Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess

102 events across 2 channels

Event IDTitleChannel
1Provisioning Secure Process createdDebug
1Operational
2Provisioning Secure Process could not initialize based on the command line …Debug
2Operational
3Provisioning Secure Process is closingDebug
3Operational
4Provisioning Secure Process argument was TemplateNameFound.Debug
4Operational
5Provisioning Secure Process was not provided the expected argument and will exitDebug
5Operational
6Provisioning Secure Process was not provided the expected argument and will exitDebug
6Operational
7Provisioning Secure Process parsed the command line arguments as MachineID.Debug
7Operational
8Provisioning Secure Process could not set the trustlet identity and must exitDebug
8Operational
9Provisioning Secure Process could not initialize the remote TPM assets and must …Debug
9Operational
10Provisioning Secure Process could not initialize the RPC serverDebug
10Operational
11Provisioning Secure Process could not register with the RPC serverDebug
11Operational
12Provisioning Secure Process transitioned to state EndState.Debug
12Operational
13Provisioning Secure Process transitioned to state EndState.Debug
13Operational
14Provisioning Secure Process is not running within IUM.Debug
14Operational
15Provisioning Secure Process received a message from source SourceGroup of length …Debug
15Operational
16Provisioning Secure Process received a request for the PDK.Debug
16Operational
17Provisioning Secure Process is sending the PDK to the provisioning agent.Debug
17Operational
18Provisioning Secure Process has sent the encrypted PDK to the virtual machine.Debug
18Operational
19Provisioning Secure Process received a PDK that was invalid or could not be …Debug
19Operational
20Provisioning Secure Process encountered an error while processing the EFI …Debug
20Operational
21Provisioning Secure Process encountered an error while generating the server key …Debug
21Operational
22Provisioning Secure Process encountered an error while extending the Secure Boot …Debug
22Operational
23Provisioning Secure Process encountered an error while extending the Boot Lock …Debug
23Operational
24Provisioning Secure Process encountered an error while accessing secure storage …Debug
24Operational
25Provisioning Secure Process encountered an error while working with the remote …Debug
25Operational
26Provisioning Secure Process encountered an error while working with the remote …Debug
26Operational
27Provisioning Secure Process encountered an error while attempting miniature …Debug
27Operational
28Provisioning Secure Process encountered an error while creating and sending the …Debug
28Operational
29Provisioning Secure Process could not collect necessary security info from the …Debug
29Operational
30Provisioning Secure Process is populating the boot authority information from …Debug
30Operational
31Provisioning Secure Process will allow the UEFI certificate authority for this …Debug
31Operational
32Provisioning Secure Process attestation error - PCR PcrIndex, error …Debug
32Operational
33Provisioning Secure Process received a PDK that was invalid or could not be …Debug
33Operational
34Provisioning Secure Process received a message from NMPS that was invalid or …Debug
34Operational
35Provisioning Secure Process received a message from NMPS that was invalid or …Debug
35Operational
36Provisioning Secure Process received a message that was invalid or could not be …Debug
36Operational
37Provisioning Secure Process received a message that was invalid or could not be …Debug
37Operational
38Provisioning Secure Process is starting the version negotiation with the …Debug
38Operational
39Provisioning Secure Process received version information from the provisioning …Debug
39Operational
40Provisioning Secure Process declared version informationDebug
40Operational
41Provisioning Secure Process finished negotiating the protocol versionDebug
41Operational
42Provisioning Secure Process accepted a protocol version for communicationDebug
42Operational
43Provisioning Secuity Process failed to predict the UEFI Secure Boot variables …Debug
43Operational
44Provisioning Secuity Process detected a mismatched UEFI db variable on the …Debug
44Operational
45Provisioning Secuity Process detected a mismatched UEFI dbx variable on the …Debug
45Operational
46Provisioning Secuity Process failed to match the target machine UEFI Secure Boot …Debug
46Operational
47Provisioning Secuity Process failed to validate the target BootOS Provisioning …Debug
47Operational
48Provisioning Secuity Process has failed to verify the target machine so no …Debug
48Operational
49The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be …Debug
49Operational
50The PDK decypted by PSP contains an RRK and a VMRK has been generatedDebug
50Operational
51Processing the RRK failedDebug
51Operational

Event ID 1 — Provisioning Secure Process created

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process created.

Message #

Provisioning Secure Process created

Fields #

NameDescription
NtStatus UInt32

Event ID 1 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process created.

Fields #

NameDescription
NtStatus UInt32

Event ID 2 — Provisioning Secure Process could not initialize based on the command line arguments

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not initialize based on the command line arguments.

Message #

Provisioning Secure Process could not initialize based on the command line arguments

Fields #

NameDescription
NtStatus UInt32

Event ID 2 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not initialize based on the command line arguments.

Fields #

NameDescription
NtStatus UInt32

Event ID 3 — Provisioning Secure Process is closing

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process is closing.

Message #

Provisioning Secure Process is closing

Fields #

NameDescription
NtStatus UInt32

Event ID 3 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process is closing.

Fields #

NameDescription
NtStatus UInt32

Event ID 4 — Provisioning Secure Process argument was TemplateNameFound.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process argument was TemplateNameFound.

Message #

Provisioning Secure Process argument was %1

Fields #

NameDescription
TemplateNameFound UnicodeString

Event ID 4 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process argument was.

Fields #

NameDescription
TemplateNameFound UnicodeString

Event ID 5 — Provisioning Secure Process was not provided the expected argument and will exit

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process was not provided the expected argument and will exit.

Message #

Provisioning Secure Process was not provided the expected argument and will exit

Fields #

NameDescription
NtStatus UInt32

Event ID 5 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process was not provided the expected argument and will exit.

Fields #

NameDescription
NtStatus UInt32

Event ID 6 — Provisioning Secure Process was not provided the expected argument and will exit

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process was not provided the expected argument and will exit.

Message #

Provisioning Secure Process was not provided the expected argument and will exit

Fields #

NameDescription
TemplateNameFound UnicodeString

Event ID 6 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process was not provided the expected argument and will exit.

Fields #

NameDescription
TemplateNameFound UnicodeString

Event ID 7 — Provisioning Secure Process parsed the command line arguments as MachineID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process parsed the command line arguments as MachineID.

Message #

Provisioning Secure Process parsed the command line arguments as %1

Fields #

NameDescription
MachineID GUID

Event ID 7 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process parsed the command line arguments as.

Fields #

NameDescription
MachineID GUID

Event ID 8 — Provisioning Secure Process could not set the trustlet identity and must exit

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not set the trustlet identity and must exit.

Message #

Provisioning Secure Process could not set the trustlet identity and must exit

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 8 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not set the trustlet identity and must exit.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 9 — Provisioning Secure Process could not initialize the remote TPM assets and must exit

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not initialize the remote TPM assets and must exit.

Message #

Provisioning Secure Process could not initialize the remote TPM assets and must exit

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 9 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not initialize the remote TPM assets and must exit.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 10 — Provisioning Secure Process could not initialize the RPC server

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not initialize the RPC server.

Message #

Provisioning Secure Process could not initialize the RPC server

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 10 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not initialize the RPC server.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 11 — Provisioning Secure Process could not register with the RPC server

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not register with the RPC server.

Message #

Provisioning Secure Process could not register with the RPC server

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 11 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not register with the RPC server.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 12 — Provisioning Secure Process transitioned to state EndState.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process transitioned to state EndState.

Message #

Provisioning Secure Process transitioned to state %5

Fields #

NameDescription
MachineID GUID
TransitionTime FILETIME
ValidStartState Boolean
StartState UInt8
EndState UInt8

Event ID 12 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process transitioned to state.

Fields #

NameDescription
MachineID GUID
TransitionTime FILETIME
ValidStartState Boolean
StartState UInt8
EndState UInt8

Event ID 13 — Provisioning Secure Process transitioned to state EndState.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process transitioned to state EndState.

Message #

Provisioning Secure Process transitioned to state %5

Fields #

NameDescription
MachineID GUID
TransitionTime FILETIME
ValidStartState Boolean
StartState UInt8
EndState UInt8
ActionPriority UInt32
ActionStartingState UInt8
ActionNewState UInt8
ActionType UInt8

Event ID 13 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process transitioned to state.

Fields #

NameDescription
MachineID GUID
TransitionTime FILETIME
ValidStartState Boolean
StartState UInt8
EndState UInt8
ActionPriority UInt32
ActionStartingState UInt8
ActionNewState UInt8
ActionType UInt8

Event ID 14 — Provisioning Secure Process is not running within IUM.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process is not running within IUM. This degrades security.

Message #

Provisioning Secure Process is not running within IUM. This degrades security.

Fields #

NameDescription
MachineID GUID

Event ID 14 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process is not running within IUM. This degrades security.

Fields #

NameDescription
MachineID GUID

Event ID 15 — Provisioning Secure Process received a message from source SourceGroup of length Length.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a message from source SourceGroup of length Length.

Message #

Provisioning Secure Process received a message from source %2 of length %3.

Fields #

NameDescription
MachineID GUID
SourceGroup UInt8
Length UInt32

Event ID 15 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a message from source of length .

Fields #

NameDescription
MachineID GUID
SourceGroup UInt8
Length UInt32

Event ID 16 — Provisioning Secure Process received a request for the PDK.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a request for the PDK.

Message #

Provisioning Secure Process received a request for the PDK.

Fields #

NameDescription
MachineID GUID

Event ID 16 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a request for the PDK.

Fields #

NameDescription
MachineID GUID

Event ID 17 — Provisioning Secure Process is sending the PDK to the provisioning agent.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process is sending the PDK to the provisioning agent.

Message #

Provisioning Secure Process is sending the PDK to the provisioning agent.

Fields #

NameDescription
MachineID GUID

Event ID 17 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process is sending the PDK to the provisioning agent.

Fields #

NameDescription
MachineID GUID

Event ID 18 — Provisioning Secure Process has sent the encrypted PDK to the virtual machine.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process has sent the encrypted PDK to the virtual machine.

Message #

Provisioning Secure Process has sent the encrypted PDK to the virtual machine.

Fields #

NameDescription
MachineID GUID

Event ID 18 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process has sent the encrypted PDK to the virtual machine.

Fields #

NameDescription
MachineID GUID

Event ID 19 — Provisioning Secure Process received a PDK that was invalid or could not be decrypted.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a PDK that was invalid or could not be decrypted.

Message #

Provisioning Secure Process received a PDK that was invalid or could not be decrypted.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 19 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a PDK that was invalid or could not be decrypted.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 20 — Provisioning Secure Process encountered an error while processing the EFI database.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while processing the EFI database.

Message #

Provisioning Secure Process encountered an error while processing the EFI database.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 20 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while processing the EFI database.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 21 — Provisioning Secure Process encountered an error while generating the server key and cannot continue.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while generating the server key and cannot continue.

Message #

Provisioning Secure Process encountered an error while generating the server key and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 21 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while generating the server key and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 22 — Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.

Message #

Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 22 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 23 — Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.

Message #

Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 23 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 24 — Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.

Message #

Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 24 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 25 — Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.

Message #

Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 25 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 26 — Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.

Message #

Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 26 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 27 — Provisioning Secure Process encountered an error while attempting miniature attestation.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while attempting miniature attestation.

Message #

Provisioning Secure Process encountered an error while attempting miniature attestation.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 27 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while attempting miniature attestation.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 28 — Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.

Message #

Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 28 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 29 — Provisioning Secure Process could not collect necessary security info from the secure kernel.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not collect necessary security info from the secure kernel.

Message #

Provisioning Secure Process could not collect necessary security info from the secure kernel.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 29 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not collect necessary security info from the secure kernel.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 30 — Provisioning Secure Process is populating the boot authority information from the template.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process is populating the boot authority information from the template.

Message #

Provisioning Secure Process is populating the boot authority information from the template.

Fields #

NameDescription
MachineID GUID

Event ID 30 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process is populating the boot authority information from the template.

Fields #

NameDescription
MachineID GUID

Event ID 31 — Provisioning Secure Process will allow the UEFI certificate authority for this boot.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process will allow the UEFI certificate authority for this boot.

Message #

Provisioning Secure Process will allow the UEFI certificate authority for this boot.

Fields #

NameDescription
MachineID GUID

Event ID 31 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process will allow the UEFI certificate authority for this boot.

Fields #

NameDescription
MachineID GUID

Event ID 32 — Provisioning Secure Process attestation error - PCR PcrIndex, error DiagnosticEventId.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process attestation error - PCR PcrIndex, error DiagnosticEventId.

Message #

Provisioning Secure Process attestation error - PCR %2, error %3

Fields #

NameDescription
MachineID GUID
PcrIndex UInt32
DiagnosticEventId UInt32
Name UnicodeString
AuthoritativeEventOrder UInt32
AuthoritativeEventLength UInt32
AuthoritativeEvent Binary
AttestationEventOrder UInt32
AttestationEventLength UInt32
AttestationEvent Binary

Event ID 32 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process attestation error - PCR , error.

Fields #

NameDescription
MachineID GUID
PcrIndex UInt32
DiagnosticEventId UInt32
Name UnicodeString
AuthoritativeEventOrder UInt32
AuthoritativeEventLength UInt32
AuthoritativeEvent Binary
AttestationEventOrder UInt32
AttestationEventLength UInt32
AttestationEvent Binary

Event ID 33 — Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included)

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included).

Message #

Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included)

Fields #

NameDescription
MachineID GUID
NtStatus UInt32
BlobSize UInt32
Blob Binary

Event ID 33 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included).

Fields #

NameDescription
MachineID GUID
NtStatus UInt32
BlobSize UInt32
Blob Binary

Event ID 34 — Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted.

Message #

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted

Fields #

NameDescription
MachineID GUID

Event ID 34 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted.

Fields #

NameDescription
MachineID GUID

Event ID 35 — Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included)

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included).

Message #

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included)

Fields #

NameDescription
MachineID GUID
BlobSize UInt32
Blob Binary

Event ID 35 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included).

Fields #

NameDescription
MachineID GUID
BlobSize UInt32
Blob Binary

Event ID 36 — Provisioning Secure Process received a message that was invalid or could not be interpreted

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a message that was invalid or could not be interpreted.

Message #

Provisioning Secure Process received a message that was invalid or could not be interpreted

Fields #

NameDescription
MachineID GUID

Event ID 36 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a message that was invalid or could not be interpreted.

Fields #

NameDescription
MachineID GUID

Event ID 37 — Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included)

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included).

Message #

Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included)

Fields #

NameDescription
MachineID GUID
BlobSize UInt32
Blob Binary

Event ID 37 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included).

Fields #

NameDescription
MachineID GUID
BlobSize UInt32
Blob Binary

Event ID 38 — Provisioning Secure Process is starting the version negotiation with the provisioning agent

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process is starting the version negotiation with the provisioning agent.

Message #

Provisioning Secure Process is starting the version negotiation with the provisioning agent

Fields #

NameDescription
MachineID GUID

Event ID 38 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process is starting the version negotiation with the provisioning agent.

Fields #

NameDescription
MachineID GUID

Event ID 39 — Provisioning Secure Process received version information from the provisioning agent

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received version information from the provisioning agent.

Message #

Provisioning Secure Process received version information from the provisioning agent

Fields #

NameDescription
MachineID GUID
VersionNegotiationVersion UInt8
DeclaredVersionMajor UInt16
DeclaredVersionMinor UInt16
DeclaredVersionBuild UInt16
DeclaredVersionRelease UInt16
DeclaredVersionLogicalMajor UInt8
DeclaredVersionLogicalMinor UInt8
AcceptableVersionStartMajor UInt8
AcceptableVersionStartMinor UInt8

Event ID 39 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received version information from the provisioning agent.

Fields #

NameDescription
MachineID GUID
VersionNegotiationVersion UInt8
DeclaredVersionMajor UInt16
DeclaredVersionMinor UInt16
DeclaredVersionBuild UInt16
DeclaredVersionRelease UInt16
DeclaredVersionLogicalMajor UInt8
DeclaredVersionLogicalMinor UInt8
AcceptableVersionStartMajor UInt8
AcceptableVersionStartMinor UInt8

Event ID 40 — Provisioning Secure Process declared version information

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process declared version information.

Message #

Provisioning Secure Process declared version information

Fields #

NameDescription
MachineID GUID
DeclaredVersionMajor UInt16
DeclaredVersionMinor UInt16
DeclaredVersionBuild UInt16
DeclaredVersionRelease UInt16
DeclaredVersionLogicalMajor UInt8
DeclaredVersionLogicalMinor UInt8

Event ID 40 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process declared version information.

Fields #

NameDescription
MachineID GUID
DeclaredVersionMajor UInt16
DeclaredVersionMinor UInt16
DeclaredVersionBuild UInt16
DeclaredVersionRelease UInt16
DeclaredVersionLogicalMajor UInt8
DeclaredVersionLogicalMinor UInt8

Event ID 41 — Provisioning Secure Process finished negotiating the protocol version

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process finished negotiating the protocol version.

Message #

Provisioning Secure Process finished negotiating the protocol version

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 41 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process finished negotiating the protocol version.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 42 — Provisioning Secure Process accepted a protocol version for communication

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process accepted a protocol version for communication.

Message #

Provisioning Secure Process accepted a protocol version for communication

Fields #

NameDescription
MachineID GUID
AcceptedVersionStartMajor UInt8
AcceptedVersionStartMinor UInt8

Event ID 42 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process accepted a protocol version for communication.

Fields #

NameDescription
MachineID GUID
AcceptedVersionStartMajor UInt8
AcceptedVersionStartMinor UInt8

Event ID 43 — Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation.

Message #

Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 43 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 44 — Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy.

Message #

Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy

Fields #

NameDescription
MachineID GUID

Event ID 44 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy.

Fields #

NameDescription
MachineID GUID

Event ID 45 — Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy.

Message #

Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy

Fields #

NameDescription
MachineID GUID

Event ID 45 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy.

Fields #

NameDescription
MachineID GUID

Event ID 46 — Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration.

Message #

Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 46 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 47 — Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version.

Message #

Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version

Fields #

NameDescription
MachineID GUID

Event ID 47 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version.

Fields #

NameDescription
MachineID GUID

Event ID 48 — Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail.

Message #

Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail

Fields #

NameDescription
MachineID GUID

Event ID 48 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail.

Fields #

NameDescription
MachineID GUID

Event ID 49 — The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated.

Message #

The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated

Fields #

NameDescription
MachineID GUID

Event ID 49 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated.

Fields #

NameDescription
MachineID GUID

Event ID 50 — The PDK decypted by PSP contains an RRK and a VMRK has been generated

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

The PDK decypted by PSP contains an RRK and a VMRK has been generated.

Message #

The PDK decypted by PSP contains an RRK and a VMRK has been generated

Fields #

NameDescription
MachineID GUID

Event ID 50 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

The PDK decypted by PSP contains an RRK and a VMRK has been generated.

Fields #

NameDescription
MachineID GUID

Event ID 51 — Processing the RRK failed

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Processing the RRK failed.

Message #

Processing the RRK failed

Fields #

NameDescription
MachineID GUID

Event ID 51 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Processing the RRK failed.

Fields #

NameDescription
MachineID GUID