Microsoft-Windows-SENSE
211 events across 1 channel
Event ID 1 — Service is starting (Version %1).
Description
Occurs during system startup, shut down, and during onboarding. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
parameter | — |
References
Event ID 2 — Service is shutting down.
Description
Occurs when the device is shut down or offboarded. Normal operating notification; no action required.
Message
References
Event ID 3 — Windows Defender Advanced Threat Protection service failed to start.
Description
Service didn't start. Review other messages to determine possible cause and troubleshooting steps.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 4 — Contacted server %1 times, all succeeded, URI: %2.
Description
Variable = URL of the Defender for Endpoint processing servers. This URL matches that seen in the Firewall or network activity. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
References
Event ID 5 — Contacted server %1 times, all failed, URI: %2.
Description
Variable = URL of the Defender for Endpoint processing servers. The service couldn't contact the external processing servers at that URL. Check the connection to the URL. See Configure proxy and Internet connectivity.
Message
Fields
| Name | Description |
|---|---|
Last_HTTP_error_code | 1 times, all failed, URI. |
UInt1 | — |
Message1 | — |
Int1 | — |
References
Event ID 6 — Windows Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found.
Description
The device didn't onboard correctly and isn't reporting to the portal. Onboarding must be run before starting the service. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices.
Message
References
Event ID 7 — Windows Defender Advanced Threat Protection service failed to read the onboarding parameters.
Description
Variable = detailed error description. The device didn't onboard correctly and isn't reporting to the portal. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices.
Message
Fields
| Name | Description |
|---|---|
parameter | — |
References
Event ID 8 — Service failed to clean configuration settings.
Description
During onboarding: The service failed to clean its configuration during the onboarding. The onboarding process continues. During offboarding: The service failed to clean its configuration during the offboarding. The offboarding process finished but the service keeps running. Onboarding: No action required. Offboarding: Reboot the system. See Onboard client devices.
Message
References
Event ID 9 — Windows Defender Advanced Threat Protection service failed to change its start type.
Description
During onboarding: The device didn't onboard correctly and isn't reporting to the portal. During offboarding: Failed to change the service start type. The offboarding process continues. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 10 — Windows Defender Advanced Threat Protection service failed to persist the onboarding information.
Description
The device didn't onboard correctly and isn't reporting to the portal. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 11 — Onboarding or re-onboarding of Windows Defender Advanced Threat Protection service completed.
Description
The device onboarded correctly. Normal operating notification; no action required. It might take several hours for the device to appear in the portal.
Message
References
Event ID 12 — New cloud configuration failed to apply, version.
Description
Service was unable to apply the default configuration. This error should resolve after a short period of time.
Message
Fields
| Name | Description |
|---|---|
parameter1 | — |
parameter2 | — |
References
Event ID 13 — Windows Defender Advanced Threat Protection machine ID calculated.
Description
Normal operating process. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
parameter | — |
References
Event ID 14 — Windows Defender Advanced Threat Protection cannot calculate machine ID.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 15 — Windows Defender Advanced Threat Protection cannot start command channel with URL.
Description
Variable = URL of the Defender for Endpoint processing servers. The service couldn't contact the external processing servers at that URL. Check the connection to the URL. See Configure proxy and Internet connectivity.
Message
Fields
| Name | Description |
|---|---|
parameter | — |
References
Event ID 17 — Windows Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location.
Description
An error occurred with the Windows telemetry service. Ensure the diagnostic data service is enabled. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 18 — OOBE (Windows Welcome) is completed.
Description
Service will only start after any Windows updates have finished installing. Normal operating notification; no action required.
Message
References
Event ID 19 — OOBE (Windows Welcome) has not yet completed.
Description
Service will only start after any Windows updates finish installing. Normal operating notification; no action required. If this error persists after a system restart, ensure all Windows updates have full installed.
Message
References
Event ID 20 — Cannot wait for OOBE (Windows Welcome) to complete.
Description
Internal error. If this error persists after a system restart, ensure all Windows updates are installed.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 25 — Service failed to reset health status in the registry.
Description
The device didn't onboard correctly. It reports to the portal; however, the service might not appear as registered in SCCM or the registry. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 26 — Windows Defender Advanced Threat Protection service failed to set the onboarding status in the registry.
Description
The device didn't onboard correctly. It reports to the portal; however the service may not appear as registered in SCCM or the registry. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 27 — Failed to enable Windows Defender Advanced Threat Protection mode in Windows Defender.
Description
Normally, Microsoft Defender Antivirus enters a special passive state if another real-time antimalware product is running properly on the device, and the device is reporting to Defender for Endpoint. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS. Ensure real-time antimalware protection is running properly.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 28 — Connected User Experiences and Telemetry service registration failed with failure code.
Description
An error occurred with the Windows telemetry service. Ensure the diagnostic data service is enabled. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
diskSizeQuotaValue | — |
dailyUploadQuotaValue | — |
References
Event ID 29 — Failed to read the offboarding parameters.
Description
This event occurs when the system can't read the offboarding parameters. Ensure the device has Internet access, then run the entire offboarding process again. Ensure the offboarding package isn't expired.
Message
Fields
| Name | Description |
|---|---|
errorType | — |
HRESULT | — |
description | — |
References
Event ID 30 — Failed to disable Windows Defender Advanced Threat Protection mode in Windows Defender.
Description
Normally, Microsoft Defender Antivirus enters a special passive state if another real-time antimalware product is running properly on the device, and the device is reporting to Defender for Endpoint. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS. Ensure real-time antimalware protection is running properly.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 31 — Windows Defender Advanced Threat Protection Connected User Experiences and Telemetry service unregistration failed.
Description
An error occurred with the Windows telemetry service during onboarding. The offboarding process continues. Check for errors with the Windows telemetry service.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 32 — Windows Defender Advanced Threat Protection service failed to request to stop itself after offboarding process.
Description
An error occurred during offboarding. Reboot the device.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 33 — Windows Defender Advanced Threat Protection service failed to persist SENSE GUID.
Description
A unique identifier is used to represent each device that is reporting to the portal. If the identifier doesn't persist, the same device might appear twice in the portal. Check registry permissions on the device to ensure the service can update the registry.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 34 — Microsoft Defender for Endpoint service failed to add itself as a dependency on the Connected User Experiences and Telemetry service, causing onboarding process to fail. Failure code: variable.
Description
An error occurred with the Windows telemetry service. Ensure the diagnostic data service is enabled. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.
Message
References
Event ID 35 — Communication quotas are updated.
Description
Variable = disk quota in MB. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
diskSizeQuotaValue | — |
dailyUploadQuotaValue | — |
References
Event ID 36 — Connected User Experiences and Telemetry service registration succeeded with completion code.
Description
Registering Defender for Endpoint with the Connected User Experiences and Telemetry service completed successfully. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
diskSizeQuotaValue | — |
dailyUploadQuotaValue | — |
References
Event ID 37 — Module: %1, Quota: {%2} {%3}, Percentage of quota utilization: %4.
Description
The device is near its allocated quota of the current 24-hour window. It's about to be throttled. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
Module | — |
module | — |
quotaValue | — |
quotaValueUnit | — |
percentageValue | — |
References
Event ID 38 — Network connection is identified as low.
Description
The device is using a metered/paid network and contacts the server less frequently. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
pollingInterval | — |
meteredConnectionState | — |
internetAvailabilityState | — |
freeNetworkAvailabilityState | — |
proxyDefined | — |
References
Event ID 39 — Network connection is identified as normal.
Description
The device isn't using a metered/paid connection and contacts the server as usual. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
pollingInterval | — |
meteredConnectionState | — |
internetAvailabilityState | — |
freeNetworkAvailabilityState | — |
proxyDefined | — |
References
Event ID 40 — Battery state is identified as low.
Description
The device has low battery level and contacts the server less frequently. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
battery_saver_mode | 1 seconds. AC state. |
battery_low_state | — |
battery_critical_state | — |
pollingInterval | — |
acPowerState | — |
batterySavingState | — |
batteryLowState | — |
batteryCriticalState | — |
References
Event ID 41 — Battery state is identified as normal.
Description
The device doesn't have low battery level and contacts the server as usual. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
battery_saver_mode | 1 seconds. AC state. |
battery_low_state | — |
battery_critical_state | — |
pollingInterval | — |
acPowerState | — |
batterySavingState | — |
batteryLowState | — |
batteryCriticalState | — |
References
Event ID 42 — Component failed to perform action.
Description
Internal error. The service failed to start. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
Component | — |
Operation | — |
ExceptionType | — |
ExceptionMessage | — |
References
Event ID 43 — Component failed to perform action.
Description
Internal error. The service failed to start. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
Component | — |
Operation | — |
ExceptionType | — |
ExceptionErrorCode | — |
ExceptionMessage | — |
References
Event ID 44 — Offboarding of Windows Defender Advanced Threat Protection service completed.
Description
The service was offboarded. Normal operating notification; no action required.
Message
References
Event ID 45 — Failed to register and to start the event trace session [.
Description
An error occurred on service startup while creating ETW session. This caused service start-up failure. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
TraceSessionName | — |
HRESULT | — |
References
Event ID 46 — Failed to register and start the event trace session [.
Description
An error occurred on service startup while creating ETW session due to lack of resources. The service is running, but doesn't report sensor events until the ETW session starts. Normal operating notification; no action required. The service tries to start the session every minute.
Message
Fields
| Name | Description |
|---|---|
TraceSessionName | — |
HRESULT | — |
References
Event ID 47 — Successfully registered and started the event trace session - recovered after previous failed attempts.
Description
This event follows the previous event after successfully starting of the ETW session. Normal operating notification; no action required.
Message
References
Event ID 48 — Failed to add a provider [.
Description
Failed to add a provider to ETW session. As a result, the provider events aren't reported. Check the error code. If the error persists contact Support.
Message
Fields
| Name | Description |
|---|---|
ProviderId | — |
TraceSessionName | — |
ErrorCode | — |
References
Event ID 49 — Invalid cloud configuration command received and ignored.
Description
Received an invalid configuration file from the cloud service that was ignored. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
Version | — |
Status | — |
HRESULT | — |
ErrorMessage | — |
References
Event ID 50 — New cloud configuration applied successfully.
Description
Successfully applied a new configuration from the cloud service. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
parameter | — |
References
Event ID 51 — New cloud configuration failed to apply, version.
Description
Received a bad configuration file from the cloud service. Last known good configuration was applied successfully. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
parameter1 | — |
parameter2 | — |
References
Event ID 52 — New cloud configuration failed to apply, version.
Description
Received a bad configuration file from the cloud service. Failed to apply the last known good configuration - and the default configuration was applied. The service will attempt to download a new configuration file within 5 minutes. If you don't see event #50 - contact Support.
Message
Fields
| Name | Description |
|---|---|
parameter1 | — |
parameter2 | — |
References
Event ID 53 — Cloud configuration loaded from persistent storage, version.
Description
The configuration was loaded from persistent storage on service startup. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
parameter | — |
References
Event ID 54 — Global (per-pattern) state changed.
Message
Fields
| Name | Description |
|---|---|
Global_perpattern_state_changed_State | Global (per-pattern) state changed. State. |
pattern | — |
Value1 | — |
Value2 | — |
Value3 | — |
Event ID 55 — Failed to create the Secure ETW autologger.
Description
Failed to create the secure ETW logger. Reboot the device. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 56 — Failed to remove the Secure ETW autologger.
Description
Failed to remove the secure ETW session on offboarding. Contact Support.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 57 — Capturing a snapshot of the machine for troubleshooting purposes.
Description
An investigation package, also known as forensics package, is being collected. Normal operating notification; no action required.
Message
References
Event ID 59 — Starting command.
Description
Starting response command execution. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
Starting_command | — |
parameter | — |
References
Event ID 60 — Failed to run command %1, error: %2.
Description
Failed to execute response command. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
CommandName | — |
HRESULT | — |
References
Event ID 61 — Data collection command parameters are invalid: SasUri: %1, compressionLevel: %2.
Description
Failed to read or parse the data collection command arguments (invalid arguments). If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
SasUri | — |
CompressionLevel | — |
References
Event ID 62 — Failed to start Connected User Experiences and Telemetry service.
Description
Connected User Experiences and Telemetry (diagtrack) service failed to start. Non-Microsoft Defender for Endpoint telemetry isn't sent from this machine. Look for more troubleshooting hints in the event log: Microsoft-Windows-UniversalTelemetryClient/Operational.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 63 — Updating the start type of external service.
Description
Updated start type of the external service. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
ServiceName | — |
ActualStartType | — |
ExpectedStartType | — |
ErrorCode | — |
References
Event ID 64 — Starting stopped external service.
Description
Starting an external service. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
Starting_stopped_external_service_Name | Starting stopped external service. Name. |
exit_code | — |
ServiceName | — |
ErrorCode | — |
References
Event ID 65 — Failed to load Microsoft Security Events Component Minifilter driver.
Description
Failed to load MsSecFlt.sys filesystem minifilter. Reboot the device. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 66 — Policy update: Latency mode - %1.
Description
The C&C connection frequency policy was updated. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
parameter | — |
References
Event ID 67 — Contacted server %1 times, failed %2 times and succeeded %3 times.
Message
Fields
| Name | Description |
|---|---|
Last_HTTP_error_code | — |
UInt1 | — |
UInt2 | — |
UInt3 | — |
Message1 | — |
Int1 | — |
Event ID 68 — The start type of the service is unexpected.
Description
Unexpected external service start type. Fix the external service start type.
Message
Fields
| Name | Description |
|---|---|
ServiceName | — |
ActualStartType | — |
ExpectedStartType | — |
References
Event ID 69 — The service is stopped.
Description
The external service is stopped. Start the external service.
Message
Fields
| Name | Description |
|---|---|
parameter | — |
References
Event ID 70 — Policy update: Allow sample collection - %1.
Description
The sample collection policy was updated. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
References
Event ID 71 — Succeeded to run command.
Description
The command was executed successfully. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
parameter | — |
References
Event ID 72 — Tried to send first full machine profile report.
Description
Informational only. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 73 — Sense starting for platform.
Description
Informational only. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
platformBitMask | — |
References
Event ID 74 — Device tag in registry exceeds length limit.
Description
The device tag exceeds the length limit. Use a shorter device tag.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
References
Event ID 75 — Device tag name in registry exceeds length limit.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
Event ID 76 — Number of customer tags in registry exceeds limit.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Event ID 77 — Successfully applied protection on Connected User Experiences and Telemetry service
Message
Event ID 78 — Successfully removed protection from Connected User Experiences and Telemetry service
Message
Event ID 79 — Failed to apply protection on Connected User Experiences and Telemetry service.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 80 — Failed to remove protection from Connected User Experiences and Telemetry service.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 81 — Failed to create Windows Defender Advanced Threat Protection ETW autologger.
Description
Failed to create the ETW session. Reboot the device. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 82 — Failed to remove Windows Defender Advanced Threat Protection ETW autologger.
Description
Failed to delete the ETW session. Contact Support.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 83 — Cyber event may be dropped because its size [.
Message
Fields
| Name | Description |
|---|---|
RealValue | — |
quotaValue | — |
Event ID 84 — Set Windows Defender Antivirus running mode.
Description
Set defender running mode (active or passive). Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
forcePassiveMode | — |
HRESULT | — |
References
Event ID 85 — Failed to trigger Windows Defender Advanced Threat Protection Incident Response executable.
Description
Starring SenseIR executable failed. Reboot the device. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 86 — Starting again stopped external service that should be up.
Description
Starting the external service again. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
ServiceName | — |
ErrorCode | — |
References
Event ID 87 — Cannot start the external service.
Description
Failed to start the external service. Contact Support.
Message
Fields
| Name | Description |
|---|---|
ServiceName | — |
References
Event ID 88 — Updating the start type of external service again.
Description
Updated the start type of the external service. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
ServiceName | — |
ActualStartType | — |
ExpectedStartType | — |
ErrorCode | — |
References
Event ID 89 — Cannot update the start type of external service.
Description
Can't update the start type of the external service. Contact Support.
Message
Fields
| Name | Description |
|---|---|
ServiceName | — |
ActualStartType | — |
ExpectedStartType | — |
References
Event ID 90 — Failed to configure System Guard Runtime Monitor to connect to cloud service in geo-region %1.
Description
System Guard Runtime Monitor doesn't send attestation data to the cloud service. Check the permissions on register path: "HKLM\Software\Microsoft\Windows\CurrentVersion\Sgrm". If no issues spotted, contact Support.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
HRESULT | — |
References
Event ID 91 — Failed to remove System Guard Runtime Monitor geo-region information.
Description
System Guard Runtime Monitor doesn't send attestation data to the cloud service. Check the permissions on register path: "HKLM\Software\Microsoft\Windows\CurrentVersion\Sgrm". If no issues spotted, contact Support.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 92 — Stopping sending sensor cyber data quota because data quota is exceed.
Description
Exceed throttling limit. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt2 | — |
References
Event ID 93 — Resuming sending sensor cyber data.
Description
Resume cyber data submission. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt2 | — |
References
Event ID 94 — Windows Defender Advanced Threat Protection Classification Engine executable has started
Description
The SenseCE executable has started. Normal operating notification; no action required.
Message
References
Event ID 95 — Windows Defender Advanced Threat Protection Classification Engine executable has ended
Description
The SenseCE executable has ended. Normal operating notification; no action required.
Message
References
Event ID 96 — Windows Defender Advanced Threat Protection Classification Engine Init has called.
Description
The SenseCE executable has called MCE initialization. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 97 — There are connectivity issues to the Cloud for the DLP scenario
Description
There are network connectivity issues that affect the DLP classification flow. Check the network connectivity.
Message
References
Event ID 98 — The connectivity to the Cloud for the DLP scenario has been restored
Description
The connectivity to the network was restored and the DLP classification flow can continue. Normal operating notification; no action required.
Message
References
Event ID 99 — Sense has encoutered the following error while communicating with server.
Description
A communication error occurred. Check the following events in the event log for further details.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
HRESULT | — |
References
Event ID 100 — Windows Defender Advanced Threat Protection Classification Engine executable failed to start.
Description
The SenseCE executable has failed to start. Reboot the device. If this error persists, contact Support.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 101 — Windows Defender Advanced Threat Protection Network Detection and Response executable failed to start.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 102 — Windows Defender Advanced Threat Protection Network Detection and Response executable has started
Description
The SenseNdr executable has started. Normal operating notification; no action required.
Message
References
Event ID 103 — Windows Defender Advanced Threat Protection Network Detection and Response executable has ended
Description
The SenseNdr executable has ended. Normal operating notification; no action required.
Message
References
Event ID 104 — Failed to queue asynchronous driver unload.
Description
Occurs during offboarding. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 105 — Failed to wait for driver unload.
Description
Occurs during offboarding. Normal operating notification; no action required.
Message
References
Event ID 106 — Windows Defender Advanced Threat Protection service failed to start.
Description
Occurs during startup. Contact support.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 107 — Windows Defender Advanced Threat Protection service failed to start.
Description
Occurs during startup. Contact support.
Message
Fields
| Name | Description |
|---|---|
UInt2 | — |
References
Event ID 108 — Update phase:%1, new platform version: %2, message: %3.
Description
Occurs during update. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
Update_phase | — |
new_platform_version | — |
message | — |
phase | — |
newVersion | — |
References
Event ID 109 — Update phase:%1 new platform version: %2, failure message: %3, error: %4.
Description
Occurs during update. Contact support.
Message
Fields
| Name | Description |
|---|---|
Update_phase | — |
new_platform_version | — |
failure_message | — |
error | — |
phase | — |
newVersion | — |
message | — |
HRESULT | — |
References
Event ID 110 — Failed to remove MDEContain WFP filters
Description
Occurs during offboarding. Contact support.
Message
References
Event ID 111 — Failed to Leave SecurityManagement.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 112 — MsSecFlt.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 113 — MsSecFlt.
Message
Event ID 114 — MsSecFlt.
Message
Event ID 115 — MsSecWfp.
Message
Event ID 116 — MsSecWfp.
Message
Event ID 117 — %1: Failed to modify service object trust label.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
HRESULT | — |
Event ID 118 — Update phase:%1, new platform version: %2, success message: %3.
Message
Fields
| Name | Description |
|---|---|
Update_phase | — |
new_platform_version | — |
success_message | — |
phase | — |
newVersion | — |
message | — |
Event ID 119 — Windows Defender Advanced Threat Protection service failed to remove its failure actions.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 120 — EventTraker Event data:
Message
Fields
| Name | Description |
|---|---|
parameter | — |
Event ID 121 — Info message.
Message
Fields
| Name | Description |
|---|---|
Info_message | — |
message | — |
Event ID 122 — Update phase:%1 new platform version: %2, warning message: %3.
Message
Fields
| Name | Description |
|---|---|
Update_phase | — |
new_platform_version | — |
warning_message | — |
phase | — |
newVersion | — |
message | — |
HRESULT | — |
Event ID 123 — Update error message: %5, Additional parameters: %1: %2, %3: %4, error message: %6.
Message
Fields
| Name | Description |
|---|---|
valueName1 | — |
value1 | — |
valueName2 | — |
value2 | — |
message | — |
HRESULT | — |
Event ID 124 — Windows Defender Advanced Threat Protection Trace Event Monitor executable has started
Message
Event ID 125 — Windows Defender Advanced Threat Protection Trace Event Monitor executable has ended
Message
Event ID 126 — Windows Defender Advanced Threat Protection Trace Event Monitor executable failed to start.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 127 — Windows Defender Advanced Threat Protection Dlp Processor executable failed to start.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 128 — Windows Defender Advanced Threat Protection Dlp Processor executable has started
Message
Event ID 129 — Windows Defender Advanced Threat Protection Dlp Processor executable has ended
Message
Event ID 130 — Received DLP policy type.
Message
Fields
| Name | Description |
|---|---|
Received_DLP_policy_type | — |
Policy_Hash | — |
Timestamp | — |
CommandType | — |
PolicyHash | — |
TimeStamp | — |
Event ID 131 — Completed processing DLP policy type.
Message
Fields
| Name | Description |
|---|---|
Completed_processing_DLP_policy_type | — |
Policy_Hash | — |
Timestamp | — |
CommandType | — |
PolicyHash | — |
TimeStamp | — |
Event ID 132 — Failed to process DLP policy type.
Message
Fields
| Name | Description |
|---|---|
CommandType | — |
PolicyHash | — |
TimeStamp | — |
HRESULT | — |
ErrorMessage | — |
Event ID 133 — Ignore DLP policy type: %1 at %2 due to Data Loss Prevention feature currently disabled.
Message
Fields
| Name | Description |
|---|---|
Ignore_DLP_policy_type | — |
CommandType | — |
TimeStamp | — |
Event ID 134 — Offboarding blob is revoked via configuration.
Message
Fields
| Name | Description |
|---|---|
BlobSha256 | — |
Event ID 135 — Offboarding is blocked for blob with Epoch: %1 , BlobSha256: %2.
Message
Fields
| Name | Description |
|---|---|
BlobEpoch | — |
BlobSha256 | — |
Event ID 300 — Windows Defender Advanced Threat Protection Session Recorder executable has started
Message
Event ID 301 — Windows Defender Advanced Threat Protection Session Recorder executable has ended
Message
Event ID 302 — Windows Defender Advanced Threat Protection Session Recorder init has called from user session %1.
Message
Fields
| Name | Description |
|---|---|
parameter | — |
Event ID 303 — Windows Defender Advanced Threat Protection Session Recorder executable failed to start from user session %1.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
HRESULT | — |
Event ID 304 — Windows Defender Advanced Threat Protection Session Recorder user session logon event for session id: %1, session name: %2.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
Event ID 305 — Windows Defender Advanced Threat Protection Session Recorder user session logoff event for session id.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Event ID 306 — Windows Defender Advanced Threat Protection Session Recorder user session unlock event for session id.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
Event ID 307 — Failed to update driver permissions Failure code.
Description
Occurs during onboarding. Contact support.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 308 — Failed to ACL on Folder %1 Failure code: %2.
Description
Occurs during onboarding. Contact support.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
HRESULT | — |
References
Event ID 309 — Windows Defender Advanced Threat Protection Network Detection and Response failed to subscribe to event id %1 of event log channel: %2, with provid...
Message
Fields
| Name | Description |
|---|---|
with_provider | 1 of event log channel. |
UInt1 | — |
Message1 | — |
providerName | — |
Event ID 310 — Failed to store cloud configuration.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 400 — Windows Defender Advanced Threat Protection service failed to create certificate.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 401 — Windows Defender Advanced Threat Protection service failed to generate key.
Description
Failed to create crypto key. If machine isn't reporting, contact support. Otherwise, no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 402 — Windows Defender Advanced Threat Protection service failed to persist authentication state.
Description
Failed to persist authentication state. If a device isn't reporting, contact support. Otherwise, no action required.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
HRESULT | — |
References
Event ID 403 — Registration of device by Windows Defender Advanced Threat Protection service completed.
Description
Successful registration to authentication service. Normal operating notification; no action required.
Message
References
Event ID 404 — Windows Defender Advanced Threat Protection service successfully generated a key.
Description
Successful crypto key generation. Normal operating notification; no action required.
Message
References
Event ID 405 — Failed to communicate with authentication service.
Description
Failed to send request to authentication service. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HTTP_error_code | 1 request failed, hresult. |
requestType | — |
HRESULT | — |
errorCode | — |
References
Event ID 406 — Request for %1 rejected by authentication service.
Description
Request returned undesired response. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
error_code | 1 rejected by authentication service. Hresult. |
requestType | — |
HRESULT | — |
errorCode | — |
References
Event ID 407 — Windows Defender Advanced Threat Protection service failed to sign message (authentication).
Description
Failed to sign request. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 408 — Windows Defender Advanced Threat Protection service failed to remove persist authentication state.
Description
Failed to persist authentication state. If a device isn't reporting, contact support. Otherwise, no action required.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
HRESULT | — |
References
Event ID 409 — Windows Defender Advanced Threat Protection service failed to open key.
Description
Failed to open crypto key. If a device isn't reporting, contact support. Otherwise, no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 410 — Registration is required as part of re-onboarding of Windows Defender Advanced Threat Protection service.
Description
Occurs during reonboarding. Normal operating notification; no action required.
Message
References
Event ID 411 — Cyber telemetry upload has been suspended for Windows Defender Advanced Threat Protection service due to invalid/expired token.
Description
Cyber upload temporarily suspended. Normal operating notification; no action required.
Message
References
Event ID 412 — Cyber telemetry upload been resumed for Windows Defender Advanced Threat Protection service due to newly refreshed token.
Description
Cyber upload successfully resumed. Normal operating notification; no action required.
Message
References
Event ID 413 — Windows Defender Advanced Threat Protection Network Detection and Response failed to subscribe to event id {UInt1} of event log channel: {Message1}.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
Event ID 414 — Key rotation of device by Windows Defender Advanced Threat Protection service completed.
Message
Event ID 415 — Authentication initialization for Windows Defender Advanced Threat Protection service completed successfully.
Message
Event ID 416 — EventTraker Event data:
Message
Fields
| Name | Description |
|---|---|
parameter | — |
Event ID 417 — Windows Defender Advanced Threat Protection service opened key successfully.
Message
Event ID 418 — Windows Defender Advanced Threat Protection service certificate creation completed successfully.
Message
Event ID 419 — Windows Defender Advanced Threat Protection service authentication request signing completed successfully.
Message
Event ID 420 — Rename of device by Windows Defender Advanced Threat Protection service completed.
Message
Event ID 500 — Windows Defender Advanced Threat Protection orchestrator failed to perform.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
HRESULT | — |
Event ID 501 — Windows Defender Advanced Threat Protection orchestrator performed: %1 successfully.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
Event ID 1800 — CSP: Get Node's Value.
Description
An operation of Get is about to start. Contact support.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
References
Event ID 1801 — CSP: Failed to Get Node's Value.
Description
An operation of Get has failed. Contact support.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
HRESULT | — |
References
Event ID 1802 — CSP: Get Node's Value complete.
Description
An operation of Get has succeeded. Contact support.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
HRESULT | — |
References
Event ID 1803 — CSP: Get Last Connected value complete.
Description
Last time the device communicated with CNC. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
Boolean1 | — |
References
Event ID 1804 — CSP: Get Org ID value complete.
Description
The org ID device get during onboarding. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
Boolean1 | — |
References
Event ID 1805 — CSP: Get Sense Is Running value complete.
Description
Sense running message after onboarding. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
References
Event ID 1806 — CSP: Get Onboarding State value complete.
Description
Get is Sense onboarded. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Boolean1 | — |
References
Event ID 1807 — CSP: Get Onboarding value complete.
Description
Get is Sense onboarded and onboarding blob hash. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
onboardingBlobHash | — |
isDefaultOnboardingBlob | — |
onboardingState | — |
isDefaultOnboardingState | — |
References
Event ID 1808 — CSP: Get Offboarding value complete.
Description
Get offboarding blob hash. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
offboardingBlobHash | — |
isDefaultOffboardingBlob | — |
References
Event ID 1809 — CSP: Get Sample Sharing value complete.
Description
Get is sample upload is allowed. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Boolean1 | — |
References
Event ID 1810 — CSP: Onboarding process.
Description
Started onboarding flow. Normal operating notification; no action required.
Message
References
Event ID 1811 — CSP: Onboarding process.
Description
Deleted offboarding blob as part of onboarding flow. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 1812 — CSP: Onboarding process.
Description
Wrote onboarding blob to registry as part of onboarding flow. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 1813 — CSP: Onboarding process.
Description
Started Sense service as part of onboarding flow. Normal operating notification; no action required.
Message
References
Event ID 1814 — CSP: Onboarding process.
Description
Finished waiting for Sense to start as part of onboarding flow. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 1815 — CSP: Set Sample Sharing value complete.
Description
Set sample sharing value. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
previousSampleCollectionValue | — |
IsDefault | — |
newSampleSharing | — |
HRESULT | — |
References
Event ID 1816 — CSP: Offboarding process.
Description
Deleted onboarding blob as part of offboarding flow. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 1817 — CSP: Offboarding process.
Description
Wrote offboarding blob to registry as part of offboarding flow. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
References
Event ID 1818 — CSP: Set Node's Value started.
Description
An operation of Set is about to start. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
References
Event ID 1819 — CSP: Failed to Set Node's Value.
Description
An operation of Set has failed. Contact support.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
HRESULT | — |
References
Event ID 1820 — CSP: Set Node's Value complete.
Description
An operation of Set has succeeded. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
HRESULT | — |
References
Event ID 1821 — CSP: Set Telemetry Reporting Frequency started.
Description
Start setting the value of TelemetryReportingFrequency. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
References
Event ID 1822 — CSP: Set Telemetry Reporting Frequency complete.
Description
Finish setting the value of TelemetryReportingFrequency. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
previousLatencyMode | — |
IsDefault | — |
newLatencyMode | — |
HRESULT | — |
References
Event ID 1823 — CSP: Get Telemetry Reporting Frequency complete.
Description
Gets the value of TelemetryReportingFrequency. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
Message1 | — |
Boolean1 | — |
References
Event ID 1824 — CSP: Get Group Ids complete.
Description
Got groupIds from registry. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
Boolean1 | — |
References
Event ID 1825 — CSP: Set Group Ids exceeded allowed limit.
Description
Failed to set groupIds due to length. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
UInt2 | — |
References
Event ID 1826 — CSP: Set Group Ids complete.
Description
Set groupIds. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
HRESULT | — |
References
Event ID 1827 — CSP: Onboarding process.
Description
Trace values as part of onboarding. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
isServiceRunningAlready | — |
previousOnboardingBlobHash | — |
isDefaultOnboardingBlob | — |
onboardingState | — |
isDefaultOnboardingState | — |
newOnboardingBlobHash | — |
References
Event ID 1828 — CSP: Onboarding process.
Description
Trace values as part of offboarding. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
isServiceRunning | — |
previousOffboardingBlobHash | — |
isDefaultOffboardingBlob | — |
onboardingState | — |
isDefaultOnboardingState | — |
newOffboardingBlobHash | — |
References
Event ID 1829 — CSP: Failed to Set Sample Sharing Value.
Description
Invalid value for SampleSharing operation. Contact support.
Message
Fields
| Name | Description |
|---|---|
requestedValue | — |
minimumAllowedValue | — |
maximumAllowedValue | — |
References
Event ID 1830 — CSP: Failed to Set Telemetry Reporting Frequency Value.
Description
Setting the value of TelemetryReportingFrequency failed. Contact support if problem persists.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
References
Event ID 1831 — CSP: Get Sense is running.
Description
Get SenseIsRunning result. Normal operating notification; no action required.
Message
References
Event ID 1832 — CSP: Get Device Tagging Group complete.
Description
Get DeviceTagging Group from registry completed. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
Boolean1 | — |
References
Event ID 1833 — CSP: Get Device Tagging Criticality value complete.
Description
Get DeviceTagging Criticality from registry completed. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
registryValue | — |
IsDefault | — |
conversionSucceeded | — |
Result | — |
References
Event ID 1834 — CSP: Get Device Tagging Identification Method value complete.
Description
Get DeviceTagging Id Method from registry completed. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
registryValue | — |
IsDefault | — |
conversionSucceeded | — |
Result | — |
References
Event ID 1835 — CSP: Set Device Tagging Group complete.
Description
Set DeviceTagging Group in registry completed. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
HRESULT | — |
References
Event ID 1836 — CSP: Set Device Tagging Group exceeded allowed limit.
Description
Set DeviceTagging Group failed as maximum Length Limit exceeded. Contact support if problem persists.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
UInt2 | — |
References
Event ID 1837 — CSP: Set Device Tagging Criticality value complete.
Description
Set DeviceTagging Criticality in registry completed. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
previousCriticalityValue | — |
IsDefault | — |
newCriticalityValue | — |
HRESULT | — |
References
Event ID 1838 — CSP: Failed to Set Device Tagging Criticality Value.
Description
Set DeviceTagging Criticality failed as value was not within expected range. Contact support if problem persists.
Message
Fields
| Name | Description |
|---|---|
requestedValue | — |
minimumAllowedValue | — |
maximumAllowedValue | — |
References
Event ID 1839 — CSP: Set Device Tagging Identification Method value complete.
Description
Set DeviceTagging Id Method in registry completed. Normal operating notification; no action required.
Message
Fields
| Name | Description |
|---|---|
previousIdMethodValue | — |
IsDefault | — |
newIdMethodValue | — |
HRESULT | — |
References
Event ID 1840 — CSP: Failed to Set Device Tagging Identification Method Value.
Description
Set DeviceTagging Id Method failed as value was not within expected range. Contact support if problem persists.
Message
Fields
| Name | Description |
|---|---|
requestedValue | — |
minimumAllowedValue | — |
maximumAllowedValue | — |
References
Event ID 1841 — CSP: Get AadDeviceId complete.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
Boolean1 | — |
Event ID 1842 — CSP: Set AadDeviceId complete.
Message
Fields
| Name | Description |
|---|---|
Message1 | — |
HRESULT | — |
Event ID 1843 — CSP: Set AadDeviceId exceeded allowed limit.
Message
Fields
| Name | Description |
|---|---|
UInt1 | — |
UInt2 | — |
Event ID 2001 — SenseCM.
Message
Fields
| Name | Description |
|---|---|
SenseCM | — |
parameter | — |
Event ID 2002 — Info.
Message
Fields
| Name | Description |
|---|---|
Info | — |
parameter | — |
Event ID 2003 — Warning.
Message
Fields
| Name | Description |
|---|---|
Warning | — |
parameter | — |
Event ID 2004 — Error.
Message
Fields
| Name | Description |
|---|---|
Error | — |
parameter | — |