Microsoft-Windows-Privacy-Auditing
33 events across 1 channel
Event ID 1000 — Allow access to SettingName on this device setting has successfully changed from OldConsentValue to NewConsentValue by CallerProcessName.
Description
Allow access to SettingName on this device setting has successfully changed from OldConsentValue to NewConsentValue by CallerProcessName.
Message #
Fields #
| Name | Description |
|---|---|
CallerUserSid UnicodeString | — |
CallerProcessName UnicodeString | — |
CallerAppPackageFamilyName UnicodeString | — |
OldConsentValue UnicodeString | — |
NewConsentValue UnicodeString | — |
SetByHigherAuthority Boolean | — |
EffectiveConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Privacy-Auditing",
"guid": "D67FBB76-D18A-5AE3-24A3-8C1DB52D6C62",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 4,
"task": 10,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2025-12-31T19:32:58.262536+00:00",
"event_record_id": 4,
"correlation": {},
"execution": {
"process_id": 3728,
"thread_id": 3820
},
"channel": "Microsoft-Windows-Privacy-Auditing/Operational",
"computer": "WIN11-22H2-X64",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"CallerUserSid": "S-1-5-18",
"CallerProcessName": "msoobe.exe",
"CallerAppPackageFamilyName": "",
"OldConsentValue": "Undefined",
"NewConsentValue": "Deny",
"SetByHigherAuthority": false,
"EffectiveConsentValue": "Deny",
"TargetUserSid": "NULL",
"ConsentID": "NULL",
"AppPackageFamilyName": "NULL",
"HResult": "0x0",
"SettingName": "location"
},
"message": ""
}
Event ID 1001 — Allow access to SettingName on this device setting has failed to change by CallerProcessName.
Description
Allow access to SettingName on this device setting has failed to change by CallerProcessName.
Message #
Fields #
| Name | Description |
|---|---|
CallerUserSid UnicodeString | — |
CallerProcessName UnicodeString | — |
CallerAppPackageFamilyName UnicodeString | — |
OldConsentValue UnicodeString | — |
NewConsentValue UnicodeString | — |
SetByHigherAuthority Boolean | — |
EffectiveConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Event ID 1002 — Allow apps to access your SettingName setting for user TargetUserSid successfully changed from OldConsentValue to NewConsentValue by CallerProcessName.
Description
Allow apps to access your SettingName setting for user TargetUserSid successfully changed from OldConsentValue to NewConsentValue by CallerProcessName.
Message #
Fields #
| Name | Description |
|---|---|
CallerUserSid UnicodeString | — |
CallerProcessName UnicodeString | — |
CallerAppPackageFamilyName UnicodeString | — |
OldConsentValue UnicodeString | — |
NewConsentValue UnicodeString | — |
SetByHigherAuthority Boolean | — |
EffectiveConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Event ID 1003 — Allow apps to access your SettingName setting for user TargetUserSid failed to change by CallerProcessName.
Description
Allow apps to access your SettingName setting for user TargetUserSid failed to change by CallerProcessName.
Message #
Fields #
| Name | Description |
|---|---|
CallerUserSid UnicodeString | — |
CallerProcessName UnicodeString | — |
CallerAppPackageFamilyName UnicodeString | — |
OldConsentValue UnicodeString | — |
NewConsentValue UnicodeString | — |
SetByHigherAuthority Boolean | — |
EffectiveConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Event ID 1004 — User TargetUserSid setting for allow app AppPackageFamilyName access to SettingName successfully changed from OldConsentValue to NewConsentValue by CallerProcessName.
Description
User TargetUserSid setting for allow app AppPackageFamilyName access to SettingName successfully changed from OldConsentValue to NewConsentValue by CallerProcessName.
Message #
Fields #
| Name | Description |
|---|---|
CallerUserSid UnicodeString | — |
CallerProcessName UnicodeString | — |
CallerAppPackageFamilyName UnicodeString | — |
OldConsentValue UnicodeString | — |
NewConsentValue UnicodeString | — |
SetByHigherAuthority Boolean | — |
EffectiveConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Event ID 1005 — User TargetUserSid setting for allow app AppPackageFamilyName access to SettingName failed to change by CallerProcessName.
Description
User TargetUserSid setting for allow app AppPackageFamilyName access to SettingName failed to change by CallerProcessName.
Message #
Fields #
| Name | Description |
|---|---|
CallerUserSid UnicodeString | — |
CallerProcessName UnicodeString | — |
CallerAppPackageFamilyName UnicodeString | — |
OldConsentValue UnicodeString | — |
NewConsentValue UnicodeString | — |
SetByHigherAuthority Boolean | — |
EffectiveConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Event ID 1006 — Allow access to SettingName on this device default setting successfully created as NewConsentValue.
#Description
Allow access to SettingName on this device default setting successfully created as NewConsentValue.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Migrated Boolean | — |
Suppressed Boolean | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Privacy-Auditing",
"guid": "D67FBB76-D18A-5AE3-24A3-8C1DB52D6C62",
"event_source_name": "",
"event_id": 1006,
"version": 0,
"level": 4,
"task": 20,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2023-10-25T21:24:02.614760+00:00",
"event_record_id": 42,
"correlation": {},
"execution": {
"process_id": 2376,
"thread_id": 6016
},
"channel": "Microsoft-Windows-Privacy-Auditing/Operational",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NewConsentValue": "Allow",
"TargetUserSid": "NULL",
"ConsentID": "NULL",
"AppPackageFamilyName": "NULL",
"HResult": "0x0",
"SettingName": "wiFiDirect",
"Migrated": false,
"Suppressed": false
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1007 — Allow access to SettingName on this device default setting failed creation.
Description
Allow access to SettingName on this device default setting failed creation.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Migrated Boolean | — |
Suppressed Boolean | — |
Event ID 1008 — Allow apps to access your SettingName setting default for user TargetUserSid successfully created as NewConsentValue.
#Description
Allow apps to access your SettingName setting default for user TargetUserSid successfully created as NewConsentValue.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Migrated Boolean | — |
Suppressed Boolean | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Privacy-Auditing",
"guid": "D67FBB76-D18A-5AE3-24A3-8C1DB52D6C62",
"event_source_name": "",
"event_id": 1008,
"version": 0,
"level": 4,
"task": 20,
"opcode": 0,
"keywords": 9223372036854775810,
"time_created": "2023-11-05T22:37:47.009514+00:00",
"event_record_id": 160,
"correlation": {},
"execution": {
"process_id": 5264,
"thread_id": 4196
},
"channel": "Microsoft-Windows-Privacy-Auditing/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NewConsentValue": "Allow",
"TargetUserSid": "S-1-5-21-1992711665-1655669231-58201500-1000",
"ConsentID": "",
"AppPackageFamilyName": "NULL",
"HResult": "0x0",
"SettingName": "microphone",
"Migrated": false,
"Suppressed": false
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1009 — Allow apps to access your SettingName setting default for user TargetUserSid failed creation.
Description
Allow apps to access your SettingName setting default for user TargetUserSid failed creation.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Migrated Boolean | — |
Suppressed Boolean | — |
Event ID 1010 — User TargetUserSid setting for allow app AppPackageFamilyName access to SettingName default successfully created as NewConsentValue.
#Description
User TargetUserSid setting for allow app AppPackageFamilyName access to SettingName default successfully created as NewConsentValue.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Migrated Boolean | — |
Suppressed Boolean | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Privacy-Auditing",
"guid": "D67FBB76-D18A-5AE3-24A3-8C1DB52D6C62",
"event_source_name": "",
"event_id": 1010,
"version": 0,
"level": 4,
"task": 20,
"opcode": 0,
"keywords": 9223372036854775812,
"time_created": "2023-11-05T22:37:51.451442+00:00",
"event_record_id": 161,
"correlation": {},
"execution": {
"process_id": 5264,
"thread_id": 5356
},
"channel": "Microsoft-Windows-Privacy-Auditing/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NewConsentValue": "Allow",
"TargetUserSid": "S-1-5-21-1992711665-1655669231-58201500-1000",
"ConsentID": "",
"AppPackageFamilyName": "MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy",
"HResult": "0x0",
"SettingName": "location",
"Migrated": false,
"Suppressed": false
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1011 — User TargetUserSid setting for allow app AppPackageFamilyName access to SettingName default failed creation.
Description
User TargetUserSid setting for allow app AppPackageFamilyName access to SettingName default failed creation.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Migrated Boolean | — |
Suppressed Boolean | — |
Event ID 1012 — During app AppPackageFamilyName installation setting SettingName default set for user TargetUserSid as NewConsentValue.
#Description
During app AppPackageFamilyName installation setting SettingName default set for user TargetUserSid as NewConsentValue.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Migrated Boolean | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Privacy-Auditing",
"guid": "D67FBB76-D18A-5AE3-24A3-8C1DB52D6C62",
"event_source_name": "",
"event_id": 1012,
"version": 0,
"level": 4,
"task": 30,
"opcode": 0,
"keywords": 9223372036854775812,
"time_created": "2023-11-05T22:33:54.035083+00:00",
"event_record_id": 159,
"correlation": {
"ActivityID": "E4DB489E-1037-0000-5D8E-DBE43710DA01"
},
"execution": {
"process_id": 5264,
"thread_id": 5356
},
"channel": "Microsoft-Windows-Privacy-Auditing/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NewConsentValue": "Allow",
"TargetUserSid": "S-1-5-21-1992711665-1655669231-58201500-1000",
"AppPackageFamilyName": "Microsoft.549981C3F5F10_8wekyb3d8bbwe",
"HResult": "0x0",
"SettingName": "microphone",
"Migrated": false
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1013 — During app AppPackageFamilyName installation setting SettingName default failed to be set.
#Description
During app AppPackageFamilyName installation setting SettingName default failed to be set.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
Migrated Boolean | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Privacy-Auditing",
"guid": "D67FBB76-D18A-5AE3-24A3-8C1DB52D6C62",
"event_source_name": "",
"event_id": 1013,
"version": 0,
"level": 2,
"task": 30,
"opcode": 0,
"keywords": 9223372036854775876,
"time_created": "2022-04-07T16:48:29.235595+00:00",
"event_record_id": 35,
"correlation": {
"ActivityID": "DD7B0B6A-4A9E-0001-6F24-7BDD9E4AD801"
},
"execution": {
"process_id": 3104,
"thread_id": 1276
},
"channel": "Microsoft-Windows-Privacy-Auditing/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NewConsentValue": "Allow",
"TargetUserSid": "S-1-5-21-2121334350-1110938707-2888912545-500",
"AppPackageFamilyName": "Microsoft.Windows.Search_cw5n1h2txyewy",
"HResult": "0x8000ffff",
"SettingName": "wifiData",
"Migrated": false
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1014 — User TargetUserSid answered prompt successfully for capability SettingName and app AppID.
Description
User TargetUserSid answered prompt successfully for capability SettingName and app AppID. Response was NewConsentValue.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppID UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
AutoAccepted Boolean | — |
FileID UnicodeString | — |
ProgramID UnicodeString | — |
Event ID 1015 — User TargetUserSid could not be prompted for capability SettingName and app AppID.
Description
User TargetUserSid could not be prompted for capability SettingName and app AppID.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
ConsentID UnicodeString | — |
AppID UnicodeString | — |
HResult HexInt32 | — |
SettingName UnicodeString | — |
AutoAccepted Boolean | — |
FileID UnicodeString | — |
ProgramID UnicodeString | — |
Event ID 1016 — During app AppPackageFamilyName installation for user TargetUserSid, secondary setup for capability Capability with initial value NewConsentValue was successfully completed.
Description
During app AppPackageFamilyName installation for user TargetUserSid, secondary setup for capability Capability with initial value NewConsentValue was successfully completed.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
Capability UnicodeString | — |
Event ID 1017 — During app AppPackageFamilyName installation for user TargetUserSid, secondary setup for capability Capability with initial value NewConsentValue failed with error code HResult.
Description
During app AppPackageFamilyName installation for user TargetUserSid, secondary setup for capability Capability with initial value NewConsentValue failed with error code HResult.
Message #
Fields #
| Name | Description |
|---|---|
NewConsentValue UnicodeString | — |
TargetUserSid UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
HResult HexInt32 | — |
Capability UnicodeString | — |
Event ID 1018 — Compliance database successfully created at version DatabaseVersion.
Event ID 1019 — Compliance database could not be created at version DatabaseVersion.
Event ID 1020 — Database schema was successfully migrated in Duration UTC (unit 100NS).
Event ID 1021 — Database could not be migrated.
Event ID 1022 — Database was successfully recovered in Duration UTC (unit 100NS) - old data was lost.
Description
Database was successfully recovered in Duration UTC (unit 100NS) - old data was lost. Old database version: DatabaseVersion. Runtime version: RuntimeVersion. Justification string: Justification.
Message #
Fields #
| Name | Description |
|---|---|
DatabaseVersion HexInt32 | — |
RuntimeVersion HexInt32 | — |
Justification UnicodeString | — |
Duration HexInt64 | — |
HResult HexInt32 | — |
Event ID 1023 — Database recovery could not be completed, database is in an unhealthy state.
Description
Database recovery could not be completed, database is in an unhealthy state. Database version: DatabaseVersion. Runtime version: RuntimeVersion. Justification string: Justification. Result code: HResult.
Message #
Fields #
| Name | Description |
|---|---|
DatabaseVersion HexInt32 | — |
RuntimeVersion HexInt32 | — |
Justification UnicodeString | — |
Duration HexInt64 | — |
HResult HexInt32 | — |
Event ID 1024 — Package AppPackageFamilyName for user UserSid successfully deprovisioned.
Event ID 1025 — Consent for Package AppPackageFamilyName and User UserSid has been deemed invalid for capability Capability.
Description
Consent for Package AppPackageFamilyName and User UserSid has been deemed invalid for capability Capability. Removing consent. Justification: Justification.
Message #
Fields #
| Name | Description |
|---|---|
UserSid UnicodeString | — |
AppPackageFamilyName UnicodeString | — |
Capability UnicodeString | — |
Justification UnicodeString | — |