Microsoft-Windows-LUA

45 events across 2 channels

EventTitleChannel
15001ConsentUI_GetUserDesktopSnapshotStartDiagnostic
15002ConsentUI_GetUserDesktopSnapshotStopDiagnostic
15003ConsentUI_WindowThreadStartDiagnostic
15004ConsentUI_WindowThreadStopDiagnostic
15005ConsentUI_WindowThreadDiagnostic
15006ConsentUI_SwitchDesktopStartDiagnostic
15007ConsentUI_SwitchDesktopStopDiagnostic
15008ConsentUI_ReturnUserDesktopStartDiagnostic
15009ConsentUI_ReturnUserDesktopStopDiagnostic
15010ConsentUI_WindowThreadStart15010Diagnostic
15011ConsentUI_WindowThreadStop15011Diagnostic
15012ConsentUI_CheckActiveDesktopStartDiagnostic
15013ConsentUI_CheckActiveDesktopStopDiagnostic
15014ConsentUI_CheckActiveDesktopStart15014Diagnostic
15015ConsentUI_CheckActiveDesktopStop15015Diagnostic
15016ConsentUI_WindowThreadStart15016Diagnostic
15017ConsentUI_WindowThreadStop15017Diagnostic
15018ConsentUI_WindowThreadStart15018Diagnostic
15019ConsentUI_WindowThreadStop15019Diagnostic
15020ConsentUI_WindowThreadStart15020Diagnostic
15021ConsentUI_WindowThreadStop15021Diagnostic
15022ConsentUI_ExperienceStartDiagnostic
15023ConsentUI_ExperienceStopDiagnostic
15024ConsentUI_ExperienceStart15024Diagnostic
15025ConsentUI_ExperienceStop15025Diagnostic
15026ConsentUI_ExperienceStart15026Diagnostic
15027ConsentUI_ExperienceStop15027Diagnostic
15028ConsentUI_LEASVCDiagnostic
15029ConsentUI_AMScanStartDiagnostic
15030ConsentUI_AMScanStopDiagnostic
15031Success: Elevation prompt for executable FullCommandLine (ProgramName published …Diagnostic
15031Success: Elevation prompt for executable FullCommandLine (ProgramName published …Elevation
15032Elevation prompt for executable FullCommandLine (ProgramName published by …Diagnostic
15032Elevation prompt for executable FullCommandLine (ProgramName published by …Elevation
16001AppInfo_PerfTrack_ElevationPathStartDiagnostic
16002AppInfo_PerfTrack_ElevationPathStopDiagnostic
16003AppInfo_PerfTrack_ElevationPathStart16003Diagnostic
16004AppInfo_PerfTrack_ElevationPathStop16004Diagnostic
16005AppInfo_PerfTrack_ElevationPathStart16005Diagnostic
16006AppInfo_PerfTrack_ElevationPathStop16006Diagnostic
16007AppInfo_PerfTrack_ElevationPathStart16007Diagnostic
16008AppInfo_PerfTrack_ElevationPathStop16008Diagnostic
16009AppInfo_PerfTrack_ElevationPathStop16009Diagnostic
16010AppInfo_PerfTrack_ElevationPathStart16010Diagnostic
16011AppInfo_PerfTrack_ElevationPathStop16011Diagnostic

Event ID 15001: ConsentUI_GetUserDesktopSnapshotStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_GetUserDesktopSnapshot
Opcode
Start

Event ID 15002: ConsentUI_GetUserDesktopSnapshotStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_GetUserDesktopSnapshot
Opcode
Stop

Event ID 15003: ConsentUI_WindowThreadStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Start

Event ID 15004: ConsentUI_WindowThreadStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Stop

Event ID 15005: ConsentUI_WindowThread

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread

Event ID 15006: ConsentUI_SwitchDesktopStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_SwitchDesktop
Opcode
Start

Event ID 15007: ConsentUI_SwitchDesktopStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_SwitchDesktop
Opcode
Stop

Event ID 15008: ConsentUI_ReturnUserDesktopStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_ReturnUserDesktop
Opcode
Start

Event ID 15009: ConsentUI_ReturnUserDesktopStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_ReturnUserDesktop
Opcode
Stop

Event ID 15010: ConsentUI_WindowThreadStart15010

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Start

Event ID 15011: ConsentUI_WindowThreadStop15011

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Stop

Event ID 15012: ConsentUI_CheckActiveDesktopStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_CheckActiveDesktop
Opcode
Start

Event ID 15013: ConsentUI_CheckActiveDesktopStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_CheckActiveDesktop
Opcode
Stop

Event ID 15014: ConsentUI_CheckActiveDesktopStart15014

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_CheckActiveDesktop
Opcode
Start

Event ID 15015: ConsentUI_CheckActiveDesktopStop15015

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_CheckActiveDesktop
Opcode
Stop

Event ID 15016: ConsentUI_WindowThreadStart15016

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Start

Event ID 15017: ConsentUI_WindowThreadStop15017

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Stop

Event ID 15018: ConsentUI_WindowThreadStart15018

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Start

Event ID 15019: ConsentUI_WindowThreadStop15019

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Stop

Event ID 15020: ConsentUI_WindowThreadStart15020

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Start

Event ID 15021: ConsentUI_WindowThreadStop15021

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Stop

Event ID 15022: ConsentUI_ExperienceStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Start

Event ID 15023: ConsentUI_ExperienceStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Stop

Event ID 15024: ConsentUI_ExperienceStart15024

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Start

Event ID 15025: ConsentUI_ExperienceStop15025

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Stop

Event ID 15026: ConsentUI_ExperienceStart15026

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Start

Event ID 15027: ConsentUI_ExperienceStop15027

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Stop

Event ID 15028: ConsentUI_LEASVC

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_LEASVC

Fields #

NameDescription
Parameters Pointer

Event ID 15029: ConsentUI_AMScanStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_AMScan
Opcode
Start

Event ID 15030: ConsentUI_AMScanStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_AMScan
Opcode
Stop

Event ID 15031: Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
CredUI_Elevation

Description

Success: Elevation prompt for executable ( published by ) answered by , will elevate as .

Fields #

NameDescription
ProgramName UnicodeString
Publisher UnicodeString
FullCommandLine UnicodeString
UserName UnicodeString
ShadowAdmin UnicodeString
ShadowAdminSID UnicodeString
ReturnCode UInt32
ReturnMessage UnicodeString

Event ID 15031: Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as ShadowAdmin.

#
Provider
Microsoft-Windows-LUA
Channel
Elevation
Task
CredUI_Elevation

Description

Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as ShadowAdmin.

Message #

Success: Elevation prompt for executable %3 (%1 published by %2) answered by %4, will elevate as %5.

Fields #

NameDescription
ProgramName UnicodeString
Publisher UnicodeString
FullCommandLine UnicodeString
UserName UnicodeString
ShadowAdmin UnicodeString
ShadowAdminSID UnicodeString
ReturnCode UInt32
ReturnMessage UnicodeString

Event ID 15032: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
CredUI_Elevation_Failure

Description

Elevation prompt for executable ( published by ) answered by . Error : .

Fields #

NameDescription
ProgramName UnicodeString
Publisher UnicodeString
FullCommandLine UnicodeString
UserName UnicodeString
ShadowAdmin UnicodeString
ShadowAdminSID UnicodeString
ReturnCode UInt32
ReturnMessage UnicodeString

Event ID 15032: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName.

#
Provider
Microsoft-Windows-LUA
Channel
Elevation
Task
CredUI_Elevation_Failure

Description

Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName. Error ReturnCode: ReturnMessage.

Message #

Elevation prompt for executable %3 (%1 published by %2) answered by %4. Error %7: %8.

Fields #

NameDescription
ProgramName UnicodeString
Publisher UnicodeString
FullCommandLine UnicodeString
UserName UnicodeString
ShadowAdmin UnicodeString
ShadowAdminSID UnicodeString
ReturnCode UInt32
ReturnMessage UnicodeString

Event ID 16001: AppInfo_PerfTrack_ElevationPathStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Start

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16002: AppInfo_PerfTrack_ElevationPathStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16003: AppInfo_PerfTrack_ElevationPathStart16003

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Start

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16004: AppInfo_PerfTrack_ElevationPathStop16004

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16005: AppInfo_PerfTrack_ElevationPathStart16005

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Start

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16006: AppInfo_PerfTrack_ElevationPathStop16006

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16007: AppInfo_PerfTrack_ElevationPathStart16007

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Start

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16008: AppInfo_PerfTrack_ElevationPathStop16008

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16009: AppInfo_PerfTrack_ElevationPathStop16009

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16010: AppInfo_PerfTrack_ElevationPathStart16010

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Start

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16011: AppInfo_PerfTrack_ElevationPathStop16011

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 93c05d69-51a3-485e-877f-1806a8731346

Defined in appinfo.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0.20348.1 · captured 2026-06-02
  • Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.4484 · captured 2026-06-02

Downloads

Credits

  • Microsoft - authored the ETW manifests and PDBs the schema comes from
  • jdu2600 - the event-schema TSV format this catalog adopted
  • nasbench - the tool that dumps registered providers and manifests