enterprise management client.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully located an enterprise management client.

Message #

Windows Hello for Business successfully located an enterprise management client.

Event ID 8207 — Windows Hello for Business successfully located an enterprise management client.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully located an enterprise management client.

Event ID 8208 — Windows Hello for Business successfully located a sign-in certificate profile.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully located a sign-in certificate profile.

Message #

Windows Hello for Business successfully located a sign-in certificate profile.

Event ID 8208 — Windows Hello for Business successfully located a sign-in certificate profile.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully located a sign-in certificate profile.

Event ID 8209 — Windows Hello for Business successfully located a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully located a certificate payload for the sign-in certificate. The SCEP Request is available.

Message #

Windows Hello for Business successfully located a certificate payload for the sign-in certificate. The SCEP Request is available.

Event ID 8209 — Windows Hello for Business successfully located a certificate payload for the sign-in certificate.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully located a certificate payload for the sign-in certificate. The SCEP Request is available.

Event ID 8210 — Windows Hello for Business successfully completed the remote desktop prerequisite check.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully completed the remote desktop prerequisite check.

Message #

Windows Hello for Business successfully completed the remote desktop prerequisite check.

Event ID 8210 — Windows Hello for Business successfully completed the remote desktop prerequisite check.

#
Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Level
16
Task
Prerequisites Check
Opcode
Informational

Description

Windows Hello for Business successfully completed the remote desktop prerequisite check.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HelloForBusiness",
    "guid": "906B8A99-63CE-58D7-86AB-10989BBD5567",
    "event_source_name": "",
    "event_id": 8210,
    "version": 0,
    "level": 16,
    "task": 12,
    "opcode": 12,
    "keywords": 9223372036854775809,
    "time_created": "2022-04-07T16:57:32.150041+00:00",
    "event_record_id": 17,
    "correlation": {},
    "execution": {
      "process_id": 4128,
      "thread_id": 4156
    },
    "channel": "Microsoft-Windows-HelloForBusiness/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 8211 — The Secondary Account Primary Refresh Token prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Debug
Task
Prerequisites Check
Opcode
Informational

Description

The Secondary Account Primary Refresh Token prerequisite check completed successfully.

Message #

The Secondary Account Primary Refresh Token prerequisite check completed successfully.

Event ID 8211 — The Secondary Account Primary Refresh Token prerequisite check completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Prerequisites Check
Opcode
Informational

Description

The Secondary Account Primary Refresh Token prerequisite check completed successfully.

Event ID 8225 — Windows Hello key creation completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Key Creation
Opcode
Stop

Description

Windows Hello key creation completed successfully.

Message #

Windows Hello key creation completed successfully.
Processing time: %1 seconds

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8226 — Windows Hello successfully deleted a Key_Name KeyProvider key from the Windows Hello container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Key Deletion
Opcode
Informational

Description

Windows Hello successfully deleted a Key_Name KeyProvider key from the Windows Hello container.

Message #

Windows Hello successfully deleted a %1 %2 key from the Windows Hello container.

Key Name: %3

Fields #

NameDescription
Key_Name
KeyProvider UInt32
KeyType UInt32
Known values
%%2499
Machine key
%%2500
User key
KeyName UnicodeString

Event ID 8510 — Windows Hello key registration completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Key Registration
Opcode
Stop

Description

Windows Hello key registration completed successfully.

Message #

Windows Hello key registration completed successfully.

Event ID 8520 — Successfully authenticated the user's credential.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Multi-Factor Unlock
Opcode
Stop

Description

Successfully authenticated the user's credential.

Message #

Successfully authenticated the user's credential.
Processing time: %1 milliseconds.

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8525 — AD/Azure AD plugin request completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Hello Provisioning
Opcode
Stop

Description

AD/Azure AD plugin request completed successfully.

Message #

AD/Azure AD plugin request completed successfully.
Processing time: %1 seconds

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8555 — The Windows Hello container creation completed successfully.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Container Creation
Opcode
Stop

Description

The Windows Hello container creation completed successfully.

Message #

The Windows Hello container creation completed successfully.
Processing time: %1 seconds

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8601 — Windows Hello successfully deleted the container in response to a policy change.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Container Deletion
Opcode
Stop

Description

Windows Hello successfully deleted the container in response to a policy change.

Message #

Windows Hello successfully deleted the container in response to a policy change.

Processing time: %1 milliseconds.

Fields #

NameDescription
Processing_time UInt32
ProcessingTime UInt32

Event ID 8611 — Windows Hello successfully deleted the container.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Container Deletion
Opcode
Stop

Description

Windows Hello successfully deleted the container.

Message #

Windows Hello successfully deleted the container.

Event ID 8621 — Windows Hello successfully deleted the user's Windows Hello certificates.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Certificate Enrollment
Opcode
Informational

Description

Windows Hello successfully deleted the user's Windows Hello certificates.

Message #

Windows Hello successfully deleted the user's Windows Hello certificates.

Event ID 8631 — Windows Hello successfully deleted the user's biometric enrollments.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
BiometricEnrollment
Opcode
Informational

Description

Windows Hello successfully deleted the user's biometric enrollments.

Message #

Windows Hello successfully deleted the user's biometric enrollments.

Event ID 8632 — Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Windows Hello Username/SID Cache
Opcode
Informational

Description

Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information.

Message #

Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information: 

Username: %1
User SID: %2
Domain: %3
User-Entered: %4

Fields #

NameDescription
Username UnicodeString[Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information] Username.
User_SID SID[Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information] User SID.
Domain UnicodeString[Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information] Domain.
UserEntered Boolean[Windows Hello for Business successfully added a user entry to the Username/SID cache with the following information] User-Entered.
UserName UnicodeString
UserSid SID

Event ID 8633 — Windows Hello for Business successfully removed a user entry to the Username/SID cache with the following information: User SID.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Windows Hello Username/SID Cache
Opcode
Informational

Description

Windows Hello for Business successfully removed a user entry to the Username/SID cache with the following information.

Message #

Windows Hello for Business successfully removed a user entry to the Username/SID cache with the following information: 

User SID: %1

Fields #

NameDescription
User_SID SID[Windows Hello for Business successfully removed a user entry to the Username/SID cache with the following information] User SID.
UserSid SID

Event ID 8634 — Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache: User S...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Windows Hello Username/SID Cache
Opcode
Informational

Description

Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache.

Message #

Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache: 

User SID: %1
Username: %2
Unused Username: %3

Fields #

NameDescription
User_SID SID[Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache] User SID.
Username UnicodeString[Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache] Username.
Unused_Username UnicodeString[Windows Hello for Business found a user entry with a duplicate SID and successfully removed the unused username from the Username/SID cache] Unused Username.
UserSid SID
UserName UnicodeString
UnusedUserName UnicodeString

Event ID 8635 — Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache: Userna...

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Windows Hello Username/SID Cache
Opcode
Informational

Description

Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache.

Message #

Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache: 

Username: %1
User SID: %2
Unused User SID: %3

Fields #

NameDescription
Username UnicodeString[Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache] Username.
User_SID SID[Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache] User SID.
Unused_User_SID SID[Windows Hello for Business found a user entry with a duplicate username and successfully removed the unused SID from the Username/SID cache] Unused User SID.
UserName UnicodeString
UserSid SID
UnusedUserSid SID

Event ID 8636 — Windows Hello for Business found a stale SID in the Username/SID cache.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Windows Hello Username/SID Cache
Opcode
Informational

Description

Windows Hello for Business found a stale SID in the Username/SID cache.

Message #

Windows Hello for Business found a stale SID in the Username/SID cache: 

Username: %1
User SID: %2
Stale User SID: %3

Fields #

NameDescription
Username UnicodeString[Windows Hello for Business found a stale SID in the Username/SID cache] Username.
User_SID SID[Windows Hello for Business found a stale SID in the Username/SID cache] User SID.
Stale_User_SID SID[Windows Hello for Business found a stale SID in the Username/SID cache] Stale User SID.
UserName UnicodeString
CurrentlyMostRecentUserSid SID
StaleUserSid SID

Event ID 8637 — Windows Hello for Business found a stale username in the Username/SID cache.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Windows Hello Username/SID Cache
Opcode
Informational

Description

Windows Hello for Business found a stale username in the Username/SID cache.

Message #

Windows Hello for Business found a stale username in the Username/SID cache: 

User SID: %1
Username: %2
Stale Username: %3

Fields #

NameDescription
User_SID SID[Windows Hello for Business found a stale username in the Username/SID cache] User SID.
Username UnicodeString[Windows Hello for Business found a stale username in the Username/SID cache] Username.
Stale_Username UnicodeString[Windows Hello for Business found a stale username in the Username/SID cache] Stale Username.
UserSid SID
CurrentlyMostRecentUserName UnicodeString
StaleUserName UnicodeString

Event ID 8638 — Windows Hello for Business removed a stale SID from the Username/SID cache: Stale User SID.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Windows Hello Username/SID Cache
Opcode
Informational

Description

Windows Hello for Business removed a stale SID from the Username/SID cache.

Message #

Windows Hello for Business removed a stale SID from the Username/SID cache: 

Stale User SID: %1

Fields #

NameDescription
Stale_User_SID SID[Windows Hello for Business removed a stale SID from the Username/SID cache] Stale User SID.
StaleUserSid SID

Event ID 8639 — Windows Hello for Business removed a stale username from the Username/SID cache.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
Windows Hello Username/SID Cache
Opcode
Informational

Description

Windows Hello for Business removed a stale username from the Username/SID cache.

Message #

Windows Hello for Business removed a stale username from the Username/SID cache: 

User SID: %1
Stale Username: %2

Fields #

NameDescription
User_SID SID[Windows Hello for Business removed a stale username from the Username/SID cache] User SID.
Stale_Username UnicodeString[Windows Hello for Business removed a stale username from the Username/SID cache] Stale Username.
UserSid SID
StaleUserName UnicodeString

Event ID 8640 — Windows Hello for Business PIN was changed by a user with the following information: User SID.

Provider
Microsoft-Windows-HelloForBusiness
Channel
Operational
Task
PIN Change
Opcode
Informational

Description

Windows Hello for Business PIN was changed by a user with the following information.

Message #

Windows Hello for Business PIN was changed by a user with the following information: 
User SID: %1

Fields #

NameDescription
User_SID SID[Windows Hello for Business PIN was changed by a user with the following information] User SID.
UserSid SID