Microsoft-Windows-ShieldedVM-ProvisioningService

181 events across 2 channels

Event IDTitleChannel
0Cannot continue because a failure occurred while provisioning.Operational
1A general error occurred while provisioning the machine.Operational
2Cannot provision because the Shielded VM provisioning data cannot be decrypted.Operational
3Cannot provision because the data from the remote TPM reflects an insecure …Operational
4Cannot provision because an error was detected while communicating with the …Operational
5Cannot continue because the target machine detected a TPM failure.Operational
6Cannot continue because the provisioning agent was unable to retrieve the …Operational
7Cannot provision because the template disk attached to the machine is invalid.Operational
8Cannot provision because the volume signature catalog from the template disk is …Operational
9Cannot provision because the provided Shielded VM provisioning data is not …Operational
10The template manager has determined that the template disk signature is invalid.Operational
11Unable to continue because a failure occurred while attempting to rekey the …Operational
12An error occurred while processing the Shielded VM provisioning data content.Operational
13Cannot provision because the Shielded VM provisioning data failed to write to …Operational
14The target machine?Operational
15Cannot continue because the provided Shielded VM provisioning data failed to …Operational
16Cannot continue because the remote machine disconnected unexpectedly.Operational
17Cannot continue because a failure occurred when accessing the secure storage.Operational
18Cannot provision because the volume signature catalog from the template disk is …Operational
19Unable to create the Unattend.Operational
20An error occurred while processing the Shielded VM provisioning data content.Operational
21Cannot continue because Virtual Machine attestation failed during provisioning …Operational
22Cannot continue because a failure occurred while calculating a hash of the …Operational
23Cannot continue because the signature file in the template disk is missing.Operational
24Cannot continue because the TPM is missing the SRK.Operational
25Provisioning cannot continue because the provisioning security process could not …Operational
26Provisioning cannot continue because the template disk does not have an expected …Operational
27Provisioning cannot continue because the template disk has an unexpected volume …Operational
28Provisioning cannot continue because the disk associated with the provisioned VM …Operational
29Provisioning cannot continue because the operating system associated with the …Operational
30Provisioning cannot continue because the sealing values associated with the …Operational
31Provisioning cannot continue because the initialization data required by the …Operational
32Provisioning may not continue because the UEFI database could not be loaded.Operational
33Provisioning may not continue because a launch authority could not be …Operational
34Provisioning failed to extend the secure boot PCR.Operational
35Provisioning failed to extend the boot lock PCR.Operational
36Provisioning could not generate the server key or TPM operations.Operational
37The version of communication required by Provisioning was not understood by the …Operational
38The template disk uses a version of communication not allowed by Provisioning.Operational
39Msps_ProvisioningService: Timeout detected.Operational
40An error was provided to the provisioning service of behalf of another …Operational
41The attempt to prepare the specialized machine failed.Operational
42Provisioning agent reported a failure to unwrap the protected data.Operational
43The target has been deemed unhealthy or not secure by attestation, provisioning …Operational
44Due to prior health assessment operations the provisioning security process has …Operational
45The provisioning service received a connection request from an unknown machine.Operational
46The provisioning service received a connection request from a machine in an …Operational
47The virtual machine cannot be shielded because its virtual disk identifier …Operational
48The VM boot disk is a differencing disk which is not supported by the …Operational
301Operational
301WMI call failed.Debug
302Operational
302WMI call failed.Debug
303Msps_ProvisioningService: Shielded VM provisioning session started.Operational
304Msps_ProvisioningService: Failed to start Shielded VM provisioning session.Operational
305Msps_ProvisioningService: Failed to start Shielded VM provisioning session.Operational
306Msps_ProvisioningService: Shielded VM provisioning session opened.Operational
307Msps_ProvisioningService: Shielded VM provisioning session closed.Operational
308Msps_ProvisioningJob removed.Operational
309Operational
309Msps_ProvisioningService service activated.Debug
310Operational
310Msps_ProvisioningService service completed.Debug
311Operational
311Msps_ProvisioningJob: Received request to retrieve job.Debug
312Operational
312Msps_ProvisioningJob: Received request to delete job.Debug
313Operational
313Msps_ProvisioningJob found %1 instances.Debug
400The provisioning process logged an unknown event.Operational
401The provisioning data has been received over the secure channel.Operational
402The fabric data has been received over the secure channel.Operational
403The provisioning data was successfully transferred over the secure channel.Operational
404The secure inputs are being processed by the provisioning service.Operational
405The VM being provisioned is communicating with the remote TPM.Operational
406Provisioning started.Operational
407The Shielded VM was successfully provisioned.Operational
408The template manager is analyzing the template disk.Operational
409The template manager finished analyzing the template disk.Operational
410The template manager is sealing the template disk.Operational
411The template manager has sealed the template disk.Operational
412The specialization agent is applying the fabric data to the template disk.Operational
413The specialization agent has finished applying the fabric data to the template …Operational
414The provisioning agent has started executing the plugins for the Shielded VM.Operational
415The provisioning agent has finished executing the plugins for the Shielded VM.Operational
416A specialization value was replaced in the Shielded VM's unattend file.Operational
417The provisioning agent was started and is communicating with the host machine.Operational
418The provisioning process was started within the Shielded VM and is communicating …Operational
419The UEFI variables were received by the provisioning process.Operational
420An attestation event was received from the provisioning process.Operational
421A diagnostic attestation event was received from the provisioning process.Operational
422No instance of %2 was found in the unattend file included in the provisioning …Operational
423The template manager is skipping verification of the signature catalog on disk …Operational
424The template manager is skipping verification of the signature catalog on disk …Operational
425The template manager has updated the factory policy of the provisioned VM …Operational
426The template manager has set the sealing values of the provisioned VM Machine …Operational
427The provisioning agent is starting the Execute pass on the provisioned VM …Operational
428The provisioning agent has finished the Execute pass on the provisioned VM …Operational
429The provisioning agent has finished the platform update on the provisioned VM …Operational
430The provisioning agent is starting to predict the sealing values of the …Operational
431The provisioning agent is starting the Finalize pass on the provisioned VM …Operational
432The provisioning agent has finished the Finalize pass on the provisioned VM …Operational
433The provisioning agent is allowed to use the UEFI CA per current policy Machine …Operational
434Operational
434The provisioning service is selecting a launch authority Machine ID.Debug
435The template disk has declared its current version for the purposes of …Operational
436The provisioning service has accepted a communications version supported by the …Operational
437Operational
437Received status update from the template manager.Debug
438The template manager successfully validated the image hash.Operational
439The template manager completed rolling the FVEK.Operational
440The template manager successfully protected the volume.Operational
441Operational
441The provisioning Agent encountered an unknown data section.Debug
442An external BitLocker key was created for a template volume.Operational
443An encrypted BitLocker external key for a template volume was written to disk.Operational
500Operational
500Ptp Session Event Machine ID: %1 Source: %2 EventID %3.Debug
501Operational
501Ptp Session Event Machine ID: %1 Source: %2 EventID %3.Debug
502Operational
502Invalid payload in error notification.Debug
503Operational
503Invalid attestation payload in notification.Debug
504Operational
504%2 attestation items received from the attestation diagnostics log.Debug
505Operational
505An attestation log item was too short to be valid (%2 bytes).Debug
506Operational
506The authoritative event log was deemed invalid.Debug
507Operational
507The authoritative event log is missing an event.Debug
508Operational
508The attestation log is missing an event.Debug
509Operational
509The data in the attestation event is incorrect.Debug
510Operational
510The attestation log is invalid.Debug
511Operational
511An unexpected attestation event was encountered.Debug
512Operational
512The attestation log contained an event which was incorrect.Debug
513Operational
513The attestation event log contains an unknown event.Debug
514Operational
514An attestation event log item is corrupt.Debug
515Operational
515The name of the attestation event log item is %2.Debug
516Operational
516The attestation event log item name has no name information.Debug
517Operational
517The attestation event log item WCBL payload appears corrupt.Debug
518Operational
518PCR Index: %2, Zero-based order relative to PCR: %3, Event: %4, Length: %5 …Debug
519Operational
519The event data is too short or otherwise corrupt and does not contain a TrEE …Debug
520Operational
520TrEE authoritative variable data payload found.Debug
521Operational
521TrEE attestation variable data payload found.Debug
522Operational
522The process of converting an existing VM has started.Debug
523Operational
523A call has failed during the conversion process.Debug
524Operational
524The temporary VM will be named %2.Debug
525Operational
525The original VM's boot disk is at %2.Debug
526Operational
526The temporary VM has been created with identifier %2.Debug
527Operational
527The disk at %2 has been added to the temporary VM.Debug
528Operational
528A KVP value has been retrieved from the temporary VM: %2 / %3 Machine ID: %1.Debug
529The target UEFI db variable does not match the expected value and adoption is …Operational
530The target UEFI dbx variable does not match the expected value and adoption is …Operational
531Provisioning is unable to verify the Provisioning Agent stack version in the …Operational
532Operational
532The grandfathering utility disk and the boot disk of the original VM appear to …Debug
533Operational
533The VM boot disk is not a differencing disk.Debug

Event ID 0 — Cannot continue because a failure occurred while provisioning.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot continue because a failure occurred while provisioning. The message code is unknown, which can happen if the operating system of the VM is newer than that of the host.

Fields

NameDescription
MachineID
Source
DiagnosticID
FailureID

Event ID 1 — A general error occurred while provisioning the machine.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

A general error occurred while provisioning the machine. Unable to continue.

Fields

NameDescription
MachineID
SourceID
Win32ErrorCode

Event ID 2 — Cannot provision because the Shielded VM provisioning data cannot be decrypted.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot provision because the Shielded VM provisioning data cannot be decrypted.

Fields

NameDescription
MachineID
NtStatus

Event ID 3 — Cannot provision because the data from the remote TPM reflects an insecure state.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot provision because the data from the remote TPM reflects an insecure state. This may be caused by signing changes in the target OS or the selection of UEFI secure boot variables in Hyper-V.

Fields

NameDescription
MachineID
NtStatus

Event ID 4 — Cannot provision because an error was detected while communicating with the target machine.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot provision because an error was detected while communicating with the target machine.

Fields

NameDescription
MachineID
Win32ErrorCode

Event ID 5 — Cannot continue because the target machine detected a TPM failure.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot continue because the target machine detected a TPM failure. Verify that the target machine?s TPM is operational.

Fields

NameDescription
MachineID
NtStatus

Event ID 6 — Cannot continue because the provisioning agent was unable to retrieve the provisioning data due to a key error.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot continue because the provisioning agent was unable to retrieve the provisioning data due to a key error.

Fields

NameDescription
MachineID
NtStatus

Event ID 7 — Cannot provision because the template disk attached to the machine is invalid.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot provision because the template disk attached to the machine is invalid.

Fields

NameDescription
MachineID
NtStatus

Event ID 8 — Cannot provision because the volume signature catalog from the template disk is not properly signed.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot provision because the volume signature catalog from the template disk is not properly signed.

Fields

NameDescription
MachineID
NtStatus

Event ID 9 — Cannot provision because the provided Shielded VM provisioning data is not applicable to the template disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot provision because the provided Shielded VM provisioning data is not applicable to the template disk. Retry with an applicable template disk or update your provisioning data.

Fields

NameDescription
MachineID
NtStatus
TemplateNameFound
TemplateVersionFound

Event ID 10 — The template manager has determined that the template disk signature is invalid.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager has determined that the template disk signature is invalid. The disk may have been modified since the time at which it was originally signed.

Fields

NameDescription
MachineID
NtStatus

Event ID 11 — Unable to continue because a failure occurred while attempting to rekey the encryption on the operating system volume in the template disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Unable to continue because a failure occurred while attempting to rekey the encryption on the operating system volume in the template disk.

Fields

NameDescription
MachineID
NtStatus

Event ID 12 — An error occurred while processing the Shielded VM provisioning data content.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

An error occurred while processing the Shielded VM provisioning data content.

Fields

NameDescription
MachineID
NtStatus

Event ID 13 — Cannot provision because the Shielded VM provisioning data failed to write to disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot provision because the Shielded VM provisioning data failed to write to disk.

Fields

NameDescription
MachineID
NtStatus

Event ID 14 — The target machine?

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The target machine?s TPM is in an invalid state.

Fields

NameDescription
MachineID
NtStatus

Event ID 15 — Cannot continue because the provided Shielded VM provisioning data failed to load due to invalid content.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot continue because the provided Shielded VM provisioning data failed to load due to invalid content. Recreate the provisioning data and retry.

Fields

NameDescription
MachineID
NtStatus

Event ID 16 — Cannot continue because the remote machine disconnected unexpectedly.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot continue because the remote machine disconnected unexpectedly.

Fields

NameDescription
MachineID
NtStatus

Event ID 17 — Cannot continue because a failure occurred when accessing the secure storage.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot continue because a failure occurred when accessing the secure storage.

Fields

NameDescription
MachineID
NtStatus

Event ID 18 — Cannot provision because the volume signature catalog from the template disk is not properly signed.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot provision because the volume signature catalog from the template disk is not properly signed.

Fields

NameDescription
MachineID
NtStatus

Event ID 19 — Unable to create the Unattend.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Unable to create the Unattend.xml. Verify the Shielded VM provisioning data contains a valid Unattend.xml before provisioning.

Fields

NameDescription
MachineID
NtStatus

Event ID 20 — An error occurred while processing the Shielded VM provisioning data content.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

An error occurred while processing the Shielded VM provisioning data content.

Fields

NameDescription
MachineID
NtStatus

Event ID 21 — Cannot continue because Virtual Machine attestation failed during provisioning from template.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot continue because Virtual Machine attestation failed during provisioning from template. A common cause could be a change to the UEFI settings of the VM. Please check the event log for more details.

Fields

NameDescription
MachineID
NtStatus

Event ID 22 — Cannot continue because a failure occurred while calculating a hash of the template disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot continue because a failure occurred while calculating a hash of the template disk. If this template has been successfully used before, then this may have been the result of a transient disk error.

Fields

NameDescription
MachineID
NtStatus

Event ID 23 — Cannot continue because the signature file in the template disk is missing.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot continue because the signature file in the template disk is missing.

Fields

NameDescription
MachineID
NtStatus

Event ID 24 — Cannot continue because the TPM is missing the SRK.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Cannot continue because the TPM is missing the SRK.

Fields

NameDescription
MachineID
NtStatus

Event ID 25 — Provisioning cannot continue because the provisioning security process could not be launched.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning cannot continue because the provisioning security process could not be launched. Check whether the Isolated User Mode component is installed on the host and has been turned on.

Fields

NameDescription
MachineID
NtStatus

Event ID 26 — Provisioning cannot continue because the template disk does not have an expected volume signature catalog file and this has not been authorized by ...

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning cannot continue because the template disk does not have an expected volume signature catalog file and this has not been authorized by the provisioning data.

Fields

NameDescription
MachineID
NtStatus

Event ID 27 — Provisioning cannot continue because the template disk has an unexpected volume signature catalog file and the provisioning data does not authorize...

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning cannot continue because the template disk has an unexpected volume signature catalog file and the provisioning data does not authorize this.

Fields

NameDescription
MachineID
NtStatus

Event ID 28 — Provisioning cannot continue because the disk associated with the provisioned VM could not be protected.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning cannot continue because the disk associated with the provisioned VM could not be protected.

Fields

NameDescription
MachineID
NtStatus

Event ID 29 — Provisioning cannot continue because the operating system associated with the provisioned VM could not be updated to support appropriate security m...

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning cannot continue because the operating system associated with the provisioned VM could not be updated to support appropriate security measures.

Fields

NameDescription
MachineID
NtStatus

Event ID 30 — Provisioning cannot continue because the sealing values associated with the current boot configuration could not be properly predicted.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning cannot continue because the sealing values associated with the current boot configuration could not be properly predicted.

Fields

NameDescription
MachineID
NtStatus

Event ID 31 — Provisioning cannot continue because the initialization data required by the boot configuration process could not be updated.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning cannot continue because the initialization data required by the boot configuration process could not be updated.

Fields

NameDescription
MachineID
NtStatus

Event ID 32 — Provisioning may not continue because the UEFI database could not be loaded.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning may not continue because the UEFI database could not be loaded. This typically is caused by an improperly signed sbresources.dll. Please check the integrity of the host.

Fields

NameDescription
MachineGuid

Event ID 33 — Provisioning may not continue because a launch authority could not be calculated.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning may not continue because a launch authority could not be calculated.

Fields

NameDescription
MachineID
DataLength
Data

Event ID 34 — Provisioning failed to extend the secure boot PCR.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning failed to extend the secure boot PCR.

Fields

NameDescription
MachineGuid

Event ID 35 — Provisioning failed to extend the boot lock PCR.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning failed to extend the boot lock PCR.

Fields

NameDescription
MachineGuid

Event ID 36 — Provisioning could not generate the server key or TPM operations.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning could not generate the server key or TPM operations.

Fields

NameDescription
MachineGuid

Event ID 37 — The version of communication required by Provisioning was not understood by the template disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The version of communication required by Provisioning was not understood by the template disk.

Fields

NameDescription
MachineGuid

Event ID 38 — The template disk uses a version of communication not allowed by Provisioning.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template disk uses a version of communication not allowed by Provisioning.

Fields

NameDescription
MachineGuid

Event ID 39 — Msps_ProvisioningService: Timeout detected.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Msps_ProvisioningService: Timeout detected. The remote machine appears to be unresponsive. Provisioning failed.

Fields

NameDescription
MachineGuid

Event ID 40 — An error was provided to the provisioning service of behalf of another component.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

An error was provided to the provisioning service of behalf of another component: %1

Fields

NameDescription
MachineGuid
Name

Event ID 41 — The attempt to prepare the specialized machine failed.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The attempt to prepare the specialized machine failed. This can occur if the utility disk provided is incorrect, or if the host encounters a terminating error while interacting with Hyper-V.

Fields

NameDescription
MachineID
Win32ErrorCode

Event ID 42 — Provisioning agent reported a failure to unwrap the protected data.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning agent reported a failure to unwrap the protected data. Unable to continue.

Machine ID: %1
Error: %2

Fields

NameDescription
MachineID
NtStatus

Event ID 43 — The target has been deemed unhealthy or not secure by attestation, provisioning will not complete.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The target has been deemed unhealthy or not secure by attestation, provisioning will not complete.
  Machine ID:%1
  The status code is: %2

Fields

NameDescription
MachineID
NtStatus

Event ID 44 — Due to prior health assessment operations the provisioning security process has determined that it is not safe to generate a machine key.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Due to prior health assessment operations the provisioning security process has determined that it is not safe to generate a machine key.  Provisioning will not complete.
  Machine ID:%1
  The status code is: %2

Fields

NameDescription
MachineID
NtStatus

Event ID 45 — The provisioning service received a connection request from an unknown machine.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning service received a connection request from an unknown machine. Request will be ignored.
  Machine ID:%1

Fields

NameDescription
MachineGuid

Event ID 46 — The provisioning service received a connection request from a machine in an invalid state.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning service received a connection request from a machine in an invalid state. Request will be ignored.
  Machine ID:%1

Fields

NameDescription
MachineGuid

Event ID 47 — The virtual machine cannot be shielded because its virtual disk identifier appears to be the same as the virtual disk identifier used by the shield...

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The virtual machine cannot be shielded because its virtual disk identifier appears to be the same as the virtual disk identifier used by the shielding helper VHD.  This can occur when the same template disk was used to create both this virtual machine and the shielding helper VHD.

Fields

NameDescription
MachineGuid

Event ID 48 — The VM boot disk is a differencing disk which is not supported by the preparation process for security reasons

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The VM boot disk is a differencing disk which is not supported by the preparation process for security reasons

Fields

NameDescription
MachineGuid

Event ID 301 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
String
ErrorCode

Event ID 301 — WMI call failed.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

WMI call failed. Failure to execute %1 : MI_Result %2

Fields

NameDescription
String
ErrorCode

Event ID 302 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
String
ErrorCode

Event ID 302 — WMI call failed.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

WMI call failed. Failure to execute %1 : Win32_Result %2

Fields

NameDescription
String
ErrorCode

Event ID 303 — Msps_ProvisioningService: Shielded VM provisioning session started.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Msps_ProvisioningService: Shielded VM provisioning session started.

Machine ID: %1

Fields

NameDescription
MachineID

Event ID 304 — Msps_ProvisioningService: Failed to start Shielded VM provisioning session.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Msps_ProvisioningService: Failed to start Shielded VM provisioning session.

Machine ID: %1
Error: %2

Fields

NameDescription
MachineID
MiError

Event ID 305 — Msps_ProvisioningService: Failed to start Shielded VM provisioning session.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Msps_ProvisioningService: Failed to start Shielded VM provisioning session.

Machine ID: %1
Error: %2

Fields

NameDescription
MachineID
Win32Error

Event ID 306 — Msps_ProvisioningService: Shielded VM provisioning session opened.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Msps_ProvisioningService: Shielded VM provisioning session opened.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 307 — Msps_ProvisioningService: Shielded VM provisioning session closed.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Msps_ProvisioningService: Shielded VM provisioning session closed.

Machine ID: %1

Fields

NameDescription
MachineID

Event ID 308 — Msps_ProvisioningJob removed.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Msps_ProvisioningJob removed.

Instance ID %1

Fields

NameDescription
String

Event ID 309 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Event ID 309 — Msps_ProvisioningService service activated.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

Msps_ProvisioningService service activated.

Event ID 310 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Event ID 310 — Msps_ProvisioningService service completed.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

Msps_ProvisioningService service completed.

Event ID 311 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID

Event ID 311 — Msps_ProvisioningJob: Received request to retrieve job.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

Msps_ProvisioningJob: Received request to retrieve job.

Machine ID / Instance ID: %1

Fields

NameDescription
MachineID

Event ID 312 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID

Event ID 312 — Msps_ProvisioningJob: Received request to delete job.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

Msps_ProvisioningJob: Received request to delete job.

MachineID / Instance ID: %1

Fields

NameDescription
MachineID

Event ID 313 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
Uint

Event ID 313 — Msps_ProvisioningJob found %1 instances.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

Msps_ProvisioningJob found %1 instances.

Fields

NameDescription
Uint

Event ID 400 — The provisioning process logged an unknown event.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning process logged an unknown event. This can happen if the template disk is from a newer operating system than the host.

Machine ID: %1

Fields

NameDescription
MachineGuid
EventId
SourceId
EventPayloadSizeBytes
EventPayload

Event ID 401 — The provisioning data has been received over the secure channel.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning data has been received over the secure channel.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 402 — The fabric data has been received over the secure channel.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The fabric data has been received over the secure channel.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 403 — The provisioning data was successfully transferred over the secure channel.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning data was successfully transferred over the secure channel.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 404 — The secure inputs are being processed by the provisioning service.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The secure inputs are being processed by the provisioning service.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 405 — The VM being provisioned is communicating with the remote TPM.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The VM being provisioned is communicating with the remote TPM.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 406 — Provisioning started.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning started.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 407 — The Shielded VM was successfully provisioned.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The Shielded VM was successfully provisioned.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 408 — The template manager is analyzing the template disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager is analyzing the template disk.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 409 — The template manager finished analyzing the template disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager finished analyzing the template disk.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 410 — The template manager is sealing the template disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager is sealing the template disk.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 411 — The template manager has sealed the template disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager has sealed the template disk.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 412 — The specialization agent is applying the fabric data to the template disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The specialization agent is applying the fabric data to the template disk.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 413 — The specialization agent has finished applying the fabric data to the template disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The specialization agent has finished applying the fabric data to the template disk.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 414 — The provisioning agent has started executing the plugins for the Shielded VM.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning agent has started executing the plugins for the Shielded VM.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 415 — The provisioning agent has finished executing the plugins for the Shielded VM.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning agent has finished executing the plugins for the Shielded VM.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 416 — A specialization value was replaced in the Shielded VM's unattend file.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

A specialization value was replaced in the Shielded VM's unattend file.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 417 — The provisioning agent was started and is communicating with the host machine.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning agent was started and is communicating with the host machine.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 418 — The provisioning process was started within the Shielded VM and is communicating with the host machine.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning process was started within the Shielded VM and is communicating with the host machine.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 419 — The UEFI variables were received by the provisioning process.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The UEFI variables were received by the provisioning process.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 420 — An attestation event was received from the provisioning process.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

An attestation event was received from the provisioning process.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 421 — A diagnostic attestation event was received from the provisioning process.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

A diagnostic attestation event was received from the provisioning process.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 422 — No instance of %2 was found in the unattend file included in the provisioning data.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

No instance of %2 was found in the unattend file included in the provisioning data.

Machine ID: %1

Fields

NameDescription
MachineGuid
Name

Event ID 423 — The template manager is skipping verification of the signature catalog on disk because it does not exist and the provisioning data allows this Mach...

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager is skipping verification of the signature catalog on disk because it does not exist and the provisioning data allows this

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 424 — The template manager is skipping verification of the signature catalog on disk because it does not exist and the provisioning data allows this Mach...

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager is skipping verification of the signature catalog on disk because it does not exist and the provisioning data allows this

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 425 — The template manager has updated the factory policy of the provisioned VM Machine ID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager has updated the factory policy of the provisioned VM

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 426 — The template manager has set the sealing values of the provisioned VM Machine ID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager has set the sealing values of the provisioned VM

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 427 — The provisioning agent is starting the Execute pass on the provisioned VM Machine ID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning agent is starting the Execute pass on the provisioned VM

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 428 — The provisioning agent has finished the Execute pass on the provisioned VM Machine ID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning agent has finished the Execute pass on the provisioned VM

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 429 — The provisioning agent has finished the platform update on the provisioned VM Machine ID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning agent has finished the platform update on the provisioned VM

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 430 — The provisioning agent is starting to predict the sealing values of the provisioned VM Machine ID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning agent is starting to predict the sealing values of the provisioned VM

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 431 — The provisioning agent is starting the Finalize pass on the provisioned VM Machine ID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning agent is starting the Finalize pass on the provisioned VM

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 432 — The provisioning agent has finished the Finalize pass on the provisioned VM Machine ID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning agent has finished the Finalize pass on the provisioned VM

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 433 — The provisioning agent is allowed to use the UEFI CA per current policy Machine ID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning agent is allowed to use the UEFI CA per current policy

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 434 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 434 — The provisioning service is selecting a launch authority Machine ID.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The provisioning service is selecting a launch authority

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 435 — The template disk has declared its current version for the purposes of negotiation.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template disk has declared its current version for the purposes of negotiation.

Fields

NameDescription
MachineID
VersionNegotiationVersion
DeclaredVersionMajor
DeclaredVersionMinor
DeclaredVersionBuild
DeclaredVersionRelease
DeclaredVersionLogicalMajor
DeclaredVersionLogicalMinor
AcceptableVersionStartMajor
AcceptableVersionStartMinor

Event ID 436 — The provisioning service has accepted a communications version supported by the template disk

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The provisioning service has accepted a communications version supported by the template disk

Fields

NameDescription
MachineID
AcceptedVersionStartMajor
AcceptedVersionStartMinor

Event ID 437 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
uint
uint2

Event ID 437 — Received status update from the template manager.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

Received status update from the template manager.

Machine ID: %1
Status %2
Percent %3

Fields

NameDescription
MachineID
uint
uint2

Event ID 438 — The template manager successfully validated the image hash.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager successfully validated the image hash.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 439 — The template manager completed rolling the FVEK.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager completed rolling the FVEK.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 440 — The template manager successfully protected the volume.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The template manager successfully protected the volume.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 441 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
PDKDestinationID
PDKSectionID

Event ID 441 — The provisioning Agent encountered an unknown data section.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The provisioning Agent encountered an unknown data section.

Machine ID: %1%Destination: %2
Section ID: %3

Fields

NameDescription
MachineID
PDKDestinationID
PDKSectionID

Event ID 442 — An external BitLocker key was created for a template volume.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

An external BitLocker key was created for a template volume.
  Machine ID:%1

Fields

NameDescription
MachineGuid

Event ID 443 — An encrypted BitLocker external key for a template volume was written to disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

An encrypted BitLocker external key for a template volume was written to disk.
  Machine ID:%1

Fields

NameDescription
MachineGuid

Event ID 500 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
Source
DiagnosticID
FailureID

Event ID 500 — Ptp Session Event Machine ID: %1 Source: %2 EventID %3.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

Ptp Session Event

Machine ID: %1
Source: %2
EventID %3

Fields

NameDescription
MachineID
Source
DiagnosticID
FailureID

Event ID 501 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
Source
DiagnosticID
FailureID

Event ID 501 — Ptp Session Event Machine ID: %1 Source: %2 EventID %3.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

Ptp Session Event

Machine ID: %1
Source: %2
EventID %3

Fields

NameDescription
MachineID
Source
DiagnosticID
FailureID

Event ID 502 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
uint

Event ID 502 — Invalid payload in error notification.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

Invalid payload in error notification.

Machine ID: %1
ErrorID: %2

Fields

NameDescription
MachineID
uint

Event ID 503 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
uint

Event ID 503 — Invalid attestation payload in notification.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

Invalid attestation payload in notification.

Machine ID: %1%Size: %2

Fields

NameDescription
MachineID
uint

Event ID 504 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
uint

Event ID 504 — %2 attestation items received from the attestation diagnostics log.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

%2 attestation items received from the attestation diagnostics log.

Machine ID: %1

Fields

NameDescription
MachineID
uint

Event ID 505 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
uint

Event ID 505 — An attestation log item was too short to be valid (%2 bytes).

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

An attestation log item was too short to be valid (%2 bytes).

Machine ID: %1

Fields

NameDescription
MachineID
uint

Event ID 506 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 506 — The authoritative event log was deemed invalid.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The authoritative event log was deemed invalid.

Fields

NameDescription
MachineGuid

Event ID 507 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 507 — The authoritative event log is missing an event.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The authoritative event log is missing an event.

Fields

NameDescription
MachineGuid

Event ID 508 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 508 — The attestation log is missing an event.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The attestation log is missing an event.

Fields

NameDescription
MachineGuid

Event ID 509 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 509 — The data in the attestation event is incorrect.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The data in the attestation event is incorrect.

Fields

NameDescription
MachineGuid

Event ID 510 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 510 — The attestation log is invalid.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The attestation log is invalid.

Fields

NameDescription
MachineGuid

Event ID 511 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 511 — An unexpected attestation event was encountered.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

An unexpected attestation event was encountered.

Fields

NameDescription
MachineGuid

Event ID 512 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 512 — The attestation log contained an event which was incorrect.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The attestation log contained an event which was incorrect.

Fields

NameDescription
MachineGuid

Event ID 513 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
uint

Event ID 513 — The attestation event log contains an unknown event.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The attestation event log contains an unknown event. The event ID was %2.

Fields

NameDescription
MachineID
uint

Event ID 514 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 514 — An attestation event log item is corrupt.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

An attestation event log item is corrupt.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 515 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid
Name

Event ID 515 — The name of the attestation event log item is %2.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The name of the attestation event log item is %2.

Machine ID: %1

Fields

NameDescription
MachineGuid
Name

Event ID 516 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 516 — The attestation event log item name has no name information.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The attestation event log item name has no name information.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 517 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 517 — The attestation event log item WCBL payload appears corrupt.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The attestation event log item WCBL payload appears corrupt.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 518 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
PCRIndex
RelativeOrderToPCR
Event
Length

Event ID 518 — PCR Index: %2, Zero-based order relative to PCR: %3, Event: %4, Length: %5 Machine ID: %1.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

PCR Index: %2, Zero-based order relative to PCR: %3, Event: %4, Length: %5

Machine ID: %1

Fields

NameDescription
MachineID
PCRIndex
RelativeOrderToPCR
Event
Length

Event ID 519 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 519 — The event data is too short or otherwise corrupt and does not contain a TrEE variable.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The event data is too short or otherwise corrupt and does not contain a TrEE variable.

Machine ID: %1

Fields

NameDescription
MachineGuid

Event ID 520 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
Namespace
UnicodeName
DataLength
Data

Event ID 520 — TrEE authoritative variable data payload found.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

TrEE authoritative variable data payload found.

Machine ID: %1

Fields

NameDescription
MachineID
Namespace
UnicodeName
DataLength
Data

Event ID 521 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
Namespace
UnicodeName
DataLength
Data

Event ID 521 — TrEE attestation variable data payload found.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

TrEE attestation variable data payload found.

Machine ID: %1

Fields

NameDescription
MachineID
Namespace
UnicodeName
DataLength
Data

Event ID 522 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid
Name

Event ID 522 — The process of converting an existing VM has started.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The process of converting an existing VM has started.

Machine ID: %1

Fields

NameDescription
MachineGuid
Name

Event ID 523 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
Name
Win32ErrorCode

Event ID 523 — A call has failed during the conversion process.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

A call has failed during the conversion process.

Machine ID: %1

Call site: %2

Error code:%3

Fields

NameDescription
MachineID
Name
Win32ErrorCode

Event ID 524 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
Name

Event ID 524 — The temporary VM will be named %2.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The temporary VM will be named %2.

Machine ID: %1

Fields

NameDescription
MachineID
Name

Event ID 525 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
Name

Event ID 525 — The original VM's boot disk is at %2.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The original VM's boot disk is at %2.

Machine ID: %1

Fields

NameDescription
MachineID
Name

Event ID 526 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
Name

Event ID 526 — The temporary VM has been created with identifier %2.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The temporary VM has been created with identifier %2.

Machine ID: %1

Fields

NameDescription
MachineID
Name

Event ID 527 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
Name

Event ID 527 — The disk at %2 has been added to the temporary VM.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The disk at %2 has been added to the temporary VM.

Machine ID: %1

Fields

NameDescription
MachineID
Name

Event ID 528 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineID
Name
Value

Event ID 528 — A KVP value has been retrieved from the temporary VM: %2 / %3 Machine ID: %1.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

A KVP value has been retrieved from the temporary VM: %2 / %3

Machine ID: %1

Fields

NameDescription
MachineID
Name
Value

Event ID 529 — The target UEFI db variable does not match the expected value and adoption is blocked by policy.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The target UEFI db variable does not match the expected value and adoption is blocked by policy.  Provisioning may fail.
  Machine ID:%1

Fields

NameDescription
MachineGuid

Event ID 530 — The target UEFI dbx variable does not match the expected value and adoption is blocked by policy.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

The target UEFI dbx variable does not match the expected value and adoption is blocked by policy.  Provisioning may fail.
  Machine ID:%1

Fields

NameDescription
MachineGuid

Event ID 531 — Provisioning is unable to verify the Provisioning Agent stack version in the target.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Message

Provisioning is unable to verify the Provisioning Agent stack version in the target.  Provisioning may fail.
  Machine ID:%1

Fields

NameDescription
MachineGuid

Event ID 532 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 532 — The grandfathering utility disk and the boot disk of the original VM appear to be unique.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The grandfathering utility disk and the boot disk of the original VM appear to be unique.
  Machine ID:%1

Fields

NameDescription
MachineGuid

Event ID 533 —

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Operational

Fields

NameDescription
MachineGuid

Event ID 533 — The VM boot disk is not a differencing disk.

Provider
Microsoft-Windows-ShieldedVM-ProvisioningService
Channel
Debug

Message

The VM boot disk is not a differencing disk.
  Machine ID:%1

Fields

NameDescription
MachineGuid