Microsoft-Windows-SecurityMitigationsBroker
30 events across 3 channels
Event ID 1001 —
Event ID 1002 —
Event ID 1003 — Failed to get the COM call context.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ErrorCode | — |
Event ID 1004 — Failed to get the calling process information.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ErrorCode | — |
Event ID 1005 — Failed to get the DX adapter driver capabilities.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ErrorCode | — |
Event ID 1006 — ACG status of the DX adapter driver, AdapterId=.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ACGState | — |
Event ID 1007 — Failed to get the mitigation status of the calling proces.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
ErrorCode | — |
Event ID 1008 — Failed to set the mitigation status of the calling proces.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
ErrorCode | — |
Event ID 1009 — Calling process ACG status, AdapterId=.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
ACGState | — |
Event ID 1010 — Calling process is in ACG telemetry mode.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
Event ID 1011 — Calling process is not in an AppContainer.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
Event ID 1012 — Failed to adjust the calling process ACG status for the reported DX adapter change event.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
ErrorCode | — |
Event ID 1013 — Finished applying the security protection policies for the reported DX adapter change event.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
Event ID 1014 — Calling process does not have ACG turned on.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
Event ID 1015 — ACG will be turned off for the calling process due to unsupportive DX adapter driver.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
Event ID 1016 — Failed to create the DX object factory.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
ErrorCode | — |
Event ID 1017 — Failed to enumerate the DX adapters.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
ErrorCode | — |
Event ID 1018 — Failed to query the descriptor for the adapter id.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
ErrorCode | — |
Event ID 1019 — Enumerated a DX adapter.
Message
Fields
| Name | Description |
|---|---|
DriverId1 | — |
DriverId2 | — |
ProcessId | — |
Event ID 1020 — Calling process uses the software rendering adapter.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
Event ID 1021 — Failed to query the IDXGIAdapter2 interface from the enumerated adapter.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
ErrorCode | — |
Event ID 1022 — Encountered a DX adapter that does not support ACG.
Message
Fields
| Name | Description |
|---|---|
Description | — |
VendorId | — |
DeviceId | — |
DriverId | — |
ProcessId | — |
Event ID 1023 — Forced ACG on the DX Adapter which uses a WDDM 2.
Message
Fields
| Name | Description |
|---|---|
Description | — |
VendorId | — |
DeviceId | — |
DriverId | — |
ProcessId | — |
Event ID 1024 — Calling process does not allow remote ACG downgrade.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
Event ID 1025 — Remote downgrade is disabled through settings.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
Event ID 1026 — Non-primary adapter ID is supplied.
Message
Fields
| Name | Description |
|---|---|
Description | — |
VendorId | — |
DeviceId | — |
DriverId | — |
ProcessId | — |
Event ID 1027 — Remote downgrade is rejected since software rendering only policy is set.
Message
Fields
| Name | Description |
|---|---|
DriverId | — |
ProcessId | — |
Event ID 1028 —
Event ID 1029 —
Event ID 1030 — DisableAcgEnforcement is not enabled on current architecture.
Message
Fields
| Name | Description |
|---|---|
ModuleName | — |