Microsoft-Windows-LAPS

110 events across 1 channel

Event IDTitleChannel
10000The Local Administrator Password feature was successfully loaded and …Operational
10001The Local Administrator Password dll failed to initialize.Operational
10002The Local Administrator Password dll was unloaded.Operational
10003LAPS policy processing is now starting.Operational
10004LAPS policy processing succeeded.Operational
10005LAPS policy processing failed with the error code below.Operational
10006LAPS password encryption is required but the Active Directory domain is not yet …Operational
10007LAPS is not currently configured to manage any account.Operational
10008LAPS policy is currently not supported on domain controllers.Operational
10009LAPS is configured to backup passwords to Active Directory.Operational
10010LAPS is configured to backup passwords to Azure Active Directory.Operational
10011LAPS failed when querying Active Directory for the current computer state.Operational
10012The Active Directory schema has not been updated with the necessary LAPS …Operational
10013LAPS failed to find the currently configured local administrator account.Operational
10014LAPS is updating the managed account password due to an Administrator-initiated …Operational
10015The managed account password needs to be updated due to one or more reasons …Operational
10016The managed account password does not need to be updated at this time.Operational
10017LAPS failed to update Active Directory with the new password.Operational
10018LAPS successfully updated Active Directory with the new password.Operational
10019LAPS failed to update the local admin account with the new password.Operational
10020LAPS successfully updated the local admin account with the new password.Operational
10021The current LAPS policy is configured as follows: Policy source: %1 Backup …Operational
10022The current LAPS policy is configured as follows: Policy source: %1 Backup …Operational
10023The current LAPS policy is configured as follows: Policy source: %1 Backup …Operational
10024LAPS policy is configured as disabled.Operational
10025Azure discovery failed.Operational
10026LAPS was unable to authenticate to Azure using the device identity.Operational
10027LAPS was unable to create an acceptable new password.Operational
10028LAPS failed to update Azure Active Directory with the new password.Operational
10029LAPS successfully updated Azure Active Directory with the new password.Operational
10030LAPS is sending a message to the following endpoint.Operational
10031LAPS blocked an external request that tried to modify the password of the …Operational
10032LAPS was unable to authenticate to Azure using the device identity.Operational
10033The machine is configured with legacy LAPS policy settings but a legacy LAPS …Operational
10034The configured encryption principal is an isolated (ambiguous) name.Operational
10035The configured encryption principal name could not be mapped to a known account.Operational
10036The SID for the configured encryption principal could not be mapped to a known …Operational
10037The DSRM account cannot be managed because password encryption is disabled.Operational
10038LAPS failed to update the DSRM administrator account with the new password.Operational
10039LAPS successfully updated the DSRM administrator account with the new password.Operational
10040LAPS blocked an external request that tried to modify the password of the …Operational
10041LAPS detected a successful authentication for the currently managed account.Operational
10042The post-authentication grace period has expired per policy.Operational
10043LAPS failed to reset the password for the currently managed account.Operational
10044LAPS successfully reset the password for the currently managed account and …Operational
10045LAPS successfully reset the password for the currently managed account.Operational
10046LAPS was scheduled to reset the password for the currently managed account after …Operational
10047A pending post-authentication reset timer has been rescheduled after a reboot.Operational
10048The currently pending post-authentication reset timer has been retried the …Operational
10049LAPS attempted to reboot the machine as a post-authentication action but the …Operational
10050LAPS is updating the managed account password due to an Azure-initiated request.Operational
10051LAPS is updating the managed account password in response to a …Operational
10052LAPS is processing the current policy per normal background scheduling.Operational
10053LAPS is processing the current policy in response to an Administrator request.Operational
10054LAPS is processing the current policy in response to a Group Policy change …Operational
10055LAPS is using the following domain controller: DCName: %1 See https://go.Operational
10056LAPS failed to locate a writable domain controller.Operational
10057LAPS was unable to bind over LDAP to the domain controller: % DCName: %1 Error …Operational
10058The current policy is configured to backup the password to Azure Active …Operational
10059Azure returned a failure code.Operational
10060The current policy is configured to backup the password to Azure Active …Operational
10061The current policy is configured to backup the password to Azure Active …Operational
10062The current policy is configured to backup the password to Active Directory, but …Operational
10063The current policy is configured to backup the password to Active Directory, but …Operational
10064The current policy is configured to backup the DSRM account password to Active …Operational
10065LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password …Operational
10066LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password …Operational
10067The configured local account is currently disabled.Operational
10068This device has been joined to Azure AD.Operational
10069This device has been unjoined from Azure AD.Operational
10070This device has been joined to Active Directory.Operational
10071This device has been unjoined from Active Directory.Operational
10072Encryption of the new password failed.Operational
10073LAPS is now executing the configured post-authentication actions for the target …Operational
10074LAPS has successfully completed all configured post-authentication actions for …Operational
10075LAPS has completed all configured post-authentication actions for the …Operational
10076A post-authentication action was pending for the account below, but the current …Operational
10077LAPS found %1 interactive logon sessions using the managed account.Operational
10078LAPS successfully notified the following session that a logoff is pending …Operational
10079LAPS failed to notify the following session that a logoff is pending shortly.Operational
10080LAPS is now pausing for %1 seconds to give the notified sessions time to logoff.Operational
10081LAPS is now logging off all notified sessions.Operational
10082LAPS successfully logged off the following session.Operational
10083LAPS received an error trying to log off the following session.Operational
10084LAPS found %1 file share sessions using the managed account.Operational
10085LAPS successfully deleted the following file share session.Operational
10086LAPS failed to disconnect the following file share session.Operational
10087LAPS found %1 processes using the managed account.Operational
10088LAPS successfully terminated the following process.Operational
10089LAPS failed to terminate the following process.Operational
10090The LAPS managed account was enabled.Operational
10091The LAPS managed account was disabled.Operational
10092The LAPS policy is configured for automatic account management mode, but the …Operational
10093The current automatically LAPS managed account was renamed.Operational
10094LAPS failed to rename the managed account.Operational
10095LAPS failed to enable the managed account.Operational
10096LAPS failed to disable the managed account.Operational
10097LAPS deleted the previously managed account.Operational
10098LAPS failed to delete the previously managed account.Operational
10099LAPS renamed and disabled the previously managed builtin administrator account.Operational
10100LAPS failed to rename and disable the previously managed builtin administrator …Operational
10101LAPS blocked an external request that attempted to modify the current …Operational
10102LAPS blocked an external request that attempted to delete the current …Operational
10103LAPS blocked an external request that attempted to modify the security …Operational
10104LAPS blocked an external request that attempted to remove the current …Operational
10105LAPS failed to update its local registry state.Operational
10106LAPS has successfully completed all sysprep cleanup operations.Operational
10107LAPS failed to complete one or more sysprep cleanup operations.Operational
10108The msLAPSCurrentPasswordVersion attribute has not been added to the Active …Operational
20000One or more Local Administrator Password Solution (LAPS) MDM policy values were …Operational

Event ID 10000 — The Local Administrator Password feature was successfully loaded and initialized.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The Local Administrator Password feature was successfully loaded and initialized.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10001 — The Local Administrator Password dll failed to initialize.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The Local Administrator Password dll failed to initialize.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10002 — The Local Administrator Password dll was unloaded.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The Local Administrator Password dll was unloaded.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10003 — LAPS policy processing is now starting.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS policy processing is now starting.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10004 — LAPS policy processing succeeded.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS policy processing succeeded.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10005 — LAPS policy processing failed with the error code below.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS policy processing failed with the error code below.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Error_code
Data1

Event ID 10006 — LAPS password encryption is required but the Active Directory domain is not yet at 2016 domain functional level.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS password encryption is required but the Active Directory domain is not yet at 2016 domain functional level. The password was not updated and no changes will be made until this is corrected.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10007 — LAPS is not currently configured to manage any account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is not currently configured to manage any account.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10008 — LAPS policy is currently not supported on domain controllers.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS policy is currently not supported on domain controllers.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10009 — LAPS is configured to backup passwords to Active Directory.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is configured to backup passwords to Active Directory.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10010 — LAPS is configured to backup passwords to Azure Active Directory.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is configured to backup passwords to Azure Active Directory.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10011 — LAPS failed when querying Active Directory for the current computer state.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed when querying Active Directory for the current computer state.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Error_code
Data1

Event ID 10012 — The Active Directory schema has not been updated with the necessary LAPS attributes.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The Active Directory schema has not been updated with the necessary LAPS attributes.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10013 — LAPS failed to find the currently configured local administrator account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to find the currently configured local administrator account.
 
 Account name: %1
 Error code: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Error_code
Data1
Data2

Event ID 10014 — LAPS is updating the managed account password due to an Administrator-initiated request.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is updating the managed account password due to an Administrator-initiated request.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10015 — The managed account password needs to be updated due to one or more reasons (%1): %2 See https://go.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The managed account password needs to be updated due to one or more reasons (%1):
 
 %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2

Event ID 10016 — The managed account password does not need to be updated at this time.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The managed account password does not need to be updated at this time.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10017 — LAPS failed to update Active Directory with the new password.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to update Active Directory with the new password. The current password has not been modified.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Error_code
Data1

Event ID 10018 — LAPS successfully updated Active Directory with the new password.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS successfully updated Active Directory with the new password.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10019 — LAPS failed to update the local admin account with the new password.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to update the local admin account with the new password.
 
 Account name: %1
 Account RID: %2
 Error code: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Account_RID
Error_code
Data1
Data2
Data3

Event ID 10020 — LAPS successfully updated the local admin account with the new password.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS successfully updated the local admin account with the new password.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Account_RID
Data1
Data2

Event ID 10021 — The current LAPS policy is configured as follows: Policy source: %1 Backup directory: %2 Local administrator account name: %3 Password age in days:...

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The current LAPS policy is configured as follows:
 
 Policy source: %1
 Backup directory: %2
 Local administrator account name: %3
 Password age in days: %4
 Password complexity: %5
 Password length: %6
 Password expiration protection enabled: %7
 Password encryption enabled: %8
 Password encryption target principal: %9
 Password encrypted history size: %10
 Backup DSRM password on domain controllers: %11
 Post authentication grace period (hours): %12
 Post authentication actions: %13
 Automatic account management enabled: %14
 Automatic account management: Target: %15
 Automatic account management: Name or name prefix: %16
 Automatic account management: Account enabled: %17
 Automatic account management: Randomize name: %18
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
PolicySource
BackupDirectory
AdminAccountName
PasswordAgeDays
PasswordComplexity
PasswordLength
PasswordExpirationProtectionEnabled
PasswordEncryptionEnabled
PasswordEncryptionTargetPrincipal
PasswordEncryptionHistorySize
BackupDSRMPassword
PostAuthResetDelay
PostAuthActions
AutomaticAccountManagementEnabled
AutomaticAccountManagementTarget
AutomaticAccountManagementNameOrPrefix
AutomaticAccountManagementEnableAccount
AutomaticAccountManagementRandomizeName

Event ID 10022 — The current LAPS policy is configured as follows: Policy source: %1 Backup directory: %2 Local administrator account name: %3 Password age in days:...

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The current LAPS policy is configured as follows:
 
 Policy source: %1
 Backup directory: %2
 Local administrator account name: %3
 Password age in days: %4
 Password complexity: %5
 Password length: %6
 Post authentication grace period (hours): %7
 Post authentication actions: %8
 Automatic account management enabled: %9
 Automatic account management: Target: %10
 Automatic account management: Name or name prefix: %11
 Automatic account management: Account enabled: %12
 Automatic account management: Randomize name: %13
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
PolicySource
BackupDirectory
AdminAccountName
PasswordAgeDays
PasswordComplexity
PasswordLength
PostAuthResetDelay
PostAuthActions
AutomaticAccountManagementEnabled
AutomaticAccountManagementTarget
AutomaticAccountManagementNameOrPrefix
AutomaticAccountManagementEnableAccount
AutomaticAccountManagementRandomizeName

Event ID 10023 — The current LAPS policy is configured as follows: Policy source: %1 Backup directory: %2 Local administrator account name: %3 Password age in days:...

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The current LAPS policy is configured as follows:
 
 Policy source: %1
 Backup directory: %2
 Local administrator account name: %3
 Password age in days: %4
 Password complexity: %5
 Password length: %6
 Password expiration protection enabled: %7
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
PolicySource
BackupDirectory
AdminAccountName
PasswordAgeDays
PasswordComplexity
PasswordLength
PasswordExpirationProtectionEnabled

Event ID 10024 — LAPS policy is configured as disabled.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS policy is configured as disabled.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10025 — Azure discovery failed.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

Azure discovery failed.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Error_code
Data1

Event ID 10026 — LAPS was unable to authenticate to Azure using the device identity.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS was unable to authenticate to Azure using the device identity.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Error_code
Data1

Event ID 10027 — LAPS was unable to create an acceptable new password.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS was unable to create an acceptable new password. Please verify that the LAPS password length and complexity policy is compatible with the domain and local password policy settings.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Error_code
Data1

Event ID 10028 — LAPS failed to update Azure Active Directory with the new password.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to update Azure Active Directory with the new password.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Error_code
Data1

Event ID 10029 — LAPS successfully updated Azure Active Directory with the new password.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS successfully updated Azure Active Directory with the new password.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10030 — LAPS is sending a message to the following endpoint.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is sending a message to the following endpoint.
 
 %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1

Event ID 10031 — LAPS blocked an external request that tried to modify the password of the current managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS blocked an external request that tried to modify the password of the current managed account.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Account_RID
Data1
Data2

Event ID 10032 — LAPS was unable to authenticate to Azure using the device identity.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS was unable to authenticate to Azure using the device identity.
 
 Web status: %1(%2)
 Error code: %3
 Hresult: %4
 Error msg: %5
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Web_status
Error_code
Hresult
Error_msg
Data1
Data2
Data3
Data4
Data5

Event ID 10033 — The machine is configured with legacy LAPS policy settings but a legacy LAPS product appears to be installed.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The machine is configured with legacy LAPS policy settings but a legacy LAPS product appears to be installed. The configured account's password will not be managed by Windows until the legacy product is uninstalled. Alternatively you may consider configuring the newer LAPS policy settings.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10034 — The configured encryption principal is an isolated (ambiguous) name.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The configured encryption principal is an isolated (ambiguous) name. This must be corrected before the configured account's password can be managed. Please specify the name in either user@domain.com or domain\user format.
 
 Encryption principal name: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Encryption_principal_name
Data1

Event ID 10035 — The configured encryption principal name could not be mapped to a known account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The configured encryption principal name could not be mapped to a known account. This must be corrected before the configured account's password can be managed. 
 
 Encryption principal name: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Encryption_principal_name
Data1

Event ID 10036 — The SID for the configured encryption principal could not be mapped to a known account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The SID for the configured encryption principal could not be mapped to a known account. This must be corrected before the configured account's password can be managed. 
 
 Encryption principal SID: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Encryption_principal_SID
Data1

Event ID 10037 — The DSRM account cannot be managed because password encryption is disabled.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The DSRM account cannot be managed because password encryption is disabled. Please enable password encryption in the LAPS policy settings in order to enable DSRM account password management.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10038 — LAPS failed to update the DSRM administrator account with the new password.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to update the DSRM administrator account with the new password.
 
 DSRM account name: %1
 DSRM account RID: %2
 Error code: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
DSRM_account_name
DSRM_account_RID
Error_code
Data1
Data2
Data3

Event ID 10039 — LAPS successfully updated the DSRM administrator account with the new password.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS successfully updated the DSRM administrator account with the new password.
 
 DSRM account name: %1
 DSRM account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
DSRM_account_name
DSRM_account_RID
Data1
Data2

Event ID 10040 — LAPS blocked an external request that tried to modify the password of the currently managed DSRM account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS blocked an external request that tried to modify the password of the currently managed DSRM account.
 
 Account RID: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_RID
Data1

Event ID 10041 — LAPS detected a successful authentication for the currently managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS detected a successful authentication for the currently managed account. A background task has been scheduled to execute the configured post-authentication actions after the configured grace period has expired.
 
 Account name: %1
 Account RID: %2
 Password reset timer deadline: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Account_RID
Password_reset_timer_deadline
Data1
Data2
Data3

Event ID 10042 — The post-authentication grace period has expired per policy.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The post-authentication grace period has expired per policy. The configured post-authentication actions will now be executed.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Account_RID
Data1
Data2

Event ID 10043 — LAPS failed to reset the password for the currently managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to reset the password for the currently managed account. The password is considered expired due to an authentication event. LAPS will continue retrying the password reset operation until it succeeds.
 
 Account name: %1
 Account RID: %2
 Password reset retry count: %3
 Error code: %4
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Account_RID
Password_reset_retry_count
Error_code
Data1
Data2
Data3
Data4

Event ID 10044 — LAPS successfully reset the password for the currently managed account and completed all configured post-authentication actions.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS successfully reset the password for the currently managed account after the expiration of the post-authentication grace period.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Account_RID
Data1
Data2

Event ID 10045 — LAPS successfully reset the password for the currently managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS successfully reset the password for the currently managed account. One or more configured post-authentication actions failed. The operations will not be retried.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Account_RID
Data1
Data2

Event ID 10046 — LAPS was scheduled to reset the password for the currently managed account after expiry of the grace period after a previous authentication event.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS was scheduled to reset the password for the currently managed account after expiration of the grace period after a previous authentication event. However a password reset has already occurred so it will not be reset again. Remaining post-authentication actions will still be executed.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Account_RID
Data1
Data2

Event ID 10047 — A pending post-authentication reset timer has been rescheduled after a reboot.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

A pending post-authentication reset timer has been rescheduled after a reboot.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10048 — The currently pending post-authentication reset timer has been retried the maximum allowed number attempts and will no longer be scheduled.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The currently pending post-authentication reset timer has been retried the maximum allowed number attempts and will no longer be scheduled.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10049 — LAPS attempted to reboot the machine as a post-authentication action but the operation failed.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS attempted to reboot the machine as a post-authentication action but the operation failed.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Error_code
Data1

Event ID 10050 — LAPS is updating the managed account password due to an Azure-initiated request.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is updating the managed account password due to an Azure-initiated request.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10051 — LAPS is updating the managed account password in response to a post-authentication action.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is updating the managed account password in response to a post-authentication action.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10052 — LAPS is processing the current policy per normal background scheduling.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is processing the current policy per normal background scheduling.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10053 — LAPS is processing the current policy in response to an Administrator request.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is processing the current policy in response to an Administrator request.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10054 — LAPS is processing the current policy in response to a Group Policy change notification.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is processing the current policy in response to a Group Policy change notification.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10055 — LAPS is using the following domain controller: DCName: %1 See https://go.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is using the following domain controller:
 
 DCName: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
DCName[LAPS is using the following domain controller] DCName.
Data1

Event ID 10056 — LAPS failed to locate a writable domain controller.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to locate a writable domain controller.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Error_code
Data1

Event ID 10057 — LAPS was unable to bind over LDAP to the domain controller: % DCName: %1 Error code: %2 See https://go.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS was unable to bind over LDAP to the domain controller:
 %
 DCName: %1
 Error code: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
DCName[LAPS was unable to bind over LDAP to the domain controller] DCName.
Error_code[LAPS was unable to bind over LDAP to the domain controller] Error code.
Data1
Data2

Event ID 10058 — The current policy is configured to backup the password to Azure Active Directory, but has a configured PasswordAgeDays value that is less than the...

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The current policy is configured to backup the password to Azure Active Directory, but has a configured PasswordAgeDays value that is less than the required minimum:
 
 Configured value: %1
 Minimum value: %2
 
 The configured value will be ignored and the minimum value will be used instead.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Configured_value[The current policy is configured to backup the password to Azure Active Directory, but has a configured PasswordAgeDays value that is less than the required minimum] Configured value.
Minimum_value[The current policy is configured to backup the password to Azure Active Directory, but has a configured PasswordAgeDays value that is less than the required minimum] Minimum value.
Data1
Data2

Event ID 10059 — Azure returned a failure code.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

Azure returned a failure code.
 
 HTTP status code: %1
 
 Response text:
 %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
HTTP_status_code
Response_text
Data1
Data2

Event ID 10060 — The current policy is configured to backup the password to Azure Active Directory, but the machine is only joined to Active Directory.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The current policy is configured to backup the password to Azure Active Directory, but the machine is only joined to Active Directory. Please configure the policy to backup the password to Active Directory. No action will be taken until this is corrected.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10061 — The current policy is configured to backup the password to Azure Active Directory, but the machine is workplace-joined.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The current policy is configured to backup the password to Azure Active Directory, but the machine is workplace-joined. LAPS does not support workplace-joined machines for any scenario.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10062 — The current policy is configured to backup the password to Active Directory, but the machine is only joined to Azure Active Directory.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The current policy is configured to backup the password to Active Directory, but the machine is only joined to Azure Active Directory. Please configure the policy to backup the password to Azure Active Directory. No action will be taken until this is corrected.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10063 — The current policy is configured to backup the password to Active Directory, but the machine is workplace-joined.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The current policy is configured to backup the password to Active Directory, but the machine is workplace-joined. LAPS does not support workplace-joined machines for any scenario.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10064 — The current policy is configured to backup the DSRM account password to Active Directory, but password encryption is not enabled.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The current policy is configured to backup the DSRM account password to Active Directory, but password encryption is not enabled. Please configure the policy to enable password encryption. No action will be taken until this is corrected.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10065 — LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password using the legacy LAPS password attribute.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password using the legacy LAPS password attribute. You should update the permissions on this computer's container using the Update-AdmPwdComputerSelfPermission cmdlet, for example:
 
 Update-AdmPwdComputerSelfPermission -Identity '%1' 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1

Event ID 10066 — LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password using the LAPS password attribute.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password using the LAPS password attribute. You should update the permissions on this computer's container using the Set-LapsADComputerSelfPermission cmdlet, for example:
 
 Set-LapsADComputerSelfPermission -Identity '%1' 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1

Event ID 10067 — The configured local account is currently disabled.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The configured local account is currently disabled. The account must be enabled before it can be used.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Account_name
Account_RID
Data1
Data2

Event ID 10068 — This device has been joined to Azure AD.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

This device has been joined to Azure AD. This message is informational only and no action is necessary.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10069 — This device has been unjoined from Azure AD.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

This device has been unjoined from Azure AD. This message is informational only and no action is necessary.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10070 — This device has been joined to Active Directory.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

This device has been joined to Active Directory. This message is informational only and no action is necessary.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10071 — This device has been unjoined from Active Directory.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

This device has been unjoined from Active Directory. This message is informational only and no action is necessary.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10072 — Encryption of the new password failed.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

Encryption of the new password failed.
 
 Error code: %1
 
 This problem may occur if a KDS root key is not available. Verify that a KDS root key is available by running the Get-KdsRootKey PowerShell cmdlet, and also verify that the root key's EffectiveTime field is valid right now.
 
 If a KDS root key is not present, you must add one by running the Add-KdsRootKey PowerShell cmdlet with the -EffectiveImmediately parameter. Allow sufficient time for the new key to replicate around your forest.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Error_code
Data1

Event ID 10073 — LAPS is now executing the configured post-authentication actions for the target account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is now executing the configured post-authentication actions for the target account.
 
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2

Event ID 10074 — LAPS has successfully completed all configured post-authentication actions for the LAPS-managed account identity.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS has successfully completed all configured post-authentication actions for the LAPS-managed account identity.
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2

Event ID 10075 — LAPS has completed all configured post-authentication actions for the LAPS-managed account identity.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS has completed all configured post-authentication actions for the LAPS-managed account identity. One or more of these actions encountered a failure. See the other intervening event log messages for more details.
 
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2

Event ID 10076 — A post-authentication action was pending for the account below, but the current policy is now targeting a different account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

A post-authentication action was pending for the account below, but the current policy is now targeting a different account. No post-authentication actions for the original account will be executed.
 
 Original account sid: %1
 Current account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2

Event ID 10077 — LAPS found %1 interactive logon sessions using the managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS found %1 interactive logon sessions using the managed account.
 
 Account name: %2
 Account sid: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2
Data3

Event ID 10078 — LAPS successfully notified the following session that a logoff is pending shortly.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS successfully notified the following session that a logoff is pending shortly.
 
 ExecEnvId: %1
 State: %2
 SessionId: %3
 Session name: %4
 Host name: %5
 User name: %6
 Domain name: %7
 Farm name: %8
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
ExecEnvId
State
SessionId
SessionName
HostName
UserName
DomainName
FarmName

Event ID 10079 — LAPS failed to notify the following session that a logoff is pending shortly.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to notify the following session that a logoff is pending shortly. The logoff action will proceed regardless.
 
 ExecEnvId: %1
 State: %2
 SessionId: %3
 Session name: %4
 Host name: %5
 User name: %6
 Domain name: %7
 Farm name: %8
 
 Error: %9
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
ExecEnvId
State
SessionId
SessionName
HostName
UserName
DomainName
FarmName
Error

Event ID 10080 — LAPS is now pausing for %1 seconds to give the notified sessions time to logoff.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is now pausing for %1 seconds to give the notified sessions time to logoff.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1

Event ID 10081 — LAPS is now logging off all notified sessions.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS is now logging off all notified sessions.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10082 — LAPS successfully logged off the following session.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS successfully logged off the following session.
 
 ExecEnvId: %1
 State: %2
 SessionId: %3
 Session name: %4
 Host name: %5
 User name: %6
 Domain name: %7
 Farm name: %8
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
ExecEnvId
State
SessionId
SessionName
HostName
UserName
DomainName
FarmName

Event ID 10083 — LAPS received an error trying to log off the following session.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS received an error trying to log off the following session. This action will not be retried.
 
 ExecEnvId: %1
 State: %2
 SessionId: %3
 Session name: %4
 Host name: %5
 User name: %6
 Domain name: %7
 Farm name: %8
 
 Error: %9
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
ExecEnvId
State
SessionId
SessionName
HostName
UserName
DomainName
FarmName
Error

Event ID 10084 — LAPS found %1 file share sessions using the managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS found %1 file share sessions using the managed account.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1

Event ID 10085 — LAPS successfully deleted the following file share session.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS successfully deleted the following file share session.
 
 SessionId: %1
 ClientComputerName: %2
 ClientUserName: %3
 NumOpens: %4
 SecondsIdle: %5
 SecondsExisted: %6
 ServerName: %7
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
SessionId
ClientComputerName
ClientUserName
NumOpens
SecondsIdle
SecondsExisted
ServerName

Event ID 10086 — LAPS failed to disconnect the following file share session.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to disconnect the following file share session. This action will not be retried.
 
 SessionId: %1
 ClientComputerName: %2
 ClientUserName: %3
 NumOpens: %4
 SecondsIdle: %5
 SecondsExisted: %6
 ServerName: %7
 
 Error: %8
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
SessionId
ClientComputerName
ClientUserName
NumOpens
SecondsIdle
SecondsExisted
ServerName
Error

Event ID 10087 — LAPS found %1 processes using the managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS found %1 processes using the managed account.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1

Event ID 10088 — LAPS successfully terminated the following process.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS successfully terminated the following process.
 
 Path: %1
 Process id: %2
 Account name: %3
 Account sid: %4
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2
Data3
Data4

Event ID 10089 — LAPS failed to terminate the following process.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to terminate the following process. This action will not be retried.
 
 Path: %1
 Process id: %2
 Account name: %3
 Account sid: %4
 Error: %5
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2
Data3
Data4
Data5

Event ID 10090 — The LAPS managed account was enabled.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The LAPS managed account was enabled.
 
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2

Event ID 10091 — The LAPS managed account was disabled.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The LAPS managed account was disabled.
 
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2

Event ID 10092 — The LAPS policy is configured for automatic account management mode, but the account name or prefix is too long and will be truncated.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The LAPS policy is configured for automatic account management mode, but the account name or prefix is too long and will be truncated. The maximum allowable length is 20 characters when account name randomization is disabled, or 14 characters when account name randomization is enabled.
 
 Configured account name or prefix: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1

Event ID 10093 — The current automatically LAPS managed account was renamed.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The current automatically LAPS managed account was renamed.
 
 Previous account name: %1
 New account name: %2
 Account sid: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2
Data3

Event ID 10094 — LAPS failed to rename the managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to rename the managed account.
 
 Account name: %1
 Account sid: %2
 Intended new account name: %3
 Error: %4
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2
Data3
Data4

Event ID 10095 — LAPS failed to enable the managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to enable the managed account.
 
 Account name: %1
 Account sid: %2
 Error: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2
Data3

Event ID 10096 — LAPS failed to disable the managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to disable the managed account.
 
 Account name: %1
 Account sid: %2
 Error: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2
Data3

Event ID 10097 — LAPS deleted the previously managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS deleted the previously managed account.
 
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2

Event ID 10098 — LAPS failed to delete the previously managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to delete the previously managed account.
 
 Account name: %1
 Account sid: %2
 Error: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2
Data3

Event ID 10099 — LAPS renamed and disabled the previously managed builtin administrator account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS renamed and disabled the previously managed builtin administrator account.
 
 Previous account name: %1
 New account name: %2
 Account sid: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2
Data3

Event ID 10100 — LAPS failed to rename and disable the previously managed builtin administrator account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to rename and disable the previously managed builtin administrator account.
 
 Account sid: %1
 Error: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1
Data2

Event ID 10101 — LAPS blocked an external request that attempted to modify the current automatically managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS blocked an external request that attempted to modify the current automatically managed account.
 
 Account name: %1
 Account sid: %2
 Client name: %3
 Client address: %4
 Client process ID: %5
 Client process exe: %6
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
LAPSManagedAccountName
LAPSManagedAccountSid
ClientName
ClientAddress
ClientProcessID
ClientProcessExe

Event ID 10102 — LAPS blocked an external request that attempted to delete the current automatically managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS blocked an external request that attempted to delete the current automatically managed account.
 
 Account name: %1
 Account sid: %2
 Client name: %3
 Client address: %4
 Client process ID: %5
 Client process exe: %6
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
LAPSManagedAccountName
LAPSManagedAccountSid
ClientName
ClientAddress
ClientProcessID
ClientProcessExe

Event ID 10103 — LAPS blocked an external request that attempted to modify the security descriptor of the current automatically managed account.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS blocked an external request that attempted to modify the security descriptor of the current automatically managed account.
 
 Account name: %1
 Account sid: %2
 Client name: %3
 Client address: %4
 Client process ID: %5
 Client process exe: %6
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
LAPSManagedAccountName
LAPSManagedAccountSid
ClientName
ClientAddress
ClientProcessID
ClientProcessExe

Event ID 10104 — LAPS blocked an external request that attempted to remove the current automatically managed account from the local administrators group.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS blocked an external request that attempted to remove the current automatically managed account from the local administrators group.
 
 Account name: %1
 Account sid: %2
 Client name: %3
 Client address: %4
 Client process ID: %5
 Client process exe: %6
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
LAPSManagedAccountName
LAPSManagedAccountSid
ClientName
ClientAddress
ClientProcessID
ClientProcessExe

Event ID 10105 — LAPS failed to update its local registry state.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to update its local registry state.
 
 Error: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1

Event ID 10106 — LAPS has successfully completed all sysprep cleanup operations.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS has successfully completed all sysprep cleanup operations.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10107 — LAPS failed to complete one or more sysprep cleanup operations.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

LAPS failed to complete one or more sysprep cleanup operations.
 
 Error: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields

NameDescription
Data1

Event ID 10108 — The msLAPSCurrentPasswordVersion attribute has not been added to the Active Directory schema.

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

The msLAPSCurrentPasswordVersion attribute has not been added to the Active Directory schema. This attribute is used to detect torn state conditions caused by OS image rollback scenarios. All primary scenarios will function without this attribute however it is recommended that administrator fix this by re-running the latest Update-LapsADSchema cmdlet.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 20000 — One or more Local Administrator Password Solution (LAPS) MDM policy values were blocked from being set because the current machine is joined to nei...

Provider
Microsoft-Windows-LAPS
Channel
Operational

Message

One or more Local Administrator Password Solution (LAPS) MDM policy values were blocked from being set because the current machine is joined to neither Azure Active Directory or Active Directory.
 
 This message may be safely ignored but is likely to re-occur periodically. To stop further instances of this warning, please reconfigure your MDM policy so that no LAPS policy settings are applied to this machine.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.