Microsoft-Windows-HostGuardianService-Client
182 events across 4 channels
Event ID 100 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 101 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 102 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 103 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 104 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 105 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 109 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 110 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 111 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 112 — Started operation 'Message'.
Event ID 112 —
Description
Started operation 'Message'.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 113 — Operation 'OperationName' ended with result: 'StatusCode'.
Event ID 113 —
Description
Operation 'OperationName' ended with result: 'StatusCode'.
Fields #
| Name | Description |
|---|---|
OperationName UnicodeString | — |
StatusCode Int32 | — |
Event ID 200 — A new ActivityID has been generated.
Event ID 1002 — Remote attestation initiated.
Description
Remote attestation initiated.
Message #
Event ID 1003 — Remote attestation completed.
Event ID 1004 — ClientAttestationHttpRequestSend: ActivityID HostId.
Event ID 1004 —
Description
ClientAttestationHttpRequestSend: ActivityID.
Fields #
| Name | Description |
|---|---|
HostId UnicodeString | — |
Event ID 1005 — ClientAttestationHttpResponseReceived: Message.
Event ID 1005 —
Description
ClientAttestationHttpResponseReceived.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1006 — ClientAttestationHttpError: Message.
Event ID 1006 —
Description
ClientAttestationHttpError.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1007 — The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation se...
Event ID 1007 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1008 — The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did ...
Event ID 1008 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1009 — The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation ser...
Event ID 1009 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1010 — The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server.
Event ID 1010 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1012 — Determining TPM endorsement key failed.
Event ID 1012 —
Description
Determining TPM endorsement key failed. Error.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1013 — The remote attestation request failed because of a TPM error.
Event ID 1013 —
Description
The remote attestation request failed because of a TPM error. Try clearing and reprovisioning the TPM. Error.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1014 — Connection to Message failed.
Event ID 1014 —
Description
Connection to failed. Reconnecting to another IP.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1015 — Switching to Active Directory attestation mode.
Description
Switching to Active Directory attestation mode.
Message #
Event ID 1016 — Connecting to Remote Attestation service at Message.
Event ID 1016 —
Description
Connecting to Remote Attestation service at.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1017 — Reconnecting to Remote Attestation service at Message.
Event ID 1017 —
Description
Reconnecting to Remote Attestation service at.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1018 — Remote attestation succeeded and returned a health certificate with the thumbprint CertThumbprint.
Event ID 1019 — The remote attestation request failed because the Remote Attestation Service could not be reached.
Description
The remote attestation request failed because the Remote Attestation Service could not be reached.
Message #
Event ID 1019 —
Description
The remote attestation request failed because the Remote Attestation Service could not be reached.
Event ID 1020 — The remote attestation request failed.
Event ID 1020 —
Description
The remote attestation request failed. Error: . For help, see http://go.microsoft.com/fwlink/?LinkId=735076.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1021 — The remote attestation request failed because this host was not booted correctly.
Event ID 1021 —
Description
The remote attestation request failed because this host was not booted correctly. Error: . To ensure a successful attestation request, verify that the host's most recent boot was a full boot.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1022 — The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
Event ID 1022 —
Description
The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1023 — Determining TPM endorsement key failed.
Description
Determining TPM endorsement key failed. Switching to Active Directory attestation mode.
Message #
Event ID 1024 — The remote attestation request failed because this host was not configured properly.
Event ID 1024 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1025 — The remote attestation request failed because Isolated User Mode could not be detected.
Event ID 1025 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1026 — The remote attestation request failed because the TPM measurements were not valid.
Event ID 1026 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1027 — The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Description
The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Message #
Event ID 1027 —
Description
The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Event ID 1028 — The remote attestation request failed because the host did not start with pagefile encryption enabled.
Description
The remote attestation request failed because the host did not start with pagefile encryption enabled.
Message #
Event ID 1028 —
Description
The remote attestation request failed because the host did not start with pagefile encryption enabled.
Event ID 1029 — The remote attestation request failed because IOMMU was not required by the hypervisor.
Message #
Event ID 1029 —
Event ID 1030 — The remote attestation request failed because the host did not start with BitLocker enabled.
Description
The remote attestation request failed because the host did not start with BitLocker enabled.
Message #
Event ID 1030 —
Description
The remote attestation request failed because the host did not start with BitLocker enabled.
Event ID 1031 — The remote attestation request failed because code integrity was not required by the hypervisor.
Message #
Event ID 1031 —
Event ID 1032 — The remote attestation request failed but no reason was given.
Message #
Event ID 1032 —
Event ID 1033 — Switching to TPM attestation mode.
Description
Switching to TPM attestation mode.
Message #
Event ID 1034 — The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.
Description
The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.
Message #
Event ID 1034 —
Description
The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.
Event ID 1035 — The remote attestation request failed because the Host Guardian Service could not be contacted.
Event ID 1035 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1036 — The remote attestation request failed because it could not authenticate to the Host Guardian Service.
Event ID 1036 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1037 — The remote attestation request failed because the host started with hibernation enabled.
Description
The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147.
Message #
Event ID 1037 —
Description
The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147.
Event ID 1038 — The remote attestation request failed because the host started with dumps enabled.
Description
The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148.
Message #
Event ID 1038 —
Description
The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148.
Event ID 1039 — The remote attestation request failed because the host did not start with dump encryption enabled.
Description
The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149.
Message #
Event ID 1039 —
Description
The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149.
Event ID 1040 — The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server.
Event ID 1040 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 1041 — Local attestation initiated.
Description
Local attestation initiated.
Message #
Event ID 1042 — No local health signing certificate was found.
Description
No local health signing certificate was found. Attempting to generate a new certificate.
Message #
Event ID 1043 — Remote attestation failed due to an invalid payload received by the Host Guardian Service.
Description
Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.
Message #
Event ID 1043 —
Description
Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.
Event ID 1044 — The endorsement key certificate could not be found in the TPM.
Event ID 1044 —
Description
The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error.
Fields #
| Name | Description |
|---|---|
StatusCode Int32 | — |
Event ID 1045 — The issuing intermediate certificate could not be found in the TPM for the endorsement key certificate.
Event ID 1045 —
Fields #
| Name | Description |
|---|---|
StatusCode Int32 | — |
Event ID 1046 — The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server.
Event ID 1046 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 2000 — The requested WMI operation failed because access is denied.
Description
The requested WMI operation failed because access is denied. You must be a member of the local 'Administrators' or 'NT VIRTUAL MACHINE\Virtual Machines' groups.
Message #
Event ID 2001 — The required value 'FirstMessage' in registry key 'SecondMessage' was not found.
Event ID 2001 —
Description
The required value 'FirstMessage' in registry key 'SecondMessage' was not found.
Fields #
| Name | Description |
|---|---|
FirstMessage UnicodeString | — |
SecondMessage UnicodeString | — |
Event ID 2002 — Successfully opened Shielded VM Local Certificates store.
Description
Successfully opened Shielded VM Local Certificates store.
Message #
Event ID 2003 — No health signing certificate was found.
Description
No health signing certificate was found. Attempting to generate a new certificate.
Message #
Event ID 2004 — The Host Guardian Service Client is unable to retrieve the encryption key (IDK) because Virtualization Based Security is not running on this system.
Event ID 2004 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 2005 — Unable to retrieve the local health certificate: Message.
Event ID 2005 —
Description
Unable to retrieve the local health certificate.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 2006 — Failed to roll the transport key: Message.
Event ID 2006 —
Description
Failed to roll the transport key.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 2007 — No signing certificates were found in the Shielded VM Local Certificates store.
Description
No signing certificates were found in the Shielded VM Local Certificates store.
Message #
Event ID 2007 —
Description
No signing certificates were found in the Shielded VM Local Certificates store.
Event ID 2008 — No encryption certificates were found in the Shielded VM Local Certificates store.
Description
No encryption certificates were found in the Shielded VM Local Certificates store.
Message #
Event ID 2008 —
Description
No encryption certificates were found in the Shielded VM Local Certificates store.
Event ID 2009 — Initiating unwrap of key protector.
Description
Initiating unwrap of key protector.
Message #
Event ID 2010 — Initiating creation of a new of key protector.
Description
Initiating creation of a new of key protector.
Message #
Event ID 2011 — Adding a guardian with signing certificate FirstMessage and encryption certificate SecondMessage to a key protector.
Event ID 2012 — Initiating privileged unwrap of key protector.
Description
Initiating privileged unwrap of key protector.
Message #
Event ID 2013 — Instantiating Host Guardian Service client in Mode mode.
Event ID 2014 — The Host Guardian Service Client failed to unwrap a Key Protector on behalf of a calling process.
Event ID 2014 —
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 2015 — The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.
Description
The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.
Message #
Event ID 2015 —
Description
The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.
Event ID 2016 — The signing certificate need set 'DigitalSignature' key usage.
Description
The signing certificate need set 'DigitalSignature' key usage.
Message #
Event ID 2016 —
Description
The signing certificate need set 'DigitalSignature' key usage.
Event ID 2017 — The encryption certificate need set 'DataEncipherment' key usage.
Description
The encryption certificate need set 'DataEncipherment' key usage.
Message #
Event ID 2017 —
Description
The encryption certificate need set 'DataEncipherment' key usage.
Event ID 2018 — Failures rolling the transport key as the health certificate is invalid.
Event ID 2019 — Raw certificate dump.
Event ID 2019 —
Description
Raw certificate dump. Length(bytes)= -->.
Fields #
| Name | Description |
|---|---|
CertificateDataLength UInt32 | — |
CertificateData UInt8 | — |
Event ID 2020 — The Host Guardian Service Client reused a cached health certificate issued in OperationMode mode that is valid until CertificateValidTo.
Event ID 2021 — The Host Guardian Service Client could not contact the Host Guardian Service.
Event ID 3007 — The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation se...
Event ID 3008 — The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did ...
Event ID 3009 — The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation ser...
Event ID 3010 — The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server.
Event ID 3013 — The remote attestation request failed because of a TPM error.
Event ID 3019 — The remote attestation request failed because the Remote Attestation Service could not be reached.
Description
The remote attestation request failed because the Remote Attestation Service could not be reached.
Message #
Event ID 3020 — The remote attestation request failed.
Event ID 3021 — The remote attestation request failed because this host was not booted correctly.
Event ID 3022 — The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
Event ID 3024 — The remote attestation request failed because this host was not configured properly.
Event ID 3025 — The remote attestation request failed because Isolated User Mode could not be detected.
Event ID 3026 — The remote attestation request failed because the TPM measurements were not valid.
Event ID 3027 — The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Description
The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Message #
Event ID 3028 — The remote attestation request failed because the host did not start with pagefile encryption enabled.
Description
The remote attestation request failed because the host did not start with pagefile encryption enabled.
Message #
Event ID 3029 — The remote attestation request failed because IOMMU was not required by the hypervisor.
Message #
Event ID 3030 — The remote attestation request failed because the host did not start with BitLocker enabled.
Description
The remote attestation request failed because the host did not start with BitLocker enabled.
Message #
Event ID 3031 — The remote attestation request failed because code integrity was not required by the hypervisor.
Message #
Event ID 3032 — The remote attestation request failed but no reason was given.
Message #
Event ID 3034 — The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.
Description
The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.
Message #
Event ID 3035 — The remote attestation request failed because the Host Guardian Service could not be contacted.
Event ID 3036 — The remote attestation request failed because it could not authenticate to the Host Guardian Service.
Event ID 3037 — The remote attestation request failed because the host started with hibernation enabled.
Description
The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147.
Message #
Event ID 3038 — The remote attestation request failed because the host started with dumps enabled.
Description
The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148.
Message #
Event ID 3039 — The remote attestation request failed because the host did not start with dump encryption enabled.
Description
The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149.
Message #
Event ID 3040 — The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server.
Event ID 3043 — Remote attestation failed due to an invalid payload received by the Host Guardian Service.
Description
Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.
Message #
Event ID 3044 — The endorsement key certificate could not be found in the TPM.
Event ID 3046 — The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server.
Event ID 4001 — The HGAttest API completed the operation with status code: ResultCode.
Description
The HGAttest API completed the operation with status code: ResultCode. Operation: Operation.
Message #
Fields #
| Name | Description |
|---|---|
Operation UInt8 | — Known values
|
ResultCode UInt32 | — |
Event ID 4002 — The URL provided for SHS attestation is invalid.
Event ID 4002 —
Description
The URL provided for SHS attestation is invalid. URL.
Fields #
| Name | Description |
|---|---|
Message UnicodeString | — |
Event ID 4003 — Attestation is not supported in this configuration.
Description
Attestation is not supported in this configuration.
Message #
Event ID 4003 —
Description
Attestation is not supported in this configuration.
Event ID 4004 — Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.
Description
Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.
Message #
Event ID 4004 —
Description
Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.
Event ID 4005 — Remote attestation for a CA Intermediate Certificate is currently not supported.
Description
Remote attestation for a CA Intermediate Certificate is currently not supported.
Message #
Event ID 4005 —
Description
Remote attestation for a CA Intermediate Certificate is currently not supported.
Event ID 4006 — This host attempted a remote attestation in ClientOperationMode mode, but the targeted HGS server is operating in ServerOperationMode mode.
Event ID 4006 —
Description
This host attempted a remote attestation in mode, but the targeted HGS server is operating in mode.
Fields #
| Name | Description |
|---|---|
ClientOperationMode UInt8 | — |
ServerOperationMode UInt8 | — |
Event ID 5000 — A host key was set from certificate with thumbprint CertThumbprint.
Event ID 5000 —
Description
A host key was set from certificate with thumbprint .
Fields #
| Name | Description |
|---|---|
CertThumbprint UnicodeString | — |
Event ID 5001 — A host key was removed.
Event ID 5001 —
Description
A host key was removed. It was from certificate with thumbprint .
Fields #
| Name | Description |
|---|---|
CertThumbprint UnicodeString | — |