Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
102 events across 2 channels
Event ID 1 —
Fields
| Name | Description |
|---|---|
NtStatus | — |
Event ID 1 — Provisioning Secure Process created
Message
Fields
| Name | Description |
|---|---|
NtStatus | — |
Event ID 2 —
Fields
| Name | Description |
|---|---|
NtStatus | — |
Event ID 2 — Provisioning Secure Process could not initialize based on the command line arguments
Message
Fields
| Name | Description |
|---|---|
NtStatus | — |
Event ID 3 —
Fields
| Name | Description |
|---|---|
NtStatus | — |
Event ID 3 — Provisioning Secure Process is closing
Message
Fields
| Name | Description |
|---|---|
NtStatus | — |
Event ID 4 —
Fields
| Name | Description |
|---|---|
TemplateNameFound | — |
Event ID 4 — Provisioning Secure Process argument was %1.
Message
Fields
| Name | Description |
|---|---|
TemplateNameFound | — |
Event ID 5 —
Fields
| Name | Description |
|---|---|
NtStatus | — |
Event ID 5 — Provisioning Secure Process was not provided the expected argument and will exit
Message
Fields
| Name | Description |
|---|---|
NtStatus | — |
Event ID 6 —
Fields
| Name | Description |
|---|---|
TemplateNameFound | — |
Event ID 6 — Provisioning Secure Process was not provided the expected argument and will exit
Message
Fields
| Name | Description |
|---|---|
TemplateNameFound | — |
Event ID 7 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 7 — Provisioning Secure Process parsed the command line arguments as %1.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 8 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 8 — Provisioning Secure Process could not set the trustlet identity and must exit
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 9 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 9 — Provisioning Secure Process could not initialize the remote TPM assets and must exit
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 10 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 10 — Provisioning Secure Process could not initialize the RPC server
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 11 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 11 — Provisioning Secure Process could not register with the RPC server
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 12 —
Fields
| Name | Description |
|---|---|
MachineID | — |
TransitionTime | — |
ValidStartState | — |
StartState | — |
EndState | — |
Event ID 12 — Provisioning Secure Process transitioned to state %5.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
TransitionTime | — |
ValidStartState | — |
StartState | — |
EndState | — |
Event ID 13 —
Fields
| Name | Description |
|---|---|
MachineID | — |
TransitionTime | — |
ValidStartState | — |
StartState | — |
EndState | — |
ActionPriority | — |
ActionStartingState | — |
ActionNewState | — |
ActionType | — |
Event ID 13 — Provisioning Secure Process transitioned to state %5.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
TransitionTime | — |
ValidStartState | — |
StartState | — |
EndState | — |
ActionPriority | — |
ActionStartingState | — |
ActionNewState | — |
ActionType | — |
Event ID 14 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 14 — Provisioning Secure Process is not running within IUM.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 15 —
Fields
| Name | Description |
|---|---|
MachineID | — |
SourceGroup | — |
Length | — |
Event ID 15 — Provisioning Secure Process received a message from source %2 of length %3.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
SourceGroup | — |
Length | — |
Event ID 16 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 16 — Provisioning Secure Process received a request for the PDK.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 17 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 17 — Provisioning Secure Process is sending the PDK to the provisioning agent.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 18 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 18 — Provisioning Secure Process has sent the encrypted PDK to the virtual machine.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 19 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 19 — Provisioning Secure Process received a PDK that was invalid or could not be decrypted.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 20 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 20 — Provisioning Secure Process encountered an error while processing the EFI database.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 21 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 21 — Provisioning Secure Process encountered an error while generating the server key and cannot continue.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 22 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 22 — Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 23 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 23 — Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 24 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 24 — Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 25 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 25 — Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 26 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 26 — Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 27 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 27 — Provisioning Secure Process encountered an error while attempting miniature attestation.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 28 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 28 — Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 29 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 29 — Provisioning Secure Process could not collect necessary security info from the secure kernel.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 30 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 30 — Provisioning Secure Process is populating the boot authority information from the template.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 31 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 31 — Provisioning Secure Process will allow the UEFI certificate authority for this boot.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 32 —
Fields
| Name | Description |
|---|---|
MachineID | — |
PcrIndex | — |
DiagnosticEventId | — |
Name | — |
AuthoritativeEventOrder | — |
AuthoritativeEventLength | — |
AuthoritativeEvent | — |
AttestationEventOrder | — |
AttestationEventLength | — |
AttestationEvent | — |
Event ID 32 — Provisioning Secure Process attestation error - PCR %2, error %3.
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
PcrIndex | — |
DiagnosticEventId | — |
Name | — |
AuthoritativeEventOrder | — |
AuthoritativeEventLength | — |
AuthoritativeEvent | — |
AttestationEventOrder | — |
AttestationEventLength | — |
AttestationEvent | — |
Event ID 33 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
BlobSize | — |
Blob | — |
Event ID 33 — Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included)
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
BlobSize | — |
Blob | — |
Event ID 34 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 34 — Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 35 —
Fields
| Name | Description |
|---|---|
MachineID | — |
BlobSize | — |
Blob | — |
Event ID 35 — Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included)
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
BlobSize | — |
Blob | — |
Event ID 36 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 36 — Provisioning Secure Process received a message that was invalid or could not be interpreted
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 37 —
Fields
| Name | Description |
|---|---|
MachineID | — |
BlobSize | — |
Blob | — |
Event ID 37 — Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included)
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
BlobSize | — |
Blob | — |
Event ID 38 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 38 — Provisioning Secure Process is starting the version negotiation with the provisioning agent
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 39 —
Fields
| Name | Description |
|---|---|
MachineID | — |
VersionNegotiationVersion | — |
DeclaredVersionMajor | — |
DeclaredVersionMinor | — |
DeclaredVersionBuild | — |
DeclaredVersionRelease | — |
DeclaredVersionLogicalMajor | — |
DeclaredVersionLogicalMinor | — |
AcceptableVersionStartMajor | — |
AcceptableVersionStartMinor | — |
Event ID 39 — Provisioning Secure Process received version information from the provisioning agent
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
VersionNegotiationVersion | — |
DeclaredVersionMajor | — |
DeclaredVersionMinor | — |
DeclaredVersionBuild | — |
DeclaredVersionRelease | — |
DeclaredVersionLogicalMajor | — |
DeclaredVersionLogicalMinor | — |
AcceptableVersionStartMajor | — |
AcceptableVersionStartMinor | — |
Event ID 40 —
Fields
| Name | Description |
|---|---|
MachineID | — |
DeclaredVersionMajor | — |
DeclaredVersionMinor | — |
DeclaredVersionBuild | — |
DeclaredVersionRelease | — |
DeclaredVersionLogicalMajor | — |
DeclaredVersionLogicalMinor | — |
Event ID 40 — Provisioning Secure Process declared version information
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
DeclaredVersionMajor | — |
DeclaredVersionMinor | — |
DeclaredVersionBuild | — |
DeclaredVersionRelease | — |
DeclaredVersionLogicalMajor | — |
DeclaredVersionLogicalMinor | — |
Event ID 41 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 41 — Provisioning Secure Process finished negotiating the protocol version
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 42 —
Fields
| Name | Description |
|---|---|
MachineID | — |
AcceptedVersionStartMajor | — |
AcceptedVersionStartMinor | — |
Event ID 42 — Provisioning Secure Process accepted a protocol version for communication
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
AcceptedVersionStartMajor | — |
AcceptedVersionStartMinor | — |
Event ID 43 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 43 — Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 44 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 44 — Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 45 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 45 — Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 46 —
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 46 — Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
NtStatus | — |
Event ID 47 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 47 — Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 48 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 48 — Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 49 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 49 — The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 50 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 50 — The PDK decypted by PSP contains an RRK and a VMRK has been generated
Message
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 51 —
Fields
| Name | Description |
|---|---|
MachineID | — |
Event ID 51 — Processing the RRK failed
Message
Fields
| Name | Description |
|---|---|
MachineID | — |