Microsoft-Windows-ShieldedVM-ProvisioningService
181 events across 2 channels
Event ID 0 — Cannot continue because a failure occurred while provisioning.
Event ID 1 — A general error occurred while provisioning the machine.
Event ID 2 — Cannot provision because the Shielded VM provisioning data cannot be decrypted.
Event ID 3 — Cannot provision because the data from the remote TPM reflects an insecure state.
Event ID 4 — Cannot provision because an error was detected while communicating with the target machine.
Event ID 5 — Cannot continue because the target machine detected a TPM failure.
Event ID 6 — Cannot continue because the provisioning agent was unable to retrieve the provisioning data due to a key error.
Event ID 7 — Cannot provision because the template disk attached to the machine is invalid.
Event ID 8 — Cannot provision because the volume signature catalog from the template disk is not properly signed.
Event ID 9 — Cannot provision because the provided Shielded VM provisioning data is not applicable to the template disk.
Description
Cannot provision because the provided Shielded VM provisioning data is not applicable to the template disk. Retry with an applicable template disk or update your provisioning data.
Message #
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
NtStatus UInt32 | — |
TemplateNameFound UnicodeString | — |
TemplateVersionFound HexInt64 | — |
Event ID 10 — The template manager has determined that the template disk signature is invalid.
Event ID 11 — Unable to continue because a failure occurred while attempting to rekey the encryption on the operating system volume in the template disk.
Event ID 12 — An error occurred while processing the Shielded VM provisioning data content.
Event ID 13 — Cannot provision because the Shielded VM provisioning data failed to write to disk.
Event ID 14 — The target machine?
Event ID 15 — Cannot continue because the provided Shielded VM provisioning data failed to load due to invalid content.
Event ID 16 — Cannot continue because the remote machine disconnected unexpectedly.
Event ID 17 — Cannot continue because a failure occurred when accessing the secure storage.
Event ID 18 — Cannot provision because the volume signature catalog from the template disk is not properly signed.
Event ID 19 — Unable to create the Unattend.
Event ID 20 — An error occurred while processing the Shielded VM provisioning data content.
Event ID 21 — Cannot continue because Virtual Machine attestation failed during provisioning from template.
Event ID 22 — Cannot continue because a failure occurred while calculating a hash of the template disk.
Event ID 23 — Cannot continue because the signature file in the template disk is missing.
Event ID 24 — Cannot continue because the TPM is missing the SRK.
Event ID 25 — Provisioning cannot continue because the provisioning security process could not be launched.
Event ID 26 — Provisioning cannot continue because the template disk does not have an expected volume signature catalog file and this has not been authorized by ...
Event ID 27 — Provisioning cannot continue because the template disk has an unexpected volume signature catalog file and the provisioning data does not authorize...
Event ID 28 — Provisioning cannot continue because the disk associated with the provisioned VM could not be protected.
Event ID 29 — Provisioning cannot continue because the operating system associated with the provisioned VM could not be updated to support appropriate security m...
Event ID 30 — Provisioning cannot continue because the sealing values associated with the current boot configuration could not be properly predicted.
Event ID 31 — Provisioning cannot continue because the initialization data required by the boot configuration process could not be updated.
Event ID 32 — Provisioning may not continue because the UEFI database could not be loaded.
Event ID 33 — Provisioning may not continue because a launch authority could not be calculated.
Event ID 34 — Provisioning failed to extend the secure boot PCR.
Event ID 35 — Provisioning failed to extend the boot lock PCR.
Event ID 36 — Provisioning could not generate the server key or TPM operations.
Event ID 37 — The version of communication required by Provisioning was not understood by the template disk.
Event ID 38 — The template disk uses a version of communication not allowed by Provisioning.
Event ID 39 — Msps_ProvisioningService: Timeout detected.
Event ID 40 — An error was provided to the provisioning service of behalf of another component: MachineGuid.
Event ID 41 — The attempt to prepare the specialized machine failed.
Event ID 42 — Provisioning agent reported a failure to unwrap the protected data.
Event ID 43 — The target has been deemed unhealthy or not secure by attestation, provisioning will not complete.
Event ID 44 — Due to prior health assessment operations the provisioning security process has determined that it is not safe to generate a machine key.
Event ID 45 — The provisioning service received a connection request from an unknown machine.
Event ID 46 — The provisioning service received a connection request from a machine in an invalid state.
Event ID 47 — The virtual machine cannot be shielded because its virtual disk identifier appears to be the same as the virtual disk identifier used by the shield...
Event ID 48 — The VM boot disk is a differencing disk which is not supported by the preparation process for security reasons
Event ID 301 — WMI call failed.
Event ID 301 —
Description
WMI call failed. Failure to execute : MI_Result.
Fields #
| Name | Description |
|---|---|
String AnsiString | — |
ErrorCode UInt32 | — |
Event ID 302 — WMI call failed.
Event ID 302 —
Description
WMI call failed. Failure to execute : Win32_Result.
Fields #
| Name | Description |
|---|---|
String AnsiString | — |
ErrorCode UInt32 | — |
Event ID 303 — Msps_ProvisioningService: Shielded VM provisioning session started.
Event ID 304 — Msps_ProvisioningService: Failed to start Shielded VM provisioning session.
Event ID 305 — Msps_ProvisioningService: Failed to start Shielded VM provisioning session.
Event ID 306 — Msps_ProvisioningService: Shielded VM provisioning session opened.
Event ID 307 — Msps_ProvisioningService: Shielded VM provisioning session closed.
Event ID 308 — Msps_ProvisioningJob removed.
Event ID 309 — Msps_ProvisioningService service activated.
Description
Msps_ProvisioningService service activated.
Message #
Event ID 309 —
Description
Msps_ProvisioningService service activated.
Event ID 310 — Msps_ProvisioningService service completed.
Description
Msps_ProvisioningService service completed.
Message #
Event ID 310 —
Description
Msps_ProvisioningService service completed.
Event ID 311 — Msps_ProvisioningJob: Received request to retrieve job.
Event ID 311 —
Description
Msps_ProvisioningJob: Received request to retrieve job.
Fields #
| Name | Description |
|---|---|
MachineID UnicodeString | — |
Event ID 312 — Msps_ProvisioningJob: Received request to delete job.
Event ID 312 —
Description
Msps_ProvisioningJob: Received request to delete job.
Fields #
| Name | Description |
|---|---|
MachineID UnicodeString | — |
Event ID 313 — Msps_ProvisioningJob found Uint instances.
Event ID 313 —
Description
Msps_ProvisioningJob found instances.
Fields #
| Name | Description |
|---|---|
Uint UInt32 | — |
Event ID 400 — The provisioning process logged an unknown event.
Event ID 401 — The provisioning data has been received over the secure channel.
Event ID 402 — The fabric data has been received over the secure channel.
Event ID 403 — The provisioning data was successfully transferred over the secure channel.
Event ID 404 — The secure inputs are being processed by the provisioning service.
Event ID 405 — The VM being provisioned is communicating with the remote TPM.
Event ID 406 — Provisioning started.
Event ID 407 — The Shielded VM was successfully provisioned.
Event ID 408 — The template manager is analyzing the template disk.
Event ID 409 — The template manager finished analyzing the template disk.
Event ID 410 — The template manager is sealing the template disk.
Event ID 411 — The template manager has sealed the template disk.
Event ID 412 — The specialization agent is applying the fabric data to the template disk.
Event ID 413 — The specialization agent has finished applying the fabric data to the template disk.
Event ID 414 — The provisioning agent has started executing the plugins for the Shielded VM.
Event ID 415 — The provisioning agent has finished executing the plugins for the Shielded VM.
Event ID 416 — A specialization value was replaced in the Shielded VM's unattend file.
Event ID 417 — The provisioning agent was started and is communicating with the host machine.
Event ID 418 — The provisioning process was started within the Shielded VM and is communicating with the host machine.
Event ID 419 — The UEFI variables were received by the provisioning process.
Event ID 420 — An attestation event was received from the provisioning process.
Event ID 421 — A diagnostic attestation event was received from the provisioning process.
Event ID 422 — No instance of Name was found in the unattend file included in the provisioning data.
Event ID 423 — The template manager is skipping verification of the signature catalog on disk because it does not exist and the provisioning data allows this Mach...
Event ID 424 — The template manager is skipping verification of the signature catalog on disk because it does not exist and the provisioning data allows this Mach...
Event ID 425 — The template manager has updated the factory policy of the provisioned VM Machine ID.
Event ID 426 — The template manager has set the sealing values of the provisioned VM Machine ID.
Event ID 427 — The provisioning agent is starting the Execute pass on the provisioned VM Machine ID.
Event ID 428 — The provisioning agent has finished the Execute pass on the provisioned VM Machine ID.
Event ID 429 — The provisioning agent has finished the platform update on the provisioned VM Machine ID.
Event ID 430 — The provisioning agent is starting to predict the sealing values of the provisioned VM Machine ID.
Event ID 431 — The provisioning agent is starting the Finalize pass on the provisioned VM Machine ID.
Event ID 432 — The provisioning agent has finished the Finalize pass on the provisioned VM Machine ID.
Event ID 433 — The provisioning agent is allowed to use the UEFI CA per current policy Machine ID.
Event ID 434 — The provisioning service is selecting a launch authority Machine ID.
Event ID 434 —
Description
The provisioning service is selecting a launch authority.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 435 — The template disk has declared its current version for the purposes of negotiation.
Description
The template disk has declared its current version for the purposes of negotiation.
Message #
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
VersionNegotiationVersion UInt8 | — |
DeclaredVersionMajor UInt16 | — |
DeclaredVersionMinor UInt16 | — |
DeclaredVersionBuild UInt16 | — |
DeclaredVersionRelease UInt16 | — |
DeclaredVersionLogicalMajor UInt8 | — |
DeclaredVersionLogicalMinor UInt8 | — |
AcceptableVersionStartMajor UInt8 | — |
AcceptableVersionStartMinor UInt8 | — |
Event ID 436 — The provisioning service has accepted a communications version supported by the template disk
Event ID 437 — Received status update from the template manager.
Event ID 437 —
Description
Received status update from the template manager.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
uint UInt32 | — |
uint2 UInt32 | — |
Event ID 438 — The template manager successfully validated the image hash.
Event ID 439 — The template manager completed rolling the FVEK.
Event ID 440 — The template manager successfully protected the volume.
Event ID 441 — The provisioning Agent encountered an unknown data section.
Event ID 441 —
Description
The provisioning Agent encountered an unknown data section.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
PDKDestinationID GUID | — |
PDKSectionID GUID | — |
Event ID 442 — An external BitLocker key was created for a template volume.
Event ID 443 — An encrypted BitLocker external key for a template volume was written to disk.
Event ID 500 — Ptp Session Event.
Event ID 500 —
Description
Ptp Session Event.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
Source UInt32 | — |
DiagnosticID UInt32 | — |
FailureID UInt32 | — |
Event ID 501 — Ptp Session Event.
Event ID 501 —
Description
Ptp Session Event.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
Source UInt32 | — |
DiagnosticID UInt32 | — |
FailureID UInt32 | — |
Event ID 502 — Invalid payload in error notification.
Event ID 502 —
Description
Invalid payload in error notification.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
uint UInt32 | — |
Event ID 503 — Invalid attestation payload in notification.
Event ID 503 —
Description
Invalid attestation payload in notification.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
uint UInt32 | — |
Event ID 504 — uint attestation items received from the attestation diagnostics log.
Event ID 504 —
Description
attestation items received from the attestation diagnostics log.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
uint UInt32 | — |
Event ID 505 — An attestation log item was too short to be valid (uint bytes).
Event ID 505 —
Description
An attestation log item was too short to be valid ( bytes).
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
uint UInt32 | — |
Event ID 506 — The authoritative event log was deemed invalid.
Event ID 506 —
Description
The authoritative event log was deemed invalid.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 507 — The authoritative event log is missing an event.
Event ID 507 —
Description
The authoritative event log is missing an event.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 508 — The attestation log is missing an event.
Event ID 508 —
Description
The attestation log is missing an event.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 509 — The data in the attestation event is incorrect.
Event ID 509 —
Description
The data in the attestation event is incorrect.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 510 — The attestation log is invalid.
Event ID 510 —
Description
The attestation log is invalid.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 511 — An unexpected attestation event was encountered.
Event ID 511 —
Description
An unexpected attestation event was encountered.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 512 — The attestation log contained an event which was incorrect.
Event ID 512 —
Description
The attestation log contained an event which was incorrect.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 513 — The attestation event log contains an unknown event.
Event ID 513 —
Description
The attestation event log contains an unknown event. The event ID was .
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
uint UInt32 | — |
Event ID 514 — An attestation event log item is corrupt.
Event ID 514 —
Description
An attestation event log item is corrupt.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 515 — The name of the attestation event log item is Name.
Event ID 515 —
Description
The name of the attestation event log item is .
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Name UnicodeString | — |
Event ID 516 — The attestation event log item name has no name information.
Event ID 516 —
Description
The attestation event log item name has no name information.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 517 — The attestation event log item WCBL payload appears corrupt.
Event ID 517 —
Description
The attestation event log item WCBL payload appears corrupt.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 518 — PCR Index: PCRIndex, Zero-based order relative to PCR: RelativeOrderToPCR, Event: Event, Length: Length.
Event ID 518 —
Description
PCR Index: , Zero-based order relative to PCR: , Event: , Length.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
PCRIndex UInt32 | — |
RelativeOrderToPCR UInt32 | — |
Event UInt32 | — |
Length UInt32 | — |
Event ID 519 — The event data is too short or otherwise corrupt and does not contain a TrEE variable.
Event ID 519 —
Description
The event data is too short or otherwise corrupt and does not contain a TrEE variable.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 520 — TrEE authoritative variable data payload found.
Event ID 520 —
Description
TrEE authoritative variable data payload found.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
Namespace GUID | — |
UnicodeName UnicodeString | — |
DataLength UInt32 | — |
Data Binary | — |
Event ID 521 — TrEE attestation variable data payload found.
Event ID 521 —
Description
TrEE attestation variable data payload found.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
Namespace GUID | — |
UnicodeName UnicodeString | — |
DataLength UInt32 | — |
Data Binary | — |
Event ID 522 — The process of converting an existing VM has started.
Event ID 522 —
Description
The process of converting an existing VM has started.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Name UnicodeString | — |
Event ID 523 — A call has failed during the conversion process.
Event ID 523 —
Description
A call has failed during the conversion process.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
Name UnicodeString | — |
Win32ErrorCode UInt32 | — |
Event ID 524 — The temporary VM will be named Name.
Event ID 524 —
Description
The temporary VM will be named .
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
Name UnicodeString | — |
Event ID 525 — The original VM's boot disk is at Name.
Event ID 525 —
Description
The original VM's boot disk is at .
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
Name UnicodeString | — |
Event ID 526 — The temporary VM has been created with identifier Name.
Event ID 526 —
Description
The temporary VM has been created with identifier .
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
Name UnicodeString | — |
Event ID 527 — The disk at Name has been added to the temporary VM.
Event ID 527 —
Description
The disk at has been added to the temporary VM.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
Name UnicodeString | — |
Event ID 528 — A KVP value has been retrieved from the temporary VM: Name / Value.
Event ID 528 —
Description
A KVP value has been retrieved from the temporary VM: /.
Fields #
| Name | Description |
|---|---|
MachineID GUID | — |
Name UnicodeString | — |
Value UnicodeString | — |
Event ID 529 — The target UEFI db variable does not match the expected value and adoption is blocked by policy.
Event ID 530 — The target UEFI dbx variable does not match the expected value and adoption is blocked by policy.
Event ID 531 — Provisioning is unable to verify the Provisioning Agent stack version in the target.
Event ID 532 — The grandfathering utility disk and the boot disk of the original VM appear to be unique.
Event ID 532 —
Description
The grandfathering utility disk and the boot disk of the original VM appear to be unique.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |
Event ID 533 — The VM boot disk is not a differencing disk.
Event ID 533 —
Description
The VM boot disk is not a differencing disk.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | — |