Microsoft-Windows-HostGuardianService-Client

182 events across 4 channels

Event IDTitleChannel
100Debug
100Operational
101Debug
101Operational
102Debug
102Operational
103Analytic
103Operational
104Analytic
104Operational
105Analytic
105Operational
106Operational
107Operational
108Operational
109Admin
109Operational
110Admin
110Operational
111Admin
111Operational
112Operational
112Started operation '.Debug
113Operational
113Operation '.Debug
200A new ActivityID has been generated.Operational
1002Remote attestation initiated.Operational
1003Remote attestation completed.Operational
1004Operational
1004ClientAttestationHttpRequestSend: ActivityID %1.Debug
1005Operational
1005ClientAttestationHttpResponseReceived.Debug
1006Operational
1006ClientAttestationHttpError.Admin
1007Operational
1007The remote attestation request failed because this host is not included in the …Admin
1008Operational
1008The remote attestation request failed because the host did not start with Secure …Admin
1009Operational
1009The remote attestation request failed because this host's Code Integrity policy …Admin
1010Operational
1010The remote attestation request failed because this host is not part of an Active …Admin
1012Operational
1012Determining TPM endorsement key failed.Admin
1013Operational
1013The remote attestation request failed because of a TPM error.Admin
1014Operational
1014Connection to %1 failed.Analytic
1015Switching to Active Directory attestation mode.Operational
1016Operational
1016Connecting to Remote Attestation service at %1.Analytic
1017Operational
1017Reconnecting to Remote Attestation service at %1.Analytic
1018Remote attestation succeeded and returned a health certificate with the …Operational
1019Operational
1019The remote attestation request failed because the Remote Attestation Service …Admin
1020Operational
1020The remote attestation request failed.Admin
1021Operational
1021The remote attestation request failed because this host was not booted …Admin
1022Operational
1022The remote attestation request failed because at least one Debug Mode is enabled …Admin
1023Determining TPM endorsement key failed.Operational
1024Operational
1024The remote attestation request failed because this host was not configured …Admin
1025Operational
1025The remote attestation request failed because Isolated User Mode could not be …Admin
1026Operational
1026The remote attestation request failed because the TPM measurements were not …Admin
1027Operational
1027The remote attestation request failed because the Host Guardian Service did not …Admin
1028Operational
1028The remote attestation request failed because the host did not start with …Admin
1029Operational
1029The remote attestation request failed because IOMMU was not required by the …Admin
1030Operational
1030The remote attestation request failed because the host did not start with …Admin
1031Operational
1031The remote attestation request failed because code integrity was not required by …Admin
1032Operational
1032The remote attestation request failed but no reason was given.Admin
1033Switching to TPM attestation mode.Operational
1034Operational
1034The remote attestation request failed because the Host Guardian Service is using …Admin
1035Operational
1035The remote attestation request failed because the Host Guardian Service could …Admin
1036Operational
1036The remote attestation request failed because it could not authenticate to the …Admin
1037Operational
1037The remote attestation request failed because the host started with hibernation …Admin
1038Operational
1038The remote attestation request failed because the host started with dumps …Admin
1039Operational
1039The remote attestation request failed because the host did not start with dump …Admin
1040Operational
1040The remote attestation request failed because the host's dump encryption key …Admin
1041Local attestation initiated.Operational
1042No local health signing certificate was found.Operational
1043Operational
1043Remote attestation failed due to an invalid payload received by the Host …Admin
1044Operational
1044The endorsement key certificate could not be found in the TPM.Admin
1045Operational
1045The issuing intermediate certificate could not be found in the TPM for the …Debug
1046Operational
1046The remote attestation request failed because the host key is not inclued in the …Admin
2000The requested WMI operation failed because access is denied.Operational
2001Operational
2001The required value '.Admin
2002Successfully opened Shielded VM Local Certificates store.Operational
2003No health signing certificate was found.Operational
2004Operational
2004The Host Guardian Service Client is unable to retrieve the encryption key (IDK) …Admin
2005Operational
2005Unable to retrieve the local health certificate.Admin
2006Operational
2006Failed to roll the transport key.Admin
2007Operational
2007No signing certificates were found in the Shielded VM Local Certificates store.Admin
2008Operational
2008No encryption certificates were found in the Shielded VM Local Certificates …Admin
2009Initiating unwrap of key protector.Operational
2010Initiating creation of a new of key protector.Operational
2011Adding a guardian with signing certificate %1 and encryption certificate %2 to a …Operational
2012Initiating privileged unwrap of key protector.Operational
2013Instantiating Host Guardian Service client in %1 mode.Operational
2014Operational
2014The Host Guardian Service Client failed to unwrap a Key Protector on behalf of a …Admin
2015Operational
2015The Host Guardian Service Client successfully unwrapped a Key Protector on …Admin
2016Operational
2016The signing certificate need set 'DigitalSignature' key usage.Admin
2017Operational
2017The encryption certificate need set 'DataEncipherment' key usage.Admin
2018Failures rolling the transport key as the health certificate is invalid.Operational
2019Operational
2019Raw certificate dump.Debug
2020The Host Guardian Service Client reused a cached health certificate issued in %1 …Operational
2021The Host Guardian Service Client could not contact the Host Guardian Service.Operational
3007The remote attestation request failed because this host is not included in the …Operational
3008The remote attestation request failed because the host did not start with Secure …Operational
3009The remote attestation request failed because this host's Code Integrity policy …Operational
3010The remote attestation request failed because this host is not part of an Active …Operational
3013The remote attestation request failed because of a TPM error.Operational
3019The remote attestation request failed because the Remote Attestation Service …Operational
3020The remote attestation request failed.Operational
3021The remote attestation request failed because this host was not booted …Operational
3022The remote attestation request failed because at least one Debug Mode is enabled …Operational
3024The remote attestation request failed because this host was not configured …Operational
3025The remote attestation request failed because Isolated User Mode could not be …Operational
3026The remote attestation request failed because the TPM measurements were not …Operational
3027The remote attestation request failed because the Host Guardian Service did not …Operational
3028The remote attestation request failed because the host did not start with …Operational
3029The remote attestation request failed because IOMMU was not required by the …Operational
3030The remote attestation request failed because the host did not start with …Operational
3031The remote attestation request failed because code integrity was not required by …Operational
3032The remote attestation request failed but no reason was given.Operational
3034The remote attestation request failed because the Host Guardian Service is using …Operational
3035The remote attestation request failed because the Host Guardian Service could …Operational
3036The remote attestation request failed because it could not authenticate to the …Operational
3037The remote attestation request failed because the host started with hibernation …Operational
3038The remote attestation request failed because the host started with dumps …Operational
3039The remote attestation request failed because the host did not start with dump …Operational
3040The remote attestation request failed because the host's dump encryption key …Operational
3043Remote attestation failed due to an invalid payload received by the Host …Operational
3044The endorsement key certificate could not be found in the TPM.Operational
3046The remote attestation request failed because the host key is not inclued in the …Operational
4001The HGAttest API completed the operation with status code.Operational
4002Operational
4002The URL provided for SHS attestation is invalid.Admin
4003Operational
4003Attestation is not supported in this configuration.Admin
4004Operational
4004Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is …Admin
4005Operational
4005Remote attestation for a CA Intermediate Certificate is currently not supported.Admin
4006Operational
4006This host attempted a remote attestation in %1 mode, but the targeted HGS server …Admin
5000Operational
5000A host key was set from certificate with thumbprint %1.Admin
5001Operational
5001A host key was removed.Admin

Event ID 100 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Debug

Message

%1

Fields

NameDescription
Message

Event ID 100 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 101 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Debug

Message

%1

Fields

NameDescription
Message

Event ID 101 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 102 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Debug

Message

%1

Fields

NameDescription
Message

Event ID 102 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 103 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Analytic

Message

%1

Fields

NameDescription
Message

Event ID 103 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 104 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Analytic

Message

%1

Fields

NameDescription
Message

Event ID 104 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 105 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Analytic

Message

%1

Fields

NameDescription
Message

Event ID 105 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 106 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

%1

Fields

NameDescription
Message

Event ID 107 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

%1

Fields

NameDescription
Message

Event ID 108 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

%1

Fields

NameDescription
Message

Event ID 109 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

%1

Fields

NameDescription
Message

Event ID 109 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 110 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

%1

Fields

NameDescription
Message

Event ID 110 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 111 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

%1

Fields

NameDescription
Message

Event ID 111 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 112 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 112 — Started operation '.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Debug

Message

Started operation '%1'.

Fields

NameDescription
Message

Event ID 113 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
OperationName
StatusCode

Event ID 113 — Operation '.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Debug

Message

Operation '%1' ended with result: '%2'.

Fields

NameDescription
OperationName
StatusCode

Event ID 200 — A new ActivityID has been generated.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

A new ActivityID has been generated.

Fields

NameDescription
Id

Event ID 1002 — Remote attestation initiated.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Remote attestation initiated.

Event ID 1003 — Remote attestation completed.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Remote attestation completed.
OperationMode: %1
Status: %2
Substatus: %3

Fields

NameDescription
OperationMode
AttestationStatus
AttestationSubstatus

Event ID 1004 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
HostId

Event ID 1004 — ClientAttestationHttpRequestSend: ActivityID %1.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Debug

Message

ClientAttestationHttpRequestSend: ActivityID %1

Fields

NameDescription
HostId

Event ID 1005 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1005 — ClientAttestationHttpResponseReceived.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Debug

Message

ClientAttestationHttpResponseReceived: %1

Fields

NameDescription
Message

Event ID 1006 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1006 — ClientAttestationHttpError.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

ClientAttestationHttpError: %1

Fields

NameDescription
Message

Event ID 1007 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1007 — The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation se...

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation server. Error: %1. To add this host to the authorized list of host EKs, perform the following steps:
    1. On this host, run the Get-PlatformIdentifier cmdlet to retrieve the host EK in the form of a XML file.
    2. On the Attestation server, run the Add-HgsAttestationTpmHost cmdlet, specifying the file generated in the previous step.
Event IDs 1007 and 3007 represent the same event.

Fields

NameDescription
Message

Event ID 1008 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1008 — The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did ...

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did not match a valid baseline host. Error: %1. To ensure a successful attestation request, verify that the host configuration matches a valid baseline host. If this is a baseline host, you must first perform the following steps:
    1.  On this host, run the Get-HgsAttestationBaselinePolicy cmdlet to generate a policy file.
    2. On the attestation server, run the Add-HgsAttestationTpmPolicy cmdlet, specifying the policy file generated by the Get-HgsAttestationBaselinePolicy cmdlet. This adds the policy as a valid baseline TPM policy.
Event IDs 1008 and 3008 represent the same event.

Fields

NameDescription
Message

Event ID 1009 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1009 — The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation ser...

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation server. Error: %1. To ensure a successful attestation request, verify that this host is configured with a valid Code Integrity policy. For help, refer to http://go.microsoft.com/fwlink/?LinkId=734772
Event IDs 1009 and 3009 represent the same event.

Fields

NameDescription
Message

Event ID 1010 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1010 — The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server. Error: %1. To ensure a successful attestation request, verify that the host is a member of an authorized Active Directory host group. If the Active Directory host group is not authorized by the Attestation server, you must first perform the following steps:
    1. On the attestation server, run the Add-HgsAttestationHostGroup cmdlet to add it as a valid Active Directory host group.
Event IDs 1010 and 3010 represent the same event.

Fields

NameDescription
Message

Event ID 1012 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1012 — Determining TPM endorsement key failed.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

Determining TPM endorsement key failed. Error: %1

Fields

NameDescription
Message

Event ID 1013 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1013 — The remote attestation request failed because of a TPM error.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because of a TPM error. Try clearing and reprovisioning the TPM. Error: %1
Event IDs 1013 and 3013 represent the same event.

Fields

NameDescription
Message

Event ID 1014 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1014 — Connection to %1 failed.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Analytic

Message

Connection to %1 failed. Reconnecting to another IP.

Fields

NameDescription
Message

Event ID 1015 — Switching to Active Directory attestation mode.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Switching to Active Directory attestation mode.

Event ID 1016 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1016 — Connecting to Remote Attestation service at %1.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Analytic

Message

Connecting to Remote Attestation service at %1

Fields

NameDescription
Message

Event ID 1017 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1017 — Reconnecting to Remote Attestation service at %1.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Analytic

Message

Reconnecting to Remote Attestation service at %1

Fields

NameDescription
Message

Event ID 1018 — Remote attestation succeeded and returned a health certificate with the thumbprint %1.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Remote attestation succeeded and returned a health certificate with the thumbprint %1.

Fields

NameDescription
CertThumbprint

Event ID 1019 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1019 — The remote attestation request failed because the Remote Attestation Service could not be reached.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the Remote Attestation Service could not be reached.
Event IDs 1019 and 3019 represent the same event.

Event ID 1020 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1020 — The remote attestation request failed.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed. Error: %1. For help, see http://go.microsoft.com/fwlink/?LinkId=735076
Event IDs 1020 and 3020 represent the same event.

Fields

NameDescription
Message

Event ID 1021 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1021 — The remote attestation request failed because this host was not booted correctly.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because this host was not booted correctly. Error: %1. To ensure a successful attestation request, verify that the host's most recent boot was a full boot.
Event IDs 1021 and 3021 represent the same event.

Fields

NameDescription
Message

Event ID 1022 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1022 — The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
Event IDs 1022 and 3022 represent the same event.

Fields

NameDescription
Message

Event ID 1023 — Determining TPM endorsement key failed.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Determining TPM endorsement key failed. Switching to Active Directory attestation mode.

Event ID 1024 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1024 — The remote attestation request failed because this host was not configured properly.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because this host was not configured properly. Error: %1. To ensure a successful attestation request, verify that the host's configuration contains an attestation service URL that is valid.
Event IDs 1024 and 3024 represent the same event.

Fields

NameDescription
Message

Event ID 1025 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1025 — The remote attestation request failed because Isolated User Mode could not be detected.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because Isolated User Mode could not be detected.  Verify that the Isolated User Mode feature is installed and that Virtualization Based Security has not been disabled manually or by local/domain-level policy.
Event IDs 1025 and 3025 represent the same event.

Fields

NameDescription
Message

Event ID 1026 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1026 — The remote attestation request failed because the TPM measurements were not valid.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the TPM measurements were not valid.  This can happen when the host utilizes unsupported TPM configurations, the Host Guardian Service client version is not supported by the server, or an attempt to tamper with the TPM Measurements was made.  Some PXE boot environments can also cause this issue; for help, refer to http://go.microsoft.com/fwlink/?LinkId=734770
Event IDs 1026 and 3026 represent the same event.

Fields

NameDescription
Message

Event ID 1027 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1027 — The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Event IDs 1027 and 3027 represent the same event.

Event ID 1028 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1028 — The remote attestation request failed because the host did not start with pagefile encryption enabled.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the host did not start with pagefile encryption enabled.
Event IDs 1028 and 3028 represent the same event.

Event ID 1029 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1029 — The remote attestation request failed because IOMMU was not required by the hypervisor.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because IOMMU was not required by the hypervisor. Verify that IOMMU is enabled and that it is explicity required for Virtual Secure Mode to launch. For help, refer to http://go.microsoft.com/fwlink/?LinkId=734842
Event IDs 1029 and 3029 represent the same event.

Event ID 1030 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1030 — The remote attestation request failed because the host did not start with BitLocker enabled.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the host did not start with BitLocker enabled.
Event IDs 1030 and 3030 represent the same event.

Event ID 1031 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1031 — The remote attestation request failed because code integrity was not required by the hypervisor.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because code integrity was not required by the hypervisor. Verify that code integrity is enabled and that it is being enforced by the hypervisor. For help, please refer to http://go.microsoft.com/fwlink/?LinkId=734841
Event IDs 1031 and 3031 represent the same event.

Event ID 1032 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1032 — The remote attestation request failed but no reason was given.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed but no reason was given. This typically indicates that the Host Guardian Service has not been fully configured with valid attestation policies.  If policies have been registered with the Host Guardian Service already, verify the functionality of the server and try again.
Event IDs 1032 and 3032 represent the same event.

Event ID 1033 — Switching to TPM attestation mode.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Switching to TPM attestation mode.

Event ID 1034 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1034 — The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.
Event IDs 1034 and 3034 represent the same event.

Event ID 1035 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1035 — The remote attestation request failed because the Host Guardian Service could not be contacted.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the Host Guardian Service could not be contacted.  This happens when the request can reach the server but the service either does not respond or responds with an unknown HTTP error.  Verify that the Host Guardian Service is registered, started, and fully operational.
Error: %1
Event IDs 1035 and 3035 represent the same event.

Fields

NameDescription
Message

Event ID 1036 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1036 — The remote attestation request failed because it could not authenticate to the Host Guardian Service.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because it could not authenticate to the Host Guardian Service.  This can occur when using HTTPS with an invalid or untrusted certificate, or when using Active Directory-based attestation without configuring trust between this host's domain and the Host Guardian Service domain, preventing NTLM and Kerberos authentication from succeeding.
Error: %1
Event IDs 1036 and 3036 represent the same event.

Fields

NameDescription
Message

Event ID 1037 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1037 — The remote attestation request failed because the host started with hibernation enabled.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147
Event IDs 1037 and 3037 represent the same event.

Event ID 1038 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1038 — The remote attestation request failed because the host started with dumps enabled.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148
Event IDs 1038 and 3038 represent the same event.

Event ID 1039 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1039 — The remote attestation request failed because the host did not start with dump encryption enabled.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149
Event IDs 1039 and 3039 represent the same event.

Event ID 1040 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1040 — The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server. Error:%1. If this is a valid host, you must first perform the following steps:
    1. On the host, configure dump encryption with a certificate.
    2. On the Attestation server, run the Add-HgsAttestationDumpPolicy cmdlet, specifying the SHA256 hash of the public key blob configured on the host.
Event IDs 1040 and 3040 represent the same event.

Fields

NameDescription
Message

Event ID 1041 — Local attestation initiated.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Local attestation initiated.

Event ID 1042 — No local health signing certificate was found.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

No local health signing certificate was found.  Attempting to generate a new certificate.

Event ID 1043 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 1043 — Remote attestation failed due to an invalid payload received by the Host Guardian Service.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.

Event ID 1044 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
StatusCode

Event ID 1044 — The endorsement key certificate could not be found in the TPM.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error: %1
Event IDs 1044 and 3044 represent the same event.

Fields

NameDescription
StatusCode

Event ID 1045 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
StatusCode

Event ID 1045 — The issuing intermediate certificate could not be found in the TPM for the endorsement key certificate.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Debug

Message

The issuing intermediate certificate could not be found in the TPM for the endorsement key certificate. The intermediate certificate is necessary for nested attestation; otherwise, this event may be ignored. Error: %1

Fields

NameDescription
StatusCode

Event ID 1046 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 1046 — The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server. Error: %1. To add the host key to the authorized list of host keys, perform the following steps:
    1. On this host, run the Get-HgsAttestationHostKey cmdlet to retrieve the necessary key material.
    2. On the Attestation server, run the Add-HgsAttestationHostKey cmdlet, specifying the file generatetd in the previous step.
EventIDs 1046 and 3046 represent the same event.

Fields

NameDescription
Message

Event ID 2000 — The requested WMI operation failed because access is denied.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The requested WMI operation failed because access is denied. You must be a member of the local 'Administrators' or 'NT VIRTUAL MACHINE\Virtual Machines' groups.

Event ID 2001 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
FirstMessage
SecondMessage

Event ID 2001 — The required value '.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The required value '%1' in registry key '%2' was not found.

Fields

NameDescription
FirstMessage
SecondMessage

Event ID 2002 — Successfully opened Shielded VM Local Certificates store.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Successfully opened Shielded VM Local Certificates store.

Event ID 2003 — No health signing certificate was found.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

No health signing certificate was found. Attempting to generate a new certificate.

Event ID 2004 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 2004 — The Host Guardian Service Client is unable to retrieve the encryption key (IDK) because Virtualization Based Security is not running on this system.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The Host Guardian Service Client is unable to retrieve the encryption key (IDK) because Virtualization Based Security is not running on this system. To resolve this issue, enable Virtualization Based Security and try again:

%1

Fields

NameDescription
Message

Event ID 2005 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 2005 — Unable to retrieve the local health certificate.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

Unable to retrieve the local health certificate: %1

Fields

NameDescription
Message

Event ID 2006 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 2006 — Failed to roll the transport key.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

Failed to roll the transport key: %1

Fields

NameDescription
Message

Event ID 2007 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 2007 — No signing certificates were found in the Shielded VM Local Certificates store.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

No signing certificates were found in the Shielded VM Local Certificates store.

Event ID 2008 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 2008 — No encryption certificates were found in the Shielded VM Local Certificates store.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

No encryption certificates were found in the Shielded VM Local Certificates store.

Event ID 2009 — Initiating unwrap of key protector.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Initiating unwrap of key protector.

Event ID 2010 — Initiating creation of a new of key protector.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Initiating creation of a new of key protector.

Event ID 2011 — Adding a guardian with signing certificate %1 and encryption certificate %2 to a key protector.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Adding a guardian with signing certificate %1 and encryption certificate %2 to a key protector.

Fields

NameDescription
FirstMessage
SecondMessage

Event ID 2012 — Initiating privileged unwrap of key protector.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Initiating privileged unwrap of key protector.

Event ID 2013 — Instantiating Host Guardian Service client in %1 mode.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Instantiating Host Guardian Service client in %1 mode.

Fields

NameDescription
Mode

Event ID 2014 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 2014 — The Host Guardian Service Client failed to unwrap a Key Protector on behalf of a calling process.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The Host Guardian Service Client failed to unwrap a Key Protector on behalf of a calling process. This event will normally correspond to a failure to startup a shielded virtual machine. Consult the description for further details. This could be related to an attestation issue, a Key Protection Server issue, or a network connectivity issue:

%1

Fields

NameDescription
Message

Event ID 2015 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 2015 — The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.

Event ID 2016 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 2016 — The signing certificate need set 'DigitalSignature' key usage.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The signing certificate need set 'DigitalSignature' key usage.

Event ID 2017 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 2017 — The encryption certificate need set 'DataEncipherment' key usage.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The encryption certificate need set 'DataEncipherment' key usage.

Event ID 2018 — Failures rolling the transport key as the health certificate is invalid.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Failures rolling the transport key as the health certificate is invalid. ErrorCode: %1, Validation Status: %2, Message: %3

Fields

NameDescription
ErrorCode
ValidationStatus
Message

Event ID 2019 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
CertificateDataLength
CertificateData

Event ID 2019 — Raw certificate dump.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Debug

Message

Raw certificate dump. Length(bytes)=%1 --> %2

Fields

NameDescription
CertificateDataLength
CertificateData

Event ID 2020 — The Host Guardian Service Client reused a cached health certificate issued in %1 mode that is valid until %2.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The Host Guardian Service Client reused a cached health certificate issued in %1 mode that is valid until %2.

Fields

NameDescription
OperationMode
CertificateValidTo

Event ID 2021 — The Host Guardian Service Client could not contact the Host Guardian Service.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The Host Guardian Service Client could not contact the Host Guardian Service.  The client will reattempt the operation using the following settings:

AttestationServerUrl: %1
KeyProtectionServerUrl: %2

Fields

NameDescription
FirstMessage
SecondMessage

Event ID 3007 — The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation se...

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation server. Error: %1. To add this host to the authorized list of host EKs, perform the following steps:
    1. On this host, run the Get-PlatformIdentifier cmdlet to retrieve the host EK in the form of a XML file.
    2. On the Attestation server, run the Add-HgsAttestationTpmHost cmdlet, specifying the file generated in the previous step.
Event IDs 1007 and 3007 represent the same event.

Fields

NameDescription
Message

Event ID 3008 — The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did ...

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did not match a valid baseline host. Error: %1. To ensure a successful attestation request, verify that the host configuration matches a valid baseline host. If this is a baseline host, you must first perform the following steps:
    1.  On this host, run the Get-HgsAttestationBaselinePolicy cmdlet to generate a policy file.
    2. On the attestation server, run the Add-HgsAttestationTpmPolicy cmdlet, specifying the policy file generated by the Get-HgsAttestationBaselinePolicy cmdlet. This adds the policy as a valid baseline TPM policy.
Event IDs 1008 and 3008 represent the same event.

Fields

NameDescription
Message

Event ID 3009 — The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation ser...

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation server. Error: %1. To ensure a successful attestation request, verify that this host is configured with a valid Code Integrity policy. For help, refer to http://go.microsoft.com/fwlink/?LinkId=734772
Event IDs 1009 and 3009 represent the same event.

Fields

NameDescription
Message

Event ID 3010 — The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server. Error: %1. To ensure a successful attestation request, verify that the host is a member of an authorized Active Directory host group. If the Active Directory host group is not authorized by the Attestation server, you must first perform the following steps:
    1. On the attestation server, run the Add-HgsAttestationHostGroup cmdlet to add it as a valid Active Directory host group.
Event IDs 1010 and 3010 represent the same event.

Fields

NameDescription
Message

Event ID 3013 — The remote attestation request failed because of a TPM error.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because of a TPM error. Try clearing and reprovisioning the TPM. Error: %1
Event IDs 1013 and 3013 represent the same event.

Fields

NameDescription
Message

Event ID 3019 — The remote attestation request failed because the Remote Attestation Service could not be reached.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the Remote Attestation Service could not be reached.
Event IDs 1019 and 3019 represent the same event.

Event ID 3020 — The remote attestation request failed.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed. Error: %1. For help, see http://go.microsoft.com/fwlink/?LinkId=735076
Event IDs 1020 and 3020 represent the same event.

Fields

NameDescription
Message

Event ID 3021 — The remote attestation request failed because this host was not booted correctly.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because this host was not booted correctly. Error: %1. To ensure a successful attestation request, verify that the host's most recent boot was a full boot.
Event IDs 1021 and 3021 represent the same event.

Fields

NameDescription
Message

Event ID 3022 — The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
Event IDs 1022 and 3022 represent the same event.

Fields

NameDescription
Message

Event ID 3024 — The remote attestation request failed because this host was not configured properly.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because this host was not configured properly. Error: %1. To ensure a successful attestation request, verify that the host's configuration contains an attestation service URL that is valid.
Event IDs 1024 and 3024 represent the same event.

Fields

NameDescription
Message

Event ID 3025 — The remote attestation request failed because Isolated User Mode could not be detected.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because Isolated User Mode could not be detected.  Verify that the Isolated User Mode feature is installed and that Virtualization Based Security has not been disabled manually or by local/domain-level policy.
Event IDs 1025 and 3025 represent the same event.

Fields

NameDescription
Message

Event ID 3026 — The remote attestation request failed because the TPM measurements were not valid.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the TPM measurements were not valid.  This can happen when the host utilizes unsupported TPM configurations, the Host Guardian Service client version is not supported by the server, or an attempt to tamper with the TPM Measurements was made.  Some PXE boot environments can also cause this issue; for help, refer to http://go.microsoft.com/fwlink/?LinkId=734770
Event IDs 1026 and 3026 represent the same event.

Fields

NameDescription
Message

Event ID 3027 — The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Event IDs 1027 and 3027 represent the same event.

Event ID 3028 — The remote attestation request failed because the host did not start with pagefile encryption enabled.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the host did not start with pagefile encryption enabled.
Event IDs 1028 and 3028 represent the same event.

Event ID 3029 — The remote attestation request failed because IOMMU was not required by the hypervisor.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because IOMMU was not required by the hypervisor. Verify that IOMMU is enabled and that it is explicity required for Virtual Secure Mode to launch. For help, refer to http://go.microsoft.com/fwlink/?LinkId=734842
Event IDs 1029 and 3029 represent the same event.

Event ID 3030 — The remote attestation request failed because the host did not start with BitLocker enabled.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the host did not start with BitLocker enabled.
Event IDs 1030 and 3030 represent the same event.

Event ID 3031 — The remote attestation request failed because code integrity was not required by the hypervisor.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because code integrity was not required by the hypervisor. Verify that code integrity is enabled and that it is being enforced by the hypervisor. For help, please refer to http://go.microsoft.com/fwlink/?LinkId=734841
Event IDs 1031 and 3031 represent the same event.

Event ID 3032 — The remote attestation request failed but no reason was given.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed but no reason was given. This typically indicates that the Host Guardian Service has not been fully configured with valid attestation policies.  If policies have been registered with the Host Guardian Service already, verify the functionality of the server and try again.
Event IDs 1032 and 3032 represent the same event.

Event ID 3034 — The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.
Event IDs 1034 and 3034 represent the same event.

Event ID 3035 — The remote attestation request failed because the Host Guardian Service could not be contacted.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the Host Guardian Service could not be contacted.  This happens when the request can reach the server but the service either does not respond or responds with an unknown HTTP error.  Verify that the Host Guardian Service is registered, started, and fully operational.
Error: %1
Event IDs 1035 and 3035 represent the same event.

Fields

NameDescription
Message

Event ID 3036 — The remote attestation request failed because it could not authenticate to the Host Guardian Service.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because it could not authenticate to the Host Guardian Service.  This can occur when using HTTPS with an invalid or untrusted certificate, or when using Active Directory-based attestation without configuring trust between this host's domain and the Host Guardian Service domain, preventing NTLM and Kerberos authentication from succeeding.
Error: %1
Event IDs 1036 and 3036 represent the same event.

Fields

NameDescription
Message

Event ID 3037 — The remote attestation request failed because the host started with hibernation enabled.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147
Event IDs 1037 and 3037 represent the same event.

Event ID 3038 — The remote attestation request failed because the host started with dumps enabled.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148
Event IDs 1038 and 3038 represent the same event.

Event ID 3039 — The remote attestation request failed because the host did not start with dump encryption enabled.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149
Event IDs 1039 and 3039 represent the same event.

Event ID 3040 — The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server. Error:%1. If this is a valid host, you must first perform the following steps:
    1. On the host, configure dump encryption with a certificate.
    2. On the Attestation server, run the Add-HgsAttestationDumpPolicy cmdlet, specifying the SHA256 hash of the public key blob configured on the host.
Event IDs 1040 and 3040 represent the same event.

Fields

NameDescription
Message

Event ID 3043 — Remote attestation failed due to an invalid payload received by the Host Guardian Service.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.

Event ID 3044 — The endorsement key certificate could not be found in the TPM.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error: %1
Event IDs 1044 and 3044 represent the same event.

Fields

NameDescription
StatusCode

Event ID 3046 — The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server. Error: %1. To add the host key to the authorized list of host keys, perform the following steps:
    1. On this host, run the Get-HgsAttestationHostKey cmdlet to retrieve the necessary key material.
    2. On the Attestation server, run the Add-HgsAttestationHostKey cmdlet, specifying the file generatetd in the previous step.
EventIDs 1046 and 3046 represent the same event.

Fields

NameDescription
Message

Event ID 4001 — The HGAttest API completed the operation with status code.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Message

The HGAttest API completed the operation with status code: %2. Operation: %1

Fields

NameDescription
Operation
ResultCode

Event ID 4002 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
Message

Event ID 4002 — The URL provided for SHS attestation is invalid.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

The URL provided for SHS attestation is invalid. URL: %1

Fields

NameDescription
Message

Event ID 4003 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 4003 — Attestation is not supported in this configuration.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

Attestation is not supported in this configuration.

Event ID 4004 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 4004 — Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.

Event ID 4005 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Event ID 4005 — Remote attestation for a CA Intermediate Certificate is currently not supported.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

Remote attestation for a CA Intermediate Certificate is currently not supported.

Event ID 4006 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
ClientOperationMode
ServerOperationMode

Event ID 4006 — This host attempted a remote attestation in %1 mode, but the targeted HGS server is operating in %2 mode.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

This host attempted a remote attestation in %1 mode, but the targeted HGS server is operating in %2 mode.

Fields

NameDescription
ClientOperationMode
ServerOperationMode

Event ID 5000 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
CertThumbprint

Event ID 5000 — A host key was set from certificate with thumbprint %1.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

A host key was set from certificate with thumbprint %1.

Fields

NameDescription
CertThumbprint

Event ID 5001 —

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Operational

Fields

NameDescription
CertThumbprint

Event ID 5001 — A host key was removed.

Provider
Microsoft-Windows-HostGuardianService-Client
Channel
Admin

Message

A host key was removed. It was from certificate with thumbprint %1.

Fields

NameDescription
CertThumbprint