Microsoft-Windows-NetworkAccessProtection

45 events across 2 channels

Event IDTitleChannel
1The System Health Agent {ComponentId} is installed but not registered with the …Operational
2The System Health Agent {ComponentId} attempted to initialize; but failed …Operational
3The System Health Agent {ComponentId} attempted to uninitialize but failed …Operational
4The System Health Agent {ComponentId} successfully initialized.Operational
5The System Health Agent {ComponentId} successfully uninitialized.Operational
6The enforcement client {ComponentId} attempted to initialize but failed because …Operational
7The enforcement client {ComponentId} attempted to initialize but failed because …Operational
8The enforcement client {ComponentId} attempted to uninitialize but failed …Operational
9The enforcement client {ComponentId} successfully initialized.Operational
10The enforcement client {ComponentId} successfully uninitialized.Operational
11Call to {FunctionName} on System Health Agent {ComponentId} failed with error …Operational
12The enforcement client {ComponentId} failed the call to {FunctionName}.Operational
13The Network Access Protection Agent failed to load the peripheral component …Operational
14A Statement of Health with correlation ID {CorrelationId} could not be created …Operational
15A Statement of Health Request with correlation ID {CorrelationId} could not …Operational
16A packet has been received with an unexpected correlation of …Operational
17The Statement of Health Response received configuration for the following SHAs …Operational
18System Isolation State Change.Operational
19The Network Access Protection Agent failed to acquire a certificate for the …Operational
20The Network Access Protection Agent failed to acquire a certificate for the …Operational
21The Network Access Protection Agent failed to acquire a certificate for the …Operational
22The Network Access Protection Agent successfully acquired a certificate for the …Operational
23The Network Access Protection Agent successfully deleted the certificate with …Operational
24The Network Access Protection Agent failed to delete the certificate with the …Operational
25The client loaded NAP group policy.Operational
26The NAP service has started.Operational
27A Statement of Health with correlation ID {CorrelationId} was received from the …Operational
28A Statement of Health with correlation ID {CorrelationId} was sent to the …Operational
29A Statement of Health Response with correlation ID {CorrelationId} was received …Operational
30The System Health Agent {SHAId} has returned an error code {Error}.Operational
31The Network Access Protection agent failed to initialize the following …Operational
32The Network Access Protection Agent failed to acquire a certificate for the …Operational
33The Network Access Protection Agent failed to acquire a certificate for the …Operational
34The Network Access Protection Agent failed to acquire a certificate for the …Operational
35The Network Access Protection agent failed to get a certificate for the request …Operational
36The Network Access Protection agent failed to get a certificate for the request …Operational
37The Network Access Protection agent failed to get a certificate for the request …Operational
38The Network Access Protection agent failed to get a certificate for the request …Operational
39The Network Access Protection Agent was unable to determine which HRAs to …Operational
40The Network Access Protection Agent has dynamically discovered the following …Operational
41System Isolation State Change.Operational
42A Statement of Health Response with correlation ID {CorrelationId} was just …Operational
43The Network Access Protection Agent failed to deposit a certificate for the …Operational
44The Network Access Protection Agent received a Statement of Health Response with …Operational
100Sending Health Information to WHC: {CurrentIsolationState}({hc_stateid}).WHC

Event ID 1 — The System Health Agent {ComponentId} is installed but not registered with the NAP agent.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The System Health Agent {ComponentId} is installed but not registered with the NAP agent.

Fields

NameDescription
ComponentId

Event ID 2 — The System Health Agent {ComponentId} attempted to initialize; but failed because it has initialized already.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The System Health Agent {ComponentId} attempted to initialize; but failed because it has initialized already.

Fields

NameDescription
ComponentId

Event ID 3 — The System Health Agent {ComponentId} attempted to uninitialize but failed because it was not initialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The System Health Agent {ComponentId} attempted to uninitialize but failed because it was not initialized.

Fields

NameDescription
ComponentId

Event ID 4 — The System Health Agent {ComponentId} successfully initialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The System Health Agent {ComponentId} successfully initialized.

Fields

NameDescription
ComponentId

Event ID 5 — The System Health Agent {ComponentId} successfully uninitialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The System Health Agent {ComponentId} successfully uninitialized.

Fields

NameDescription
ComponentId

Event ID 6 — The enforcement client {ComponentId} attempted to initialize but failed because it is not registered with the NAP agent.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The enforcement client {ComponentId} attempted to initialize but failed because it is not registered with the NAP agent.

Fields

NameDescription
ComponentId

Event ID 7 — The enforcement client {ComponentId} attempted to initialize but failed because it has already initialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The enforcement client {ComponentId} attempted to initialize but failed because it has already initialized.

Fields

NameDescription
ComponentId

Event ID 8 — The enforcement client {ComponentId} attempted to uninitialize but failed because it was not initialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The enforcement client {ComponentId} attempted to uninitialize but failed because it was not initialized.

Fields

NameDescription
ComponentId

Event ID 9 — The enforcement client {ComponentId} successfully initialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The enforcement client {ComponentId} successfully initialized.

Fields

NameDescription
ComponentId

Event ID 10 — The enforcement client {ComponentId} successfully uninitialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The enforcement client {ComponentId} successfully uninitialized.

Fields

NameDescription
ComponentId

Event ID 11 — Call to {FunctionName} on System Health Agent {ComponentId} failed with error {HResult}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

Call to {FunctionName} on System Health Agent {ComponentId} failed with error {HResult}.Contact the administrator for more information.

Fields

NameDescription
FunctionName
ComponentId
HResult

Event ID 12 — The enforcement client {ComponentId} failed the call to {FunctionName}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The enforcement client {ComponentId} failed the call to {FunctionName}.

Fields

NameDescription
ComponentId
FunctionName

Event ID 13 — The Network Access Protection Agent failed to load the peripheral component {PeripheralName}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent failed to load the peripheral component {PeripheralName}. The error code was {HResult}.Contact the administrator for more information.

Fields

NameDescription
PeripheralName
HResult

Event ID 14 — A Statement of Health with correlation ID {CorrelationId} could not be created because the maximum size of the connection is too small.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

A Statement of Health with correlation ID {CorrelationId} could not be created because the maximum size of the connection is too small.

Fields

NameDescription
CorrelationId

Event ID 15 — A Statement of Health Request with correlation ID {CorrelationId} could not include the following System Health Agents in the statement of Health: ...

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

A Statement of Health Request with correlation ID {CorrelationId} could not include the following System Health Agents in the statement of Health: {OverflowingShas}

Fields

NameDescription
CorrelationId
OverflowingShas

Event ID 16 — A packet has been received with an unexpected correlation of {CorrelationIdReceived} instead of {CorrelationIdExpected}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

A packet has been received with an unexpected correlation of {CorrelationIdReceived} instead of {CorrelationIdExpected}.

Fields

NameDescription
CorrelationIdReceived
CorrelationIdExpected

Event ID 17 — The Statement of Health Response received configuration for the following SHAs that are not installed on this computer: {ComponentId}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Statement of Health Response received configuration for the following SHAs that are not installed on this computer: {ComponentId}

Fields

NameDescription
ComponentId

Event ID 18 — System Isolation State Change.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

System Isolation State Change. Previous :     State          : {CurrentIsolationState} ({CurrentIsolationStateNumeric})    Probation Time : {CurrentProbationTime}    Help URL       : {CurrentFixupUrl} Current :     State          : {PreviousIsolationState} ({PreviousIsolationStateNumeric})    Probation Time : {PreviousProbationTime}    Help URL       : {PreviousFixupUrl}

Fields

NameDescription
CurrentIsolationState
CurrentIsolationStateNumeric
CurrentProbationTime
CurrentFixupUrl
PreviousIsolationState
PreviousIsolationStateNumeric
PreviousProbationTime
PreviousFixupUrl

Event ID 19 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The server was not available to service the request ({HResult}). This server will not be tried again for {Blackout} minutes.Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL
HResult
Blackout

Event ID 20 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The server denied access to the request ({HResult}). This server will not be tried again for {Blackout} minutes.Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL
HResult
Blackout

Event ID 21 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The request failed with the error code ({HResult}). This server will not be tried again for {Blackout} minutes.Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL
HResult
Blackout

Event ID 22 — The Network Access Protection Agent successfully acquired a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent successfully acquired a certificate for the request with the correlation-id {CorrelationId} from {URL}.The certificate can be identified by its thumbprint of {Thumbprint}

Fields

NameDescription
CorrelationId
URL
Thumbprint

Event ID 23 — The Network Access Protection Agent successfully deleted the certificate with the thumbprint of {Thumbprint}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent successfully deleted the certificate with the thumbprint of {Thumbprint}.The certificate has expired or the health state of the client has changed or a replacement certificate has been acquired.Contact the administrator for more information.

Fields

NameDescription
Thumbprint

Event ID 24 — The Network Access Protection Agent failed to delete the certificate with the thumbprint of {Thumbprint}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent failed to delete the certificate with the thumbprint of {Thumbprint}.The certificate could not be found or the Network Access Protection Agent has insufficient privileges to delete the certificate ({HResult}).Contact the administrator for more information.

Fields

NameDescription
Thumbprint
HResult

Event ID 25 — The client loaded NAP group policy.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The client loaded NAP group policy.

Event ID 26 — The NAP service has started.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The NAP service has started.NAP has the following information for this computer: Computer name is {ComputerName}.Domain status is: {DomainJoined}.The OS SKU is: {OSSKU}.The service pack version is: {ProcessorType}.The processor type is: {SP}.

Fields

NameDescription
ComputerName
DomainJoined
OSSKU
ProcessorType
SP

Event ID 27 — A Statement of Health with correlation ID {CorrelationId} was received from the System Health Agent {SHAId}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

A Statement of Health with correlation ID {CorrelationId} was received from the System Health Agent {SHAId}.  The duration to check the client's health was {Duration} ms.

Fields

NameDescription
CorrelationId
SHAId
Duration

Event ID 28 — A Statement of Health with correlation ID {CorrelationId} was sent to the enforcment client {QECId}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

A Statement of Health with correlation ID {CorrelationId} was sent to the enforcment client {QECId}.

Fields

NameDescription
CorrelationId
QECId

Event ID 29 — A Statement of Health Response with correlation ID {CorrelationId} was received from the enforcement client {QECId}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

A Statement of Health Response with correlation ID {CorrelationId} was received from the enforcement client {QECId}.The current client state is {HealthState}.  The following SHAs report this client non-compliant: {Shas} The following error categories were encountered: {FCS} The probation expiration time is: {ProbationExpiry} The help URL is: {Help} The duration of health check was {Duration} ms.

Fields

NameDescription
CorrelationId
QECId
HealthState
Shas
FCS
ProbationExpiry
Help
Duration

Event ID 30 — The System Health Agent {SHAId} has returned an error code {Error}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The System Health Agent {SHAId} has returned an error code {Error}.

Fields

NameDescription
SHAId
Error

Event ID 31 — The Network Access Protection agent failed to initialize the following enrollment configuration.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection agent failed to initialize the following enrollment configuration.    HRA Group           : {Group}    CSP Name            : {CSP}    Key Specification   : {KeySpec}    Key Length          : {Length}    Signature Algorithm : {SignatureAlgorithm}The intialization failed with the error code ({Error}).Contact the HRA administrator for more information.

Fields

NameDescription
Group
CSP
KeySpec
Length
SignatureAlgorithm
Error

Event ID 32 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The server was not available to service the request ({HResult}).Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL
HResult

Event ID 33 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The server denied access to the request ({HResult}).Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL
HResult

Event ID 34 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The request failed with the error code ({HResult}).Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL
HResult

Event ID 35 — The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.The server presented a certificate that is not trusted for Enterprise authentication. This server will not be tried again for {Blackout} minutes.Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL
Blackout

Event ID 36 — The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.The validation of the server certificate for SSL resulted in an error {HResult}; the certificate is not appropriate for SSL. This server will not be tried again for {Blackout} minutes.Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL
HResult
Blackout

Event ID 37 — The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.The server presented a certificate that is not trusted for Enterprise authentication.Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL

Event ID 38 — The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.The validation of the server certificate for SSL resulted in an error {HResult}; the certificate is not appropriate for SSL.Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL
HResult

Event ID 39 — The Network Access Protection Agent was unable to determine which HRAs to request a health certificate from.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent was unable to determine which HRAs to request a health certificate from.A network change or if GP is configured; a configuration change will prompt further attempts to acquire a health certificate. Otherwise no further attempts will be made.Contact the HRA administrator for more information.

Event ID 40 — The Network Access Protection Agent has dynamically discovered the following HRAs for this network (using the query {Method}):{Urls}The DNS servers...

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent has dynamically discovered the following HRAs for this network (using the query {Method}):{Urls}The DNS servers in your configuration at the time this discovery took place included:{Dns}

Fields

NameDescription
Method
Urls
Dns

Event ID 41 — System Isolation State Change.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

System Isolation State Change. Extended State details: Previous :     Extended State          : {CurrentExtendedIsolationState} ({CurrentExtendedIsolationStateNumeric}) Current :     Extended State          : {PreviousExtendedIsolationState} ({PreviousExtendedIsolationStateNumeric})

Fields

NameDescription
CurrentExtendedIsolationState
CurrentExtendedIsolationStateNumeric
PreviousExtendedIsolationState
PreviousExtendedIsolationStateNumeric

Event ID 42 — A Statement of Health Response with correlation ID {CorrelationId} was just received from the enforcement client {QECId}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

A Statement of Health Response with correlation ID {CorrelationId} was just received from the enforcement client {QECId}.The extended state in that Statement of Health Response was {ExtendedHealthState}.

Fields

NameDescription
CorrelationId
QECId
ExtendedHealthState

Event ID 43 — The Network Access Protection Agent failed to deposit a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent failed to deposit a certificate for the request with the correlation-id {CorrelationId} from {URL}.ValidityPeriod of the certificate is below threshold ({HResult}).Contact the HRA administrator for more information.

Fields

NameDescription
CorrelationId
URL
HResult

Event ID 44 — The Network Access Protection Agent received a Statement of Health Response with correlation ID {CorrelationId}; that specified a probation end tim...

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message

The Network Access Protection Agent received a Statement of Health Response with correlation ID {CorrelationId}; that specified a probation end time of {ProbationExpiry}. The probation end time is in the past; which indicates improper synchronization of the clocks on this machine and the server.

Fields

NameDescription
CorrelationId
ProbationExpiry

Event ID 100 — Sending Health Information to WHC: {CurrentIsolationState}({hc_stateid}).

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
WHC

Message

Sending Health Information to WHC: {CurrentIsolationState}({hc_stateid})

Fields

NameDescription
CurrentIsolationState
hc_stateid