Microsoft-Windows-NetworkAccessProtection

45 events across 2 channels

Event IDTitleChannel
1The System Health Agent {ComponentId} is installed but not registered with the …Operational
2The System Health Agent {ComponentId} attempted to initialize; but failed …Operational
3The System Health Agent {ComponentId} attempted to uninitialize but failed …Operational
4The System Health Agent {ComponentId} successfully initialized.Operational
5The System Health Agent {ComponentId} successfully uninitialized.Operational
6The enforcement client {ComponentId} attempted to initialize but failed because …Operational
7The enforcement client {ComponentId} attempted to initialize but failed because …Operational
8The enforcement client {ComponentId} attempted to uninitialize but failed …Operational
9The enforcement client {ComponentId} successfully initialized.Operational
10The enforcement client {ComponentId} successfully uninitialized.Operational
11Call to {FunctionName} on System Health Agent {ComponentId} failed with error …Operational
12The enforcement client {ComponentId} failed the call to {FunctionName}.Operational
13The Network Access Protection Agent failed to load the peripheral component …Operational
14A Statement of Health with correlation ID {CorrelationId} could not be created …Operational
15A Statement of Health Request with correlation ID {CorrelationId} could not …Operational
16A packet has been received with an unexpected correlation of …Operational
17The Statement of Health Response received configuration for the following SHAs …Operational
18System Isolation State Change.Operational
19The Network Access Protection Agent failed to acquire a certificate for the …Operational
20The Network Access Protection Agent failed to acquire a certificate for the …Operational
21The Network Access Protection Agent failed to acquire a certificate for the …Operational
22The Network Access Protection Agent successfully acquired a certificate for the …Operational
23The Network Access Protection Agent successfully deleted the certificate with …Operational
24The Network Access Protection Agent failed to delete the certificate with the …Operational
25The client loaded NAP group policy.Operational
26The NAP service has started.Operational
27A Statement of Health with correlation ID {CorrelationId} was received from the …Operational
28A Statement of Health with correlation ID {CorrelationId} was sent to the …Operational
29A Statement of Health Response with correlation ID {CorrelationId} was received …Operational
30The System Health Agent {SHAId} has returned an error code {Error}.Operational
31The Network Access Protection agent failed to initialize the following …Operational
32The Network Access Protection Agent failed to acquire a certificate for the …Operational
33The Network Access Protection Agent failed to acquire a certificate for the …Operational
34The Network Access Protection Agent failed to acquire a certificate for the …Operational
35The Network Access Protection agent failed to get a certificate for the request …Operational
36The Network Access Protection agent failed to get a certificate for the request …Operational
37The Network Access Protection agent failed to get a certificate for the request …Operational
38The Network Access Protection agent failed to get a certificate for the request …Operational
39The Network Access Protection Agent was unable to determine which HRAs to …Operational
40The Network Access Protection Agent has dynamically discovered the following …Operational
41System Isolation State Change.Operational
42A Statement of Health Response with correlation ID {CorrelationId} was just …Operational
43The Network Access Protection Agent failed to deposit a certificate for the …Operational
44The Network Access Protection Agent received a Statement of Health Response with …Operational
100Sending Health Information to WHC: {CurrentIsolationState}({hc_stateid}).WHC

Event ID 1 — The System Health Agent {ComponentId} is installed but not registered with the NAP agent.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The System Health Agent {ComponentId} is installed but not registered with the NAP agent.

Message #

The System Health Agent {ComponentId} is installed but not registered with the NAP agent.

Fields #

NameDescription
ComponentId

Event ID 2 — The System Health Agent {ComponentId} attempted to initialize; but failed because it has initialized already.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The System Health Agent {ComponentId} attempted to initialize; but failed because it has initialized already.

Message #

The System Health Agent {ComponentId} attempted to initialize; but failed because it has initialized already.

Fields #

NameDescription
ComponentId

Event ID 3 — The System Health Agent {ComponentId} attempted to uninitialize but failed because it was not initialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The System Health Agent {ComponentId} attempted to uninitialize but failed because it was not initialized.

Message #

The System Health Agent {ComponentId} attempted to uninitialize but failed because it was not initialized.

Fields #

NameDescription
ComponentId

Event ID 4 — The System Health Agent {ComponentId} successfully initialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The System Health Agent {ComponentId} successfully initialized.

Message #

The System Health Agent {ComponentId} successfully initialized.

Fields #

NameDescription
ComponentId

Event ID 5 — The System Health Agent {ComponentId} successfully uninitialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The System Health Agent {ComponentId} successfully uninitialized.

Message #

The System Health Agent {ComponentId} successfully uninitialized.

Fields #

NameDescription
ComponentId

Event ID 6 — The enforcement client {ComponentId} attempted to initialize but failed because it is not registered with the NAP agent.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The enforcement client {ComponentId} attempted to initialize but failed because it is not registered with the NAP agent.

Message #

The enforcement client {ComponentId} attempted to initialize but failed because it is not registered with the NAP agent.

Fields #

NameDescription
ComponentId

Event ID 7 — The enforcement client {ComponentId} attempted to initialize but failed because it has already initialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The enforcement client {ComponentId} attempted to initialize but failed because it has already initialized.

Message #

The enforcement client {ComponentId} attempted to initialize but failed because it has already initialized.

Fields #

NameDescription
ComponentId

Event ID 8 — The enforcement client {ComponentId} attempted to uninitialize but failed because it was not initialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The enforcement client {ComponentId} attempted to uninitialize but failed because it was not initialized.

Message #

The enforcement client {ComponentId} attempted to uninitialize but failed because it was not initialized.

Fields #

NameDescription
ComponentId

Event ID 9 — The enforcement client {ComponentId} successfully initialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The enforcement client {ComponentId} successfully initialized.

Message #

The enforcement client {ComponentId} successfully initialized.

Fields #

NameDescription
ComponentId

Event ID 10 — The enforcement client {ComponentId} successfully uninitialized.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The enforcement client {ComponentId} successfully uninitialized.

Message #

The enforcement client {ComponentId} successfully uninitialized.

Fields #

NameDescription
ComponentId

Event ID 11 — Call to {FunctionName} on System Health Agent {ComponentId} failed with error {HResult}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

Call to {FunctionName} on System Health Agent {ComponentId} failed with error {HResult}.Contact the administrator for more information.

Message #

Call to {FunctionName} on System Health Agent {ComponentId} failed with error {HResult}.Contact the administrator for more information.

Fields #

NameDescription
FunctionName
ComponentId
HResult

Event ID 12 — The enforcement client {ComponentId} failed the call to {FunctionName}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The enforcement client {ComponentId} failed the call to {FunctionName}.

Message #

The enforcement client {ComponentId} failed the call to {FunctionName}.

Fields #

NameDescription
ComponentId
FunctionName

Event ID 13 — The Network Access Protection Agent failed to load the peripheral component {PeripheralName}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The Network Access Protection Agent failed to load the peripheral component {PeripheralName}. The error code was {HResult}.Contact the administrator for more information.

Message #

The Network Access Protection Agent failed to load the peripheral component {PeripheralName}. The error code was {HResult}.Contact the administrator for more information.

Fields #

NameDescription
PeripheralName
HResult

Event ID 14 — A Statement of Health with correlation ID {CorrelationId} could not be created because the maximum size of the connection is too small.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

A Statement of Health with correlation ID {CorrelationId} could not be created because the maximum size of the connection is too small.

Message #

A Statement of Health with correlation ID {CorrelationId} could not be created because the maximum size of the connection is too small.

Fields #

NameDescription
CorrelationId

Event ID 15 — A Statement of Health Request with correlation ID {CorrelationId} could not include the following System Health Agents in the statement of Health: ...

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

A Statement of Health Request with correlation ID {CorrelationId} could not include the following System Health Agents in the statement of Health: {OverflowingShas}.

Message #

A Statement of Health Request with correlation ID {CorrelationId} could not include the following System Health Agents in the statement of Health: {OverflowingShas}

Fields #

NameDescription
CorrelationId
OverflowingShas

Event ID 16 — A packet has been received with an unexpected correlation of {CorrelationIdReceived} instead of {CorrelationIdExpected}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

A packet has been received with an unexpected correlation of {CorrelationIdReceived} instead of {CorrelationIdExpected}.

Message #

A packet has been received with an unexpected correlation of {CorrelationIdReceived} instead of {CorrelationIdExpected}.

Fields #

NameDescription
CorrelationIdReceived
CorrelationIdExpected

Event ID 17 — The Statement of Health Response received configuration for the following SHAs that are not installed on this computer: {ComponentId}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The Statement of Health Response received configuration for the following SHAs that are not installed on this computer: {ComponentId}.

Message #

The Statement of Health Response received configuration for the following SHAs that are not installed on this computer: {ComponentId}

Fields #

NameDescription
ComponentId

Event ID 18 — System Isolation State Change.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

System Isolation State Change. Previous :     State          : {CurrentIsolationState} ({CurrentIsolationStateNumeric})    Probation Time : {CurrentProbationTime}    Help URL       : {CurrentFixupUrl} Current :     State          : {PreviousIsolationState} ({PreviousIsolationStateNumeric})    Probation Time : {PreviousProbationTime}    Help URL       : {PreviousFixupUrl}

Fields #

NameDescription
CurrentIsolationState
CurrentIsolationStateNumeric
CurrentProbationTime
CurrentFixupUrl
PreviousIsolationState
PreviousIsolationStateNumeric
PreviousProbationTime
PreviousFixupUrl

Event ID 19 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The server was not available to service the request ({HResult}). This server will not be tried again for {Blackout} minutes.Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL
HResult
Blackout

Event ID 20 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The server denied access to the request ({HResult}). This server will not be tried again for {Blackout} minutes.Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL
HResult
Blackout

Event ID 21 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The request failed with the error code ({HResult}). This server will not be tried again for {Blackout} minutes.Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL
HResult
Blackout

Event ID 22 — The Network Access Protection Agent successfully acquired a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent successfully acquired a certificate for the request with the correlation-id {CorrelationId} from {URL}.The certificate can be identified by its thumbprint of {Thumbprint}

Fields #

NameDescription
CorrelationId
URL
Thumbprint

Event ID 23 — The Network Access Protection Agent successfully deleted the certificate with the thumbprint of {Thumbprint}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent successfully deleted the certificate with the thumbprint of {Thumbprint}.The certificate has expired or the health state of the client has changed or a replacement certificate has been acquired.Contact the administrator for more information.

Fields #

NameDescription
Thumbprint

Event ID 24 — The Network Access Protection Agent failed to delete the certificate with the thumbprint of {Thumbprint}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent failed to delete the certificate with the thumbprint of {Thumbprint}.The certificate could not be found or the Network Access Protection Agent has insufficient privileges to delete the certificate ({HResult}).Contact the administrator for more information.

Fields #

NameDescription
Thumbprint
HResult

Event ID 25 — The client loaded NAP group policy.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The client loaded NAP group policy.

Message #

The client loaded NAP group policy.

Event ID 26 — The NAP service has started.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The NAP service has started.NAP has the following information for this computer: Computer name is {ComputerName}.Domain status is: {DomainJoined}.The OS SKU is: {OSSKU}.The service pack version is: {ProcessorType}.The processor type is: {SP}.

Fields #

NameDescription
ComputerName
DomainJoined
OSSKU
ProcessorType
SP

Event ID 27 — A Statement of Health with correlation ID {CorrelationId} was received from the System Health Agent {SHAId}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

A Statement of Health with correlation ID {CorrelationId} was received from the System Health Agent {SHAId}. The duration to check the client's health was {Duration} ms.

Message #

A Statement of Health with correlation ID {CorrelationId} was received from the System Health Agent {SHAId}.  The duration to check the client's health was {Duration} ms.

Fields #

NameDescription
CorrelationId
SHAId
Duration

Event ID 28 — A Statement of Health with correlation ID {CorrelationId} was sent to the enforcment client {QECId}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

A Statement of Health with correlation ID {CorrelationId} was sent to the enforcment client {QECId}.

Message #

A Statement of Health with correlation ID {CorrelationId} was sent to the enforcment client {QECId}.

Fields #

NameDescription
CorrelationId
QECId

Event ID 29 — A Statement of Health Response with correlation ID {CorrelationId} was received from the enforcement client {QECId}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

A Statement of Health Response with correlation ID {CorrelationId} was received from the enforcement client {QECId}.The current client state is {HealthState}.  The following SHAs report this client non-compliant: {Shas} The following error categories were encountered: {FCS} The probation expiration time is: {ProbationExpiry} The help URL is: {Help} The duration of health check was {Duration} ms.

Fields #

NameDescription
CorrelationId
QECId
HealthState
Shas
FCS
ProbationExpiry
Help
Duration

Event ID 30 — The System Health Agent {SHAId} has returned an error code {Error}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Description

The System Health Agent {SHAId} has returned an error code {Error}.

Message #

The System Health Agent {SHAId} has returned an error code {Error}.

Fields #

NameDescription
SHAId
Error

Event ID 31 — The Network Access Protection agent failed to initialize the following enrollment configuration.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection agent failed to initialize the following enrollment configuration.    HRA Group           : {Group}    CSP Name            : {CSP}    Key Specification   : {KeySpec}    Key Length          : {Length}    Signature Algorithm : {SignatureAlgorithm}The intialization failed with the error code ({Error}).Contact the HRA administrator for more information.

Fields #

NameDescription
Group
CSP
KeySpec
Length
SignatureAlgorithm
Error

Event ID 32 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The server was not available to service the request ({HResult}).Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL
HResult

Event ID 33 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The server denied access to the request ({HResult}).Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL
HResult

Event ID 34 — The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent failed to acquire a certificate for the request with the correlation-id {CorrelationId} from {URL}.The request failed with the error code ({HResult}).Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL
HResult

Event ID 35 — The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.The server presented a certificate that is not trusted for Enterprise authentication. This server will not be tried again for {Blackout} minutes.Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL
Blackout

Event ID 36 — The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.The validation of the server certificate for SSL resulted in an error {HResult}; the certificate is not appropriate for SSL. This server will not be tried again for {Blackout} minutes.Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL
HResult
Blackout

Event ID 37 — The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.The server presented a certificate that is not trusted for Enterprise authentication.Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL

Event ID 38 — The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection agent failed to get a certificate for the request with correlation-id {CorrelationId} from {URL}.The validation of the server certificate for SSL resulted in an error {HResult}; the certificate is not appropriate for SSL.Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL
HResult

Event ID 39 — The Network Access Protection Agent was unable to determine which HRAs to request a health certificate from.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent was unable to determine which HRAs to request a health certificate from.A network change or if GP is configured; a configuration change will prompt further attempts to acquire a health certificate. Otherwise no further attempts will be made.Contact the HRA administrator for more information.

Event ID 40 — The Network Access Protection Agent has dynamically discovered the following HRAs for this network (using the query {Method}):{Urls}The DNS servers...

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent has dynamically discovered the following HRAs for this network (using the query {Method}):{Urls}The DNS servers in your configuration at the time this discovery took place included:{Dns}

Fields #

NameDescription
Method
Urls
Dns

Event ID 41 — System Isolation State Change.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

System Isolation State Change. Extended State details: Previous :     Extended State          : {CurrentExtendedIsolationState} ({CurrentExtendedIsolationStateNumeric}) Current :     Extended State          : {PreviousExtendedIsolationState} ({PreviousExtendedIsolationStateNumeric})

Fields #

NameDescription
CurrentExtendedIsolationState
CurrentExtendedIsolationStateNumeric
PreviousExtendedIsolationState
PreviousExtendedIsolationStateNumeric

Event ID 42 — A Statement of Health Response with correlation ID {CorrelationId} was just received from the enforcement client {QECId}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

A Statement of Health Response with correlation ID {CorrelationId} was just received from the enforcement client {QECId}.The extended state in that Statement of Health Response was {ExtendedHealthState}.

Fields #

NameDescription
CorrelationId
QECId
ExtendedHealthState

Event ID 43 — The Network Access Protection Agent failed to deposit a certificate for the request with the correlation-id {CorrelationId} from {URL}.

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent failed to deposit a certificate for the request with the correlation-id {CorrelationId} from {URL}.ValidityPeriod of the certificate is below threshold ({HResult}).Contact the HRA administrator for more information.

Fields #

NameDescription
CorrelationId
URL
HResult

Event ID 44 — The Network Access Protection Agent received a Statement of Health Response with correlation ID {CorrelationId}; that specified a probation end tim...

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
Operational

Message #

The Network Access Protection Agent received a Statement of Health Response with correlation ID {CorrelationId}; that specified a probation end time of {ProbationExpiry}. The probation end time is in the past; which indicates improper synchronization of the clocks on this machine and the server.

Fields #

NameDescription
CorrelationId
ProbationExpiry

Event ID 100 — Sending Health Information to WHC: {CurrentIsolationState}({hc_stateid}).

Provider
Microsoft-Windows-NetworkAccessProtection
Channel
WHC

Description

Sending Health Information to WHC: {CurrentIsolationState}({hc_stateid}).

Message #

Sending Health Information to WHC: {CurrentIsolationState}({hc_stateid})

Fields #

NameDescription
CurrentIsolationState
hc_stateid