Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess

102 events across 2 channels

Event IDTitleChannel
1Operational
1Provisioning Secure Process createdDebug
2Operational
2Provisioning Secure Process could not initialize based on the command line …Debug
3Operational
3Provisioning Secure Process is closingDebug
4Operational
4Provisioning Secure Process argument was %1.Debug
5Operational
5Provisioning Secure Process was not provided the expected argument and will exitDebug
6Operational
6Provisioning Secure Process was not provided the expected argument and will exitDebug
7Operational
7Provisioning Secure Process parsed the command line arguments as %1.Debug
8Operational
8Provisioning Secure Process could not set the trustlet identity and must exitDebug
9Operational
9Provisioning Secure Process could not initialize the remote TPM assets and must …Debug
10Operational
10Provisioning Secure Process could not initialize the RPC serverDebug
11Operational
11Provisioning Secure Process could not register with the RPC serverDebug
12Operational
12Provisioning Secure Process transitioned to state %5.Debug
13Operational
13Provisioning Secure Process transitioned to state %5.Debug
14Operational
14Provisioning Secure Process is not running within IUM.Debug
15Operational
15Provisioning Secure Process received a message from source %2 of length %3.Debug
16Operational
16Provisioning Secure Process received a request for the PDK.Debug
17Operational
17Provisioning Secure Process is sending the PDK to the provisioning agent.Debug
18Operational
18Provisioning Secure Process has sent the encrypted PDK to the virtual machine.Debug
19Operational
19Provisioning Secure Process received a PDK that was invalid or could not be …Debug
20Operational
20Provisioning Secure Process encountered an error while processing the EFI …Debug
21Operational
21Provisioning Secure Process encountered an error while generating the server key …Debug
22Operational
22Provisioning Secure Process encountered an error while extending the Secure Boot …Debug
23Operational
23Provisioning Secure Process encountered an error while extending the Boot Lock …Debug
24Operational
24Provisioning Secure Process encountered an error while accessing secure storage …Debug
25Operational
25Provisioning Secure Process encountered an error while working with the remote …Debug
26Operational
26Provisioning Secure Process encountered an error while working with the remote …Debug
27Operational
27Provisioning Secure Process encountered an error while attempting miniature …Debug
28Operational
28Provisioning Secure Process encountered an error while creating and sending the …Debug
29Operational
29Provisioning Secure Process could not collect necessary security info from the …Debug
30Operational
30Provisioning Secure Process is populating the boot authority information from …Debug
31Operational
31Provisioning Secure Process will allow the UEFI certificate authority for this …Debug
32Operational
32Provisioning Secure Process attestation error - PCR %2, error %3.Debug
33Operational
33Provisioning Secure Process received a PDK that was invalid or could not be …Debug
34Operational
34Provisioning Secure Process received a message from NMPS that was invalid or …Debug
35Operational
35Provisioning Secure Process received a message from NMPS that was invalid or …Debug
36Operational
36Provisioning Secure Process received a message that was invalid or could not be …Debug
37Operational
37Provisioning Secure Process received a message that was invalid or could not be …Debug
38Operational
38Provisioning Secure Process is starting the version negotiation with the …Debug
39Operational
39Provisioning Secure Process received version information from the provisioning …Debug
40Operational
40Provisioning Secure Process declared version informationDebug
41Operational
41Provisioning Secure Process finished negotiating the protocol versionDebug
42Operational
42Provisioning Secure Process accepted a protocol version for communicationDebug
43Operational
43Provisioning Secuity Process failed to predict the UEFI Secure Boot variables …Debug
44Operational
44Provisioning Secuity Process detected a mismatched UEFI db variable on the …Debug
45Operational
45Provisioning Secuity Process detected a mismatched UEFI dbx variable on the …Debug
46Operational
46Provisioning Secuity Process failed to match the target machine UEFI Secure Boot …Debug
47Operational
47Provisioning Secuity Process failed to validate the target BootOS Provisioning …Debug
48Operational
48Provisioning Secuity Process has failed to verify the target machine so no …Debug
49Operational
49The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be …Debug
50Operational
50The PDK decypted by PSP contains an RRK and a VMRK has been generatedDebug
51Operational
51Processing the RRK failedDebug

Event ID 1 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
NtStatus

Event ID 1 — Provisioning Secure Process created

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process created

Fields

NameDescription
NtStatus

Event ID 2 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
NtStatus

Event ID 2 — Provisioning Secure Process could not initialize based on the command line arguments

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process could not initialize based on the command line arguments

Fields

NameDescription
NtStatus

Event ID 3 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
NtStatus

Event ID 3 — Provisioning Secure Process is closing

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process is closing

Fields

NameDescription
NtStatus

Event ID 4 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
TemplateNameFound

Event ID 4 — Provisioning Secure Process argument was %1.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process argument was %1

Fields

NameDescription
TemplateNameFound

Event ID 5 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
NtStatus

Event ID 5 — Provisioning Secure Process was not provided the expected argument and will exit

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process was not provided the expected argument and will exit

Fields

NameDescription
NtStatus

Event ID 6 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
TemplateNameFound

Event ID 6 — Provisioning Secure Process was not provided the expected argument and will exit

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process was not provided the expected argument and will exit

Fields

NameDescription
TemplateNameFound

Event ID 7 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 7 — Provisioning Secure Process parsed the command line arguments as %1.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process parsed the command line arguments as %1

Fields

NameDescription
MachineID

Event ID 8 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 8 — Provisioning Secure Process could not set the trustlet identity and must exit

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process could not set the trustlet identity and must exit

Fields

NameDescription
MachineID
NtStatus

Event ID 9 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 9 — Provisioning Secure Process could not initialize the remote TPM assets and must exit

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process could not initialize the remote TPM assets and must exit

Fields

NameDescription
MachineID
NtStatus

Event ID 10 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 10 — Provisioning Secure Process could not initialize the RPC server

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process could not initialize the RPC server

Fields

NameDescription
MachineID
NtStatus

Event ID 11 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 11 — Provisioning Secure Process could not register with the RPC server

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process could not register with the RPC server

Fields

NameDescription
MachineID
NtStatus

Event ID 12 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
TransitionTime
ValidStartState
StartState
EndState

Event ID 12 — Provisioning Secure Process transitioned to state %5.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process transitioned to state %5

Fields

NameDescription
MachineID
TransitionTime
ValidStartState
StartState
EndState

Event ID 13 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
TransitionTime
ValidStartState
StartState
EndState
ActionPriority
ActionStartingState
ActionNewState
ActionType

Event ID 13 — Provisioning Secure Process transitioned to state %5.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process transitioned to state %5

Fields

NameDescription
MachineID
TransitionTime
ValidStartState
StartState
EndState
ActionPriority
ActionStartingState
ActionNewState
ActionType

Event ID 14 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 14 — Provisioning Secure Process is not running within IUM.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process is not running within IUM. This degrades security.

Fields

NameDescription
MachineID

Event ID 15 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
SourceGroup
Length

Event ID 15 — Provisioning Secure Process received a message from source %2 of length %3.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process received a message from source %2 of length %3.

Fields

NameDescription
MachineID
SourceGroup
Length

Event ID 16 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 16 — Provisioning Secure Process received a request for the PDK.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process received a request for the PDK.

Fields

NameDescription
MachineID

Event ID 17 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 17 — Provisioning Secure Process is sending the PDK to the provisioning agent.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process is sending the PDK to the provisioning agent.

Fields

NameDescription
MachineID

Event ID 18 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 18 — Provisioning Secure Process has sent the encrypted PDK to the virtual machine.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process has sent the encrypted PDK to the virtual machine.

Fields

NameDescription
MachineID

Event ID 19 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 19 — Provisioning Secure Process received a PDK that was invalid or could not be decrypted.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process received a PDK that was invalid or could not be decrypted.

Fields

NameDescription
MachineID
NtStatus

Event ID 20 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 20 — Provisioning Secure Process encountered an error while processing the EFI database.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process encountered an error while processing the EFI database.

Fields

NameDescription
MachineID
NtStatus

Event ID 21 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 21 — Provisioning Secure Process encountered an error while generating the server key and cannot continue.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process encountered an error while generating the server key and cannot continue.

Fields

NameDescription
MachineID
NtStatus

Event ID 22 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 22 — Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.

Fields

NameDescription
MachineID
NtStatus

Event ID 23 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 23 — Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.

Fields

NameDescription
MachineID
NtStatus

Event ID 24 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 24 — Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.

Fields

NameDescription
MachineID
NtStatus

Event ID 25 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 25 — Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.

Fields

NameDescription
MachineID
NtStatus

Event ID 26 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 26 — Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.

Fields

NameDescription
MachineID
NtStatus

Event ID 27 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 27 — Provisioning Secure Process encountered an error while attempting miniature attestation.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process encountered an error while attempting miniature attestation.

Fields

NameDescription
MachineID
NtStatus

Event ID 28 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 28 — Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.

Fields

NameDescription
MachineID
NtStatus

Event ID 29 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 29 — Provisioning Secure Process could not collect necessary security info from the secure kernel.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process could not collect necessary security info from the secure kernel.

Fields

NameDescription
MachineID
NtStatus

Event ID 30 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 30 — Provisioning Secure Process is populating the boot authority information from the template.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process is populating the boot authority information from the template.

Fields

NameDescription
MachineID

Event ID 31 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 31 — Provisioning Secure Process will allow the UEFI certificate authority for this boot.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process will allow the UEFI certificate authority for this boot.

Fields

NameDescription
MachineID

Event ID 32 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
PcrIndex
DiagnosticEventId
Name
AuthoritativeEventOrder
AuthoritativeEventLength
AuthoritativeEvent
AttestationEventOrder
AttestationEventLength
AttestationEvent

Event ID 32 — Provisioning Secure Process attestation error - PCR %2, error %3.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process attestation error - PCR %2, error %3

Fields

NameDescription
MachineID
PcrIndex
DiagnosticEventId
Name
AuthoritativeEventOrder
AuthoritativeEventLength
AuthoritativeEvent
AttestationEventOrder
AttestationEventLength
AttestationEvent

Event ID 33 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus
BlobSize
Blob

Event ID 33 — Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included)

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included)

Fields

NameDescription
MachineID
NtStatus
BlobSize
Blob

Event ID 34 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 34 — Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted

Fields

NameDescription
MachineID

Event ID 35 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
BlobSize
Blob

Event ID 35 — Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included)

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included)

Fields

NameDescription
MachineID
BlobSize
Blob

Event ID 36 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 36 — Provisioning Secure Process received a message that was invalid or could not be interpreted

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process received a message that was invalid or could not be interpreted

Fields

NameDescription
MachineID

Event ID 37 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
BlobSize
Blob

Event ID 37 — Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included)

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included)

Fields

NameDescription
MachineID
BlobSize
Blob

Event ID 38 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 38 — Provisioning Secure Process is starting the version negotiation with the provisioning agent

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process is starting the version negotiation with the provisioning agent

Fields

NameDescription
MachineID

Event ID 39 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
VersionNegotiationVersion
DeclaredVersionMajor
DeclaredVersionMinor
DeclaredVersionBuild
DeclaredVersionRelease
DeclaredVersionLogicalMajor
DeclaredVersionLogicalMinor
AcceptableVersionStartMajor
AcceptableVersionStartMinor

Event ID 39 — Provisioning Secure Process received version information from the provisioning agent

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process received version information from the provisioning agent

Fields

NameDescription
MachineID
VersionNegotiationVersion
DeclaredVersionMajor
DeclaredVersionMinor
DeclaredVersionBuild
DeclaredVersionRelease
DeclaredVersionLogicalMajor
DeclaredVersionLogicalMinor
AcceptableVersionStartMajor
AcceptableVersionStartMinor

Event ID 40 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
DeclaredVersionMajor
DeclaredVersionMinor
DeclaredVersionBuild
DeclaredVersionRelease
DeclaredVersionLogicalMajor
DeclaredVersionLogicalMinor

Event ID 40 — Provisioning Secure Process declared version information

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process declared version information

Fields

NameDescription
MachineID
DeclaredVersionMajor
DeclaredVersionMinor
DeclaredVersionBuild
DeclaredVersionRelease
DeclaredVersionLogicalMajor
DeclaredVersionLogicalMinor

Event ID 41 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 41 — Provisioning Secure Process finished negotiating the protocol version

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process finished negotiating the protocol version

Fields

NameDescription
MachineID
NtStatus

Event ID 42 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
AcceptedVersionStartMajor
AcceptedVersionStartMinor

Event ID 42 — Provisioning Secure Process accepted a protocol version for communication

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secure Process accepted a protocol version for communication

Fields

NameDescription
MachineID
AcceptedVersionStartMajor
AcceptedVersionStartMinor

Event ID 43 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 43 — Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation

Fields

NameDescription
MachineID
NtStatus

Event ID 44 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 44 — Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy

Fields

NameDescription
MachineID

Event ID 45 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 45 — Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy

Fields

NameDescription
MachineID

Event ID 46 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID
NtStatus

Event ID 46 — Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration

Fields

NameDescription
MachineID
NtStatus

Event ID 47 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 47 — Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version

Fields

NameDescription
MachineID

Event ID 48 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 48 — Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail

Fields

NameDescription
MachineID

Event ID 49 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 49 — The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated

Fields

NameDescription
MachineID

Event ID 50 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 50 — The PDK decypted by PSP contains an RRK and a VMRK has been generated

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

The PDK decypted by PSP contains an RRK and a VMRK has been generated

Fields

NameDescription
MachineID

Event ID 51 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Fields

NameDescription
MachineID

Event ID 51 — Processing the RRK failed

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Message

Processing the RRK failed

Fields

NameDescription
MachineID