Microsoft-Windows-TerminalServices-Gateway

120 events across 3 channels

Event IDTitleChannel
100The RD Gateway service could not be initialized.Operational
101The RD Gateway service has started.Operational
102The Remote Desktop Gateway service requires a valid Secure Sockets Layer (SSL) …Operational
103The Remote Desktop Gateway service does not have sufficient permissions to …Operational
104The UDP Proxy is started.Operational
105The UDP Proxy is shutting down.Operational
106The UDP Proxy is not enabled.Operational
200The user "EventInfo.Username", on client computer "EventInfo.IpAddress", met …Operational
201The user "%1", on client computer "%2", did not meet connection authorization …Operational
202The administrator disconnected the user "%1", on client computer "%2", from the …Operational
203The number of simultaneous connections to the RD Gateway server has reached the …Operational
204The user "%1", on client computer "%2", did not meet the requirements of the …Operational
205The user "%1", on client computer "%2", successfully connected to the remote …Operational
206The user "%1", on client computer "%2", failed connection to the remote server …Operational
207The administrator disconnected the user "%1", on client computer "%2", from the …Operational
208The UDP Proxy disconnected the user "%1" on client computer "%2", from the …Operational
209The RD Gateway client supports HTTP proxy protocol but connected using Legacy …Admin
210Http transport: IN channel could not find a corresponding OUT channelAdmin
300The user "EventInfo.Username", on client computer "EventInfo.IpAddress", met …Operational
301The user "%1", on client computer "%2", did not meet resource authorization …Operational
302The user "EventInfo.Username", on client computer "EventInfo.IpAddress", …Operational
303The user "EventInfo.Username", on client computer "EventInfo.IpAddress", …Operational
304The user "%1", on client computer "%2", met connection authorization policy and …Operational
305The user "%1", on client computer "%2", was not authorized to connect to this RD …Operational
306The user "%1", on client computer "%2", was not authorized to connect to the RD …Operational
307The user "%1", on client computer "%2", disconnected from the following network …Operational
308The user "%1", on client computer "%2", met RD resource authorization policy (RD …Operational
309The user "%1", on client computer "%2", was disconnected from the following …Operational
310The user "%1", connected by using client computer "%2" and "%8" connection …Operational
311The user "%1", on client computer "%2", did not connect to the following network …Operational
312The user "EventInfo.Username", on client computer "EventInfo.IpAddress", has …Operational
313The user "%1", on client computer "%2", has initiated an inbound connection.Operational
400The RD Gateway service is shutting down.Operational
401The RD Gateway service successfully registered with the Service Connection …Operational
402The RD Gateway service failed to register with the Service Connection Point.Operational
403The RD Gateway service successfully unregistered with the Service Connection …Operational
404The RD Gateway service failed to unregister with the Service Connection Point.Operational
504Logging was enabled for the following RD Gateway event: "%1".Admin
505Logging could not be enabled for the following RD Gateway event: "%1".Admin
506Logging was disabled for the following RD Gateway event: "%1".Admin
507Logging could not be disabled for the following RD Gateway event: "%1".Admin
508The value for the maximum number of connections allowed to the RD Gateway server …Admin
509The value for the maximum number of simultaneous connections allowed to the RD …Admin
510The central connection authorization policy was enabled.Admin
511The central connection authorization policy store could not be enabled.Admin
512The central connection authorization policy was disabled.Admin
513The central connection authorization policy store could not be disabled.Admin
514The 'Request clients to send a statement of health' (SoH) setting is enabled on …Admin
515The 'Request clients to send a statement of health' (SoH) setting could not be …Admin
516The 'Request clients to send a statement of health' (SoH) setting is not enabled …Admin
517The 'Request clients to send a statement of health' (SoH) setting could not be …Admin
518The 'Request clients to send a statement of health' (SoH) setting could not be …Admin
519The server certificate is not valid because the public key of the certificate …Admin
520The connection authorization policy "%1" was created.Admin
521The connection authorization policy "%1" was deleted.Admin
522The connection authorization policy "%1" was updated.Admin
523The connection authorization policy "%1" could not be created.Admin
524The connection authorization policy "%1" could not be deleted.Admin
525The connection authorization policy "%1" could not be updated.Admin
526The system message was not enabled because a failure occurred.Admin
527The system message was successfully enabled.Admin
528The system message was not disabled because a failure occurred.Admin
529The system message was successfully disabled.Admin
530The logon message was not enabled because a failure occurred.Admin
531The logon message was successfully enabled.Admin
532The current logon message was not disabled because a failure occurred.Admin
533The current logon message was successfully disabled.Admin
540The resource authorization policy "%1" was created.Admin
541The resource authorization policy "%1" was deleted.Admin
542The resource authorization policy "%1" was updated.Admin
543The resource authorization policy (RAP) "%1" could not be created.Admin
544The resource authorization policy (RAP) "%1" could not be deleted.Admin
545The resource authorization policy (RAP) "%1" could not be updated.Admin
560The resource group "%1" was created.Admin
561The resource group "%1" was deleted.Admin
562The resource group "%1" was updated.Admin
563The resource group "%1" could not be created.Admin
564The resource group "%1" could not be deleted.Admin
565The resource group "%1" could not be updated.Admin
580The Network Policy Server (NPS) "%1" was added to the central connection …Admin
581The Network Policy Server (NPS) "%1" was deleted from the central connection …Admin
582The central connection authorization policy settings for the Network Policy …Admin
583The Network Policy Server (NPS) "%1" could not be added to the central …Admin
584The Network Policy Server (NPS) "%1" could not be deleted from the central …Admin
585The central connection authorization policy settings for the Network Policy …Admin
600Tracing
601%1, Failed with %2.Tracing
620The RD Gateway server "%1" was deleted from the list of servers in the RD …Admin
621The RD Gateway servers "%1" were added to the RD Gateway managed group.Admin
622The RD Gateway server "%1" could not be deleted from the list of servers in the …Admin
623The RD Gateway servers "%1" could not be added to the Remote Desktop Gateway …Admin
624The RD Gateway server "%1" is not a member of a domain and therefore cannot be …Admin
625A Windows Firewall exception for RD Gateway has been configured to allow data …Admin
626The Windows Firewall exception for RD Gateway to allow network traffic …Admin
627The Windows Firewall exception to allow network traffic through TCP port 3388.Admin
628The Windows Firewall exception "RD Gateway Server Farm" that allows network …Admin
629The RD Gateway servers "%1" were set to the RD Gateway managed group.Admin
630The RD Gateway servers "%1" could not be set to the RD Gateway managed group.Admin
640RD Gateway Network access Policy engine failed to contact IAS and the error was …Operational
641RD Gateway Network access Policy engine received failure from IAS and the error …Operational
642The RD Gateway server cannot open the resource authorization policy store on …Operational
643RD Gateway Resource access Policy engine failed to open Azman Application(Remote …Operational
700The following exception code "%2" occured in the RD Gateway server.Admin
701The exception code "%2" occurred in the authentication plug-in: "%1" loaded by …Admin
702The exception code "%2" occurred in the authorization plug-in: "%1" loaded by …Admin
1001The Remote Desktop Gateway service cannot determine the version of Windows that …Admin
1002The user authentication plug-in "%1" has been configured.Admin
1003RD Gateway native authentication is configured.Admin
1004The user authorization plug-in "%1" is enabled.Admin
1005The RD Gateway native authorization is enabled.Admin
2001The policy and server configuration settings for the RD Gateway server "%1" have …Admin
2002The policy and server configuration settings for the RD Gateway server "%1" …Admin
2003The policy and server configuration settings for the RD Gateway server "%1" have …Admin
2004The policy and server configuration settings for the RD Gateway server "%1" …Admin
3000The RD Gateway server certificate was changed.Admin
3001The RD Gateway server certificate cannot be changed.Admin
4001The Windows Firewall exception to allow network traffic comprising of Remote …Admin
4002The Windows Firewall exception to allow network traffic comprising of Remote …Admin
4003The Windows Firewall exception to allow network traffic comprising of Remote …Admin
4004The Windows Firewall exception to allow network traffic comprising of Remote …Admin

Event ID 100 — The RD Gateway service could not be initialized.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The RD Gateway service could not be initialized. The following error occurred: "%2". To diagnose possible causes for this problem, verify whether the following services are installed and started: (1) World Wide Web Publishing Service (2) Internet Authentication Service (IAS) (3) RPC/HTTP Load Balancing Service. Also, check Event Viewer for Network Policy Server (NPS) and IIS events that might indicate problems with NPS or IIS. Also, check whether HTTP and UDP transport IP address, port pair is in use.

Event ID 101 — The RD Gateway service has started.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The RD Gateway service has started.

Message #

The RD Gateway service has started.

Event ID 102 — The Remote Desktop Gateway service requires a valid Secure Sockets Layer (SSL) certificate to accept connections.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The Remote Desktop Gateway service requires a valid Secure Sockets Layer (SSL) certificate to accept connections. Ensure that you have obtained a valid SSL certificate, and then bind (map) the certificate by using RD Gateway Manager. For more information, see "Obtain a certificate for the RD Gateway server" in the RD Gateway Help. The following error occurred: "%2"

Event ID 103 — The Remote Desktop Gateway service does not have sufficient permissions to access the Secure Sockets Layer (SSL) certificate that is required to ac...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The Remote Desktop Gateway service does not have sufficient permissions to access the Secure Sockets Layer (SSL) certificate that is required to accept connections. To resolve this issue, bind (map) a valid SSL certificate by using RD Gateway Manager. For more information, see "Obtain a certificate for the RD Gateway server" in the RD Gateway Help. The following error occurred: "%2".

Event ID 104 — The UDP Proxy is started.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The UDP Proxy is started.

Message #

The UDP Proxy is started.

Event ID 105 — The UDP Proxy is shutting down.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The UDP Proxy is shutting down.

Message #

The UDP Proxy is shutting down.

Event ID 106 — The UDP Proxy is not enabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The UDP Proxy is not enabled.

Message #

The UDP Proxy is not enabled.

Event ID 200 — The user "EventInfo.Username", on client computer "EventInfo.IpAddress", met connection authorization policy requirements and was therefore authorized to access the RD Gateway server.

#
Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational
Level
Informational

Message #

The user "%1", on client computer "%2", met connection authorization policy requirements and was therefore authorized to access the RD Gateway server. The authentication method used was: "%3" and connection protocol used: "%5".

Fields #

NameDescription
EventInfo.Username
EventInfo.IpAddress
EventInfo.AuthType
EventInfo.Resource
EventInfo.ConnectionProtocol
EventInfo.ErrorCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 200,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 30,
    "keywords": 4620693217698906112,
    "time_created": "2024-11-04T13:59:32.400587+00:00",
    "event_record_id": 87,
    "correlation": {
      "ActivityID": "7CF86876-882F-0625-F153-3DEC514DA0B2"
    },
    "execution": {
      "process_id": 1444,
      "thread_id": 2256
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "EC2AMAZ-6C3C9U6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Username": "EC2AMAZ-6C3C9U6\\Administrator",
      "IpAddress": "198.51.100.1",
      "AuthType": "NTLM",
      "Resource": "",
      "ConnectionProtocol": "HTTP",
      "ErrorCode": 0
    }
  },
  "message": ""
}

References #

Event ID 201 — The user "%1", on client computer "%2", did not meet connection authorization policy requirements and was therefore not authorized to access the RD...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The user "%1", on client computer "%2", did not meet connection authorization policy requirements and was therefore not authorized to access the RD Gateway server. The authentication method used was: "%3" and connection protocol used: "%5". The following error occurred: "%6".

Event ID 202 — The administrator disconnected the user "%1", on client computer "%2", from the following network resource: "%4".

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The administrator disconnected the user "%1", on client computer "%2", from the following network resource: "%4". Before the user was disconnected, the client transferred %6 bytes and received %5 bytes using %8 connection protocol. The client session duration was %7 seconds.

Event ID 203 — The number of simultaneous connections to the RD Gateway server has reached the maximum number that was configured by the administrator.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The number of simultaneous connections to the RD Gateway server has reached the maximum number that was configured by the administrator. The server is therefore not accepting any new connections. The connection attempt by user "%1" on client computer "%2", using the authentication method "%3" has been denied. For information about how to modify the maximum connection limit, see the "Specify the Maximum Number of Allowable Connections for RD Gateway" topic in the RD Gateway Help.

Event ID 204 — The user "%1", on client computer "%2", did not meet the requirements of the Network Access Protection (NAP) policies defined in the Network Policy...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The user "%1", on client computer "%2", did not meet the requirements of the Network Access Protection (NAP) policies defined in the Network Policy Server. Therefore, the user was not authorized to connect to the RD Gateway server. The authentication method attempted: "%3" and connection protocol used "%5". The following error occurred: "%6".

Event ID 205 — The user "%1", on client computer "%2", successfully connected to the remote server "%4" using UDP proxy.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The user "%1", on client computer "%2", successfully connected to the remote server "%4" using UDP proxy. The authentication method used was: "%3".

Message #

The user "%1", on client computer "%2", successfully connected to the remote server "%4" using UDP proxy. The authentication method used was: "%3".

Event ID 206 — The user "%1", on client computer "%2", failed connection to the remote server "%4" using UDP proxy.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The user "%1", on client computer "%2", failed connection to the remote server "%4" using UDP proxy. The following error occurred : "%9".

Message #

The user "%1", on client computer "%2", failed connection to the remote server "%4" using UDP proxy. The following error occurred : "%9".

Event ID 207 — The administrator disconnected the user "%1", on client computer "%2", from the following network resource: "%4".

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The administrator disconnected the user "%1", on client computer "%2", from the following network resource: "%4". Before the user was disconnected, the client transferred %6 bytes and received %5 bytes. The client session duration was %7 seconds.

Event ID 208 — The UDP Proxy disconnected the user "%1" on client computer "%2", from the following network resource: "%4" because it was unresponsive.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The UDP Proxy disconnected the user "%1" on client computer "%2", from the following network resource: "%4" because it was unresponsive. Before the user was disconnected, the client transferred %6 bytes and received %5 bytes. The client session duration was %7 seconds.

Event ID 209 — The RD Gateway client supports HTTP proxy protocol but connected using Legacy RPC-HTTP.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The RD Gateway client supports HTTP proxy protocol but connected using Legacy RPC-HTTP.

Message #

The RD Gateway client supports HTTP proxy protocol but connected using Legacy RPC-HTTP.

Event ID 210 — Http transport: IN channel could not find a corresponding OUT channel

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

Http transport: IN channel could not find a corresponding OUT channel.

Message #

Http transport: IN channel could not find a corresponding OUT channel

Event ID 300 — The user "EventInfo.Username", on client computer "EventInfo.IpAddress", met resource authorization policy requirements and was therefore authorized to connect to resource "EventInfo.Resource".

#
Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational
Level
Informational

Description

The user "EventInfo.Username", on client computer "EventInfo.IpAddress", met resource authorization policy requirements and was therefore authorized to connect to resource "EventInfo.Resource".

Message #

The user "%1", on client computer "%2", met resource authorization policy requirements and was therefore authorized to connect to resource "%4".

Fields #

NameDescription
EventInfo.Username
EventInfo.IpAddress
EventInfo.AuthType
EventInfo.Resource
EventInfo.ConnectionProtocol
EventInfo.ErrorCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 300,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 30,
    "keywords": 4620693217698906112,
    "time_created": "2024-11-04T13:59:32.621299+00:00",
    "event_record_id": 88,
    "correlation": {
      "ActivityID": "7CF86876-882F-0625-F153-3DEC514DA0B2"
    },
    "execution": {
      "process_id": 1444,
      "thread_id": 2556
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "EC2AMAZ-6C3C9U6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Username": "EC2AMAZ-6C3C9U6\\Administrator",
      "IpAddress": "198.51.100.1",
      "AuthType": "",
      "Resource": "ec2-18-179-8-103.ap-northeast-1.compute.amazonaws.com",
      "ConnectionProtocol": "",
      "ErrorCode": 0
    }
  },
  "message": ""
}

References #

Event ID 301 — The user "%1", on client computer "%2", did not meet resource authorization policy requirements and was therefore not authorized to resource "%4".

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The user "%1", on client computer "%2", did not meet resource authorization policy requirements and was therefore not authorized to resource "%4". The following error occurred: "%6".

Message #

The user "%1", on client computer "%2", did not meet resource authorization policy requirements and was therefore not authorized to resource "%4". The following error occurred: "%6".

Event ID 302 — The user "EventInfo.Username", on client computer "EventInfo.IpAddress", connected to resource "EventInfo.Resource".

#
Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational
Level
Informational

Description

The user "EventInfo.Username", on client computer "EventInfo.IpAddress", connected to resource "EventInfo.Resource". Connection protocol used: "EventInfo.ConnectionProtocol".

Message #

The user "%1", on client computer "%2", connected to resource "%4". Connection protocol used: "%5".

Fields #

NameDescription
EventInfo.Username
EventInfo.IpAddress
EventInfo.AuthType
EventInfo.Resource
EventInfo.ConnectionProtocol
EventInfo.ErrorCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 302,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 30,
    "keywords": 4611686018444165120,
    "time_created": "2024-11-04T13:59:32.624374+00:00",
    "event_record_id": 89,
    "correlation": {
      "ActivityID": "7CF86876-882F-0625-F153-3DEC514DA0B2"
    },
    "execution": {
      "process_id": 1444,
      "thread_id": 2556
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "EC2AMAZ-6C3C9U6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Username": "EC2AMAZ-6C3C9U6\\Administrator",
      "IpAddress": "198.51.100.1",
      "AuthType": "",
      "Resource": "ec2-18-179-8-103.ap-northeast-1.compute.amazonaws.com",
      "ConnectionProtocol": "HTTP",
      "ErrorCode": 0
    }
  },
  "message": ""
}

References #

Event ID 303 — The user "EventInfo.Username", on client computer "EventInfo.IpAddress", disconnected from the following network resource: "EventInfo.Resource".

#
Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational
Level
Informational

Message #

The user "%1", on client computer "%2", disconnected from the following network resource: "%4". Before the user disconnected, the client transferred %6 bytes and received %5 bytes. The client session duration was %7 seconds. Connection protocol used: "%8".

Fields #

NameDescription
EventInfo.Username
EventInfo.IpAddress
EventInfo.AuthType
EventInfo.Resource
EventInfo.BytesReceived
EventInfo.BytesTransfered
EventInfo.SessionDuration
EventInfo.ConnectionProtocol
EventInfo.ErrorCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 303,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 44,
    "keywords": 4611686018444165120,
    "time_created": "2024-11-04T13:59:25.431624+00:00",
    "event_record_id": 84,
    "correlation": {
      "ActivityID": "D993DEC4-0E8C-5014-E2B6-F10CDDA2250E"
    },
    "execution": {
      "process_id": 1444,
      "thread_id": 2256
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "EC2AMAZ-6C3C9U6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Username": "EC2AMAZ-6C3C9U6\\Administrator",
      "IpAddress": "198.51.100.1",
      "AuthType": "",
      "Resource": "ec2-18-179-8-103.ap-northeast-1.compute.amazonaws.com",
      "BytesReceived": "391624",
      "BytesTransfered": "241242",
      "SessionDuration": "57",
      "ConnectionProtocol": "HTTP",
      "ErrorCode": 1226
    }
  },
  "message": ""
}

References #

Event ID 304 — The user "%1", on client computer "%2", met connection authorization policy and resource authorization policy requirements, but could not connect t...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The user "%1", on client computer "%2", met connection authorization policy and resource authorization policy requirements, but could not connect to resource "%4". Connection protocol used: "%5". The following error occurred: "%6".

Event ID 305 — The user "%1", on client computer "%2", was not authorized to connect to this RD Gateway server because the authentication method attempted by the ...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The user "%1", on client computer "%2", was not authorized to connect to this RD Gateway server because the authentication method attempted by the user is not supported. The following authentication method was attempted. "%3". The following error occurred: "%6".

Event ID 306 — The user "%1", on client computer "%2", was not authorized to connect to the RD Gateway server because a tunnel could not be created.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The user "%1", on client computer "%2", was not authorized to connect to the RD Gateway server because a tunnel could not be created. The authentication method attempted: "%3" and connection protocol "%5". The following error occurred: "%6".

Event ID 307 — The user "%1", on client computer "%2", disconnected from the following network resource: "%3" because the session exceeded the session timeout lim...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The user "%1", on client computer "%2", disconnected from the following network resource: "%3" because the session exceeded the session timeout limit of "%4" minutes.

Message #

The user "%1", on client computer "%2", disconnected from the following network resource: "%3" because the session exceeded the session timeout limit of "%4" minutes.
At the time the user was disconnected:
Client transferred: %5 bytes
 Client received:%6 bytes
 Client session duration: %7 seconds
The user can try reconnecting again to the network resource.

Event ID 308 — The user "%1", on client computer "%2", met RD resource authorization policy (RD RAP) requirements but the network resource "%5" did not meet the r...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The user "%1", on client computer "%2", met RD resource authorization policy (RD RAP) requirements but the network resource "%5" did not meet the requirements, so the connection was not authorized. Try connection to another network resource or possibly lower RD Gateway security by modifying the RD RAP requirements for the connection to be authorized.

Event ID 309 — The user "%1", on client computer "%2", was disconnected from the following network resource: "%4" because of a failure during reauthentication/rea...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The user "%1", on client computer "%2", was disconnected from the following network resource: "%4" because of a failure during reauthentication/reauthorization.

Message #

The user "%1", on client computer "%2", was disconnected from the following network resource: "%4" because of a failure during reauthentication/reauthorization.
At the time the user was disconnected:
Client transferred: %6 bytes
Client received: %5 bytes
Client session duration: %7 seconds
The user can try reconnecting again to the resource by using a valid username and password.

Event ID 310 — The user "%1", connected by using client computer "%2" and "%8" connection protocol to the network resource "%3" was successfully reauthenticated/r...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The user "%1",  connected by using client computer "%2" and "%8" connection protocol to the network resource "%3" was successfully reauthenticated/reauthorized after a session timeout of %4 minutes. No user action is required.

Event ID 311 — The user "%1", on client computer "%2", did not connect to the following network resource: "%4" because the remote computer does not support secure...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The user "%1", on client computer "%2", did not connect to the following network resource: "%4" because the remote computer does not support secure device redirection. Try selecting another network resource or possibly lower RD Gateway security by modifying RD CAP to allow client connections to resources that do not enforce device redirection.

Event ID 312 — The user "EventInfo.Username", on client computer "EventInfo.IpAddress", has initiated an outbound connection.

#
Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The user "EventInfo.Username", on client computer "EventInfo.IpAddress", has initiated an outbound connection. This connection may not be authenticated yet.

Message #

The user "%1", on client computer "%2", has initiated an outbound connection. This connection may not be authenticated yet.

Fields #

NameDescription
EventInfo.Username
EventInfo.IpAddress

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 312,
    "version": 0,
    "level": 0,
    "task": 3,
    "opcode": 30,
    "keywords": 4611686018427387904,
    "time_created": "2024-11-04T13:59:31.379210+00:00",
    "event_record_id": 86,
    "correlation": {
      "ActivityID": "7CF86876-882F-0625-F153-3DEC514DA0B2"
    },
    "execution": {
      "process_id": 1444,
      "thread_id": 2256
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "EC2AMAZ-6C3C9U6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Username": "Administrator",
      "IpAddress": "198.51.100.1:63920"
    }
  },
  "message": ""
}

References #

Event ID 313 — The user "%1", on client computer "%2", has initiated an inbound connection.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The user "%1", on client computer "%2", has initiated an inbound connection. This connection may not be authenticated yet.

Message #

The user "%1", on client computer "%2", has initiated an inbound connection. This connection may not be authenticated yet.

Event ID 400 — The RD Gateway service is shutting down.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Message #

The RD Gateway service is shutting down. This maybe voluntary administrator restart or a configuration driven restart due to RDG server certificate change. If the RD Gateway shutdown was not expected, kindly verify whether the following services are started: (1) Network Policy Server; (2) Remote Procedure Call (RPC); (3) RPC/HTTP Load Balancing Service;  and (4) World Wide Web Publishing Service. Also, check Event Viewer for Network Policy Server (NPS) and IIS events that might indicate problems with NPS or IIS.

Event ID 401 — The RD Gateway service successfully registered with the Service Connection Point.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The RD Gateway service successfully registered with the Service Connection Point. No user action is required.

Message #

The RD Gateway service successfully registered with the Service Connection Point. No user action is required.

Event ID 402 — The RD Gateway service failed to register with the Service Connection Point.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The RD Gateway service failed to register with the Service Connection Point.

Message #

The RD Gateway service failed to register with the Service Connection Point.

Event ID 403 — The RD Gateway service successfully unregistered with the Service Connection Point.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The RD Gateway service successfully unregistered with the Service Connection Point. No user action is required.

Message #

The RD Gateway service successfully unregistered with the Service Connection Point. No user action is required.

Event ID 404 — The RD Gateway service failed to unregister with the Service Connection Point.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The RD Gateway service failed to unregister with the Service Connection Point.

Message #

The RD Gateway service failed to unregister with the Service Connection Point.

Event ID 504 — Logging was enabled for the following RD Gateway event: "%1".

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

Logging was enabled for the following RD Gateway event: "%1".

Message #

Logging was enabled for the following RD Gateway event: "%1".

Event ID 505 — Logging could not be enabled for the following RD Gateway event: "%1".

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

Logging could not be enabled for the following RD Gateway event: "%1". The following error occurred: "%2". To resolve this issue, ensure that the correct permissions have been granted to the LogEvents registry key and that the Remote Registry service is started.

Event ID 506 — Logging was disabled for the following RD Gateway event: "%1".

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

Logging was disabled for the following RD Gateway event: "%1".

Message #

Logging was disabled for the following RD Gateway event: "%1".

Event ID 507 — Logging could not be disabled for the following RD Gateway event: "%1".

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

Logging could not be disabled for the following RD Gateway event: "%1". The following error occurred: "%2". To resolve this issue, ensure that the correct permissions have been granted to the LogEvents registry key and that the Remote Registry service is started.

Event ID 508 — The value for the maximum number of connections allowed to the RD Gateway server was updated.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The value for the maximum number of connections allowed to the RD Gateway server was updated.

Message #

The value for the maximum number of connections allowed to the RD Gateway server was updated.

Event ID 509 — The value for the maximum number of simultaneous connections allowed to the RD Gateway server could not be updated.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The value for the maximum number of simultaneous connections allowed to the RD Gateway server could not be updated. The following error occurred: "%2".

Message #

The value for the maximum number of simultaneous connections allowed to the RD Gateway server could not be updated. The following error occurred: "%2".

Event ID 510 — The central connection authorization policy was enabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The central connection authorization policy was enabled.

Message #

The central connection authorization policy was enabled.

Event ID 511 — The central connection authorization policy store could not be enabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The central connection authorization policy store could not be enabled. The following error occurred: "%2". To resolve this issue, ensure that you have typed the name of the Network Policy Server (NPS) correctly and that the NPS exists on the network, and then try again. If the problem persists, then identify and resolve any network connectivity issues.

Event ID 512 — The central connection authorization policy was disabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The central connection authorization policy was disabled.

Message #

The central connection authorization policy was disabled.

Event ID 513 — The central connection authorization policy store could not be disabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The central connection authorization policy store could not be disabled. The following error occurred: "%2".

Message #

The central connection authorization policy store could not be disabled. The following error occurred: "%2".

Event ID 514 — The 'Request clients to send a statement of health' (SoH) setting is enabled on this RD Gateway server.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The 'Request clients to send a statement of health' (SoH) setting is enabled on this RD Gateway server. Therefore; each time a client attempts to connect to this RD Gateway server; the client’s SoH will be requested.

Event ID 515 — The 'Request clients to send a statement of health' (SoH) setting could not be enabled on this RD Gateway server.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The 'Request clients to send a statement of health' (SoH) setting could not be enabled on this RD Gateway server. To resolve this issue; ensure that the QuarantineEnabled registry key exists and that the System and Administrators groups are granted Full Control permissions to this key. The following error occurred: '{name}'.

Fields #

NameDescription
name

Event ID 516 — The 'Request clients to send a statement of health' (SoH) setting is not enabled on this RD Gateway server.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The 'Request clients to send a statement of health' (SoH) setting is not enabled on this RD Gateway server. Therefore; the client’s SoH will not be requested when the client attempts to connect to this RD Gateway server.

Event ID 517 — The 'Request clients to send a statement of health' (SoH) setting could not be disabled on this RD Gateway server.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The 'Request clients to send a statement of health' (SoH) setting could not be disabled on this RD Gateway server. To resolve this issue; ensure that the QuarantineEnabled registry key exists and that the System and Administrators groups are granted Full Control permissions to this key. The following error occurred: '{name}'.

Fields #

NameDescription
name

Event ID 518 — The 'Request clients to send a statement of health' (SoH) setting could not be enabled on this RD Gateway server.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The 'Request clients to send a statement of health' (SoH) setting could not be enabled on this RD Gateway server. This setting could not be enabled because the public key of the server certificate that is bound (mapped) to the Remote Desktop Gateway service contains an object identifier (also known as OID) of 2.5.29.15; but does not support the Extended Key Usage (EKU) for encryption. To resolve this issue; if the certificate that you plan to use contains an OID of 2.5.29.15; you must ensure that one of the following key usage values for this certificate is also set: (1) CERT_KEY_ENCIPHERMENT_KEY_USAGE (2) CERT_KEY_AGREEMENT_KEY_USAGE (3) CERT_DATA_ENCIPHERMENT_KEY_USAGE. Bind (map) the certificate again by using RD Gateway Manager; and then attempt to enable the 'Request clients to send a statement of health' setting again. For more information; see 'Obtain a certificate for the RD Gateway server' in the RD Gateway Help.

Event ID 519 — The server certificate is not valid because the public key of the certificate contains an object identifier (also known as OID) of 2.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The server certificate is not valid because the public key of the certificate contains an object identifier (also known as OID) of 2.5.29.15, but does not support the Extended Key Usage (EKU) for encryption. For the "Request clients to send a statement of health" setting that is enabled on this RD Gateway server to function, if the certificate that you plan to use contains an OID of 2.5.29.15, you must ensure that one of the following key usage values for this certificate is also set: (1) CERT_KEY_ENCIPHERMENT_KEY_USAGE (2) CERT_KEY_AGREEMENT_KEY_USAGE (3) CERT_DATA_ENCIPHERMENT_KEY_USAGE. For more information, see "Obtain a certificate for the RD Gateway server" in the RD Gateway Help.

Event ID 520 — The connection authorization policy "%1" was created.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The connection authorization policy "%1" was created.

Message #

The connection authorization policy "%1" was created.

Event ID 521 — The connection authorization policy "%1" was deleted.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The connection authorization policy "%1" was deleted.

Message #

The connection authorization policy "%1" was deleted.

Event ID 522 — The connection authorization policy "%1" was updated.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The connection authorization policy "%1" was updated.

Message #

The connection authorization policy "%1" was updated.

Event ID 523 — The connection authorization policy "%1" could not be created.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The connection authorization policy "%1" could not be created. The following error occurred: "%2".

Message #

The connection authorization policy "%1" could not be created. The following error occurred: "%2".

Event ID 524 — The connection authorization policy "%1" could not be deleted.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The connection authorization policy "%1" could not be deleted. The following error occurred: "%2".

Message #

The connection authorization policy "%1" could not be deleted. The following error occurred: "%2".

Event ID 525 — The connection authorization policy "%1" could not be updated.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The connection authorization policy "%1" could not be updated. The following error occurred: "%2".

Message #

The connection authorization policy "%1" could not be updated. The following error occurred: "%2".

Event ID 526 — The system message was not enabled because a failure occurred.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The system message was not enabled because a failure occurred. Try enabling the system message again.

Message #

The system message was not enabled because a failure occurred. Try enabling the system message again.

Event ID 527 — The system message was successfully enabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The system message was successfully enabled. No user action is required.

Message #

The system message was successfully enabled. No user action is required.

Event ID 528 — The system message was not disabled because a failure occurred.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The system message was not disabled because a failure occurred. Try removing the system message again.

Message #

The system message was not disabled because a failure occurred. Try removing the system message again.

Event ID 529 — The system message was successfully disabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The system message was successfully disabled. No user action is required.

Message #

The system message was successfully disabled. No user action is required.

Event ID 530 — The logon message was not enabled because a failure occurred.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The logon message was not enabled because a failure occurred. Try enabling the logon message again.

Message #

The logon message was not enabled because a failure occurred. Try enabling the logon message again.

Event ID 531 — The logon message was successfully enabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The logon message was successfully enabled. No user action is required.

Message #

The logon message was successfully enabled. No user action is required.

Event ID 532 — The current logon message was not disabled because a failure occurred.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The current logon message was not disabled because a failure occurred. Try disabling the logon message again.

Message #

The current logon message was not disabled because a failure occurred. Try disabling the logon message again.

Event ID 533 — The current logon message was successfully disabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The current logon message was successfully disabled. No user action is required.

Message #

The current logon message was successfully disabled. No user action is required.

Event ID 540 — The resource authorization policy "%1" was created.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The resource authorization policy "%1" was created.

Message #

The resource authorization policy "%1" was created.

Event ID 541 — The resource authorization policy "%1" was deleted.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The resource authorization policy "%1" was deleted.

Message #

The resource authorization policy "%1" was deleted.

Event ID 542 — The resource authorization policy "%1" was updated.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The resource authorization policy "%1" was updated.

Message #

The resource authorization policy "%1" was updated.

Event ID 543 — The resource authorization policy (RAP) "%1" could not be created.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The resource authorization policy (RAP) "%1" could not be created. The following error occurred: "%2". To resolve this issue, ensure that you have configured RAP settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 544 — The resource authorization policy (RAP) "%1" could not be deleted.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The resource authorization policy (RAP) "%1" could not be deleted. The following error occurred: "%2". To resolve this issue, ensure that you have configured RAP settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 545 — The resource authorization policy (RAP) "%1" could not be updated.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The resource authorization policy (RAP) "%1" could not be updated. The following error occurred: "%2". To resolve this issue, ensure that you have configured RAP settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 560 — The resource group "%1" was created.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The resource group "%1" was created.

Message #

The resource group "%1" was created.

Event ID 561 — The resource group "%1" was deleted.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The resource group "%1" was deleted.

Message #

The resource group "%1" was deleted.

Event ID 562 — The resource group "%1" was updated.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The resource group "%1" was updated.

Message #

The resource group "%1" was updated.

Event ID 563 — The resource group "%1" could not be created.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The resource group "%1" could not be created. The following error occurred: "%2". To resolve this issue, ensure that you have configured resource group settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 564 — The resource group "%1" could not be deleted.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The resource group "%1" could not be deleted. The following error occurred: "%2". To resolve this issue, ensure that you have configured resource group settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 565 — The resource group "%1" could not be updated.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The resource group "%1" could not be updated. The following error occurred: "%2". To resolve this issue, ensure that you have configured resource group settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 580 — The Network Policy Server (NPS) "%1" was added to the central connection authorization policy.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The Network Policy Server (NPS) "%1" was added to the central connection authorization policy.

Message #

The Network Policy Server (NPS) "%1" was added to the central connection authorization policy.

Event ID 581 — The Network Policy Server (NPS) "%1" was deleted from the central connection authorization policy.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The Network Policy Server (NPS) "%1" was deleted from the central connection authorization policy.

Message #

The Network Policy Server (NPS) "%1" was deleted from the central connection authorization policy.

Event ID 582 — The central connection authorization policy settings for the Network Policy Server (NPS) "%1" have been updated.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The central connection authorization policy settings for the Network Policy Server (NPS) "%1" have been updated.

Message #

The central connection authorization policy settings for the Network Policy Server (NPS) "%1" have been updated.

Event ID 583 — The Network Policy Server (NPS) "%1" could not be added to the central connection authorization policy.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The Network Policy Server (NPS) "%1" could not be added to the central connection authorization policy. The following error occurred: "%2". To resolve this issue, ensure that you have typed the name of the Network Policy Server (NPS) correctly and that the NPS exists on the network, and then try again. If the problem persists, then identify and any resolve network connectivity issues.

Event ID 584 — The Network Policy Server (NPS) "%1" could not be deleted from the central connection authorization policy.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The Network Policy Server (NPS) "%1" could not be deleted from the central connection authorization policy. The following error occurred: "%2".

Message #

The Network Policy Server (NPS) "%1" could not be deleted from the central connection authorization policy. The following error occurred: "%2".

Event ID 585 — The central connection authorization policy settings for the Network Policy Server "%1" could not be updated.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The central connection authorization policy settings for the Network Policy Server "%1" could not be updated. The following error occurred: "%2". To resolve this issue, ensure that you have typed the name of the Network Policy Server (NPS) correctly and that the NPS exists on the network, and then try again. If the problem persists, then identify and resolve any network connectivity issues.

Event ID 600 —

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Tracing

Message #

%1

Event ID 601 — %1, Failed with %2.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Tracing

Description

, Failed with.

Message #

%1, Failed with %2

Event ID 620 — The RD Gateway server "%1" was deleted from the list of servers in the RD Gateway server farm.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The RD Gateway server "%1" was deleted from the list of servers in the RD Gateway server farm.

Message #

The RD Gateway server "%1" was deleted from the list of servers in the RD Gateway server farm.

Event ID 621 — The RD Gateway servers "%1" were added to the RD Gateway managed group.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The RD Gateway servers "%1" were added to the RD Gateway managed group. No user action is required.

Message #

The RD Gateway servers "%1" were added to the RD Gateway managed group. No user action is required.

Event ID 622 — The RD Gateway server "%1" could not be deleted from the list of servers in the RD Gateway server farm.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The RD Gateway server "%1" could not be deleted from the list of servers in the RD Gateway server farm. The following error occurred: "%2".

Message #

The RD Gateway server "%1" could not be deleted from the list of servers in the RD Gateway server farm. The following error occurred: "%2".

Event ID 623 — The RD Gateway servers "%1" could not be added to the Remote Desktop Gateway managed group.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The RD Gateway servers "%1" could not be added to the Remote Desktop Gateway managed group. The following error occurred: "%2".

Message #

The RD Gateway servers "%1" could not be added to the Remote Desktop Gateway managed group. The following error occurred: "%2".

Event ID 624 — The RD Gateway server "%1" is not a member of a domain and therefore cannot be added to the RD Gateway server farm.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The RD Gateway server "%1" is not a member of a domain and therefore cannot be added to the RD Gateway server farm. To add this RD Gateway server to the farm, you must first add the server to a domain.

Event ID 625 — A Windows Firewall exception for RD Gateway has been configured to allow data for Remote Desktop Services client connections and RPC-HTTP load bala...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

A Windows Firewall exception for RD Gateway has been configured to allow data for Remote Desktop Services client connections and RPC-HTTP load balancing to be sent between RD Gateway servers when load balancing is used. This exception is automatically configured when you add the first RD Gateway server to a RD Gateway server farm.

Event ID 626 — The Windows Firewall exception for RD Gateway to allow network traffic comprising of Remote Desktop Services client connections data and RPC-HTTP l...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The Windows Firewall exception for RD Gateway to allow network traffic comprising of Remote Desktop Services client connections data and RPC-HTTP load balancing data (to be sent between RD Gateway servers when load balancing is used) has been disabled. This exception is automatically disabled when you remove all RD Gateway servers from a RD Gateway server farm.

Event ID 627 — The Windows Firewall exception to allow network traffic through TCP port 3388.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The Windows Firewall exception to allow network traffic through TCP port 3388 (so that Remote Desktop Services client connections can be directed to the appropriate RD Gateway servers when load balancing is used) could not be configured.

Event ID 628 — The Windows Firewall exception "RD Gateway Server Farm" that allows network traffic through TCP port 3388.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The Windows Firewall exception "RD Gateway Server Farm" that allows network traffic through TCP port 3388 (so that Remote Desktop Services client connections can be directed to the appropriate Remote Desktop Gateway servers when load balancing is used) could not be disabled. We recommend that you disable this exception manually by modifying Windows Firewall settings as needed.

Event ID 629 — The RD Gateway servers "%1" were set to the RD Gateway managed group.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The RD Gateway servers "%1" were set to the RD Gateway managed group. No user action is required.

Message #

The RD Gateway servers "%1" were set to the RD Gateway managed group. No user action is required.

Event ID 630 — The RD Gateway servers "%1" could not be set to the RD Gateway managed group.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The RD Gateway servers "%1" could not be set to the RD Gateway managed group. The following error occurred: "%2".

Message #

The RD Gateway servers "%1" could not be set to the RD Gateway managed group. The following error occurred: "%2".

Event ID 640 — RD Gateway Network access Policy engine failed to contact IAS and the error was "%2".

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

RD Gateway Network access Policy engine failed to contact IAS and the error was "%2".

Message #

RD Gateway Network access Policy engine failed to contact IAS and the error was "%2"

Event ID 641 — RD Gateway Network access Policy engine received failure from IAS and the error was "%2".

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

RD Gateway Network access Policy engine received failure from IAS and the error was "%2".

Message #

RD Gateway Network access Policy engine received failure from IAS and the error was "%2"

Event ID 642 — The RD Gateway server cannot open the resource authorization policy store on Authorization Manager (Azman).

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

The RD Gateway server cannot open the resource authorization policy store on Authorization Manager (Azman). The following error occurred: "%2".

Message #

The RD Gateway server cannot open the resource authorization policy store on Authorization Manager (Azman). The following error occurred: "%2".

Event ID 643 — RD Gateway Resource access Policy engine failed to open Azman Application(Remote Desktop Gateway) and the error was "%2".

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Operational

Description

RD Gateway Resource access Policy engine failed to open Azman Application(Remote Desktop Gateway) and the error was "%2".

Message #

RD Gateway Resource access Policy engine failed to open Azman Application(Remote Desktop Gateway) and the error was "%2"

Event ID 700 — The following exception code "%2" occured in the RD Gateway server.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The following exception code "%2" occured in the RD Gateway server. The RD Gateway will be restarted. No user action is required.

Message #

The following exception code "%2" occured in the RD Gateway server. The RD Gateway will be restarted. No user action is required.

Event ID 701 — The exception code "%2" occurred in the authentication plug-in: "%1" loaded by the RD Gateway server.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The exception code "%2" occurred in the authentication plug-in: "%1" loaded by the RD Gateway server. The RD Gateway server will be restarted. Continued failures might indicate a problem with the authentication plug-in.

Event ID 702 — The exception code "%2" occurred in the authorization plug-in: "%1" loaded by the RD Gateway server.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The exception code "%2" occurred in the authorization plug-in: "%1" loaded by the RD Gateway server. The RD Gateway server will be restarted. Continued failures might indicate a problem with the authorization plug-in.

Event ID 1001 — The Remote Desktop Gateway service cannot determine the version of Windows that this computer is running.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The Remote Desktop Gateway service cannot determine the version of Windows that this computer is running. Therefore, users cannot connect to this RD Gateway server. To resolve this issue, please contact Microsoft Product Support Services. The following error occurred: "%2".

Event ID 1002 — The user authentication plug-in "%1" has been configured.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The user authentication plug-in "%1" has been configured. The configuration will take effect after the RD Gateway service is restarted.

Message #

The user authentication plug-in "%1" has been configured. The configuration will take effect after the RD Gateway service is restarted.

Event ID 1003 — RD Gateway native authentication is configured.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

RD Gateway native authentication is configured. The configuration changes will take effect after the RD Gateway service is restarted.

Message #

RD Gateway native authentication is configured. The configuration changes will take effect after the RD Gateway service is restarted.

Event ID 1004 — The user authorization plug-in "%1" is enabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The user authorization plug-in "%1" is enabled. No user action is required.

Message #

The user authorization plug-in "%1" is enabled. No user action is required.

Event ID 1005 — The RD Gateway native authorization is enabled.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The RD Gateway native authorization is enabled. No user action is required.

Message #

The RD Gateway native authorization is enabled. No user action is required.

Event ID 2001 — The policy and server configuration settings for the RD Gateway server "%1" have been successfully imported.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The policy and server configuration settings for the RD Gateway server "%1" have been successfully imported.

Message #

The policy and server configuration settings for the RD Gateway server "%1" have been successfully imported.

Event ID 2002 — The policy and server configuration settings for the RD Gateway server "%1" could not be imported.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The policy and server configuration settings for the RD Gateway server "%1" could not be imported. This problem might occur if the settings have become corrupted.

Message #

The policy and server configuration settings for the RD Gateway server "%1" could not be imported. This problem might occur if the settings have become corrupted.

Event ID 2003 — The policy and server configuration settings for the RD Gateway server "%1" have been successfully exported.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The policy and server configuration settings for the RD Gateway server "%1" have been successfully exported.

Message #

The policy and server configuration settings for the RD Gateway server "%1" have been successfully exported.

Event ID 2004 — The policy and server configuration settings for the RD Gateway server "%1" could not be exported.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The policy and server configuration settings for the RD Gateway server "%1" could not be exported. The following error occurred: "%2".

Message #

The policy and server configuration settings for the RD Gateway server "%1" could not be exported. The following error occurred: "%2".

Event ID 3000 — The RD Gateway server certificate was changed.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The RD Gateway server certificate was changed. No user action is required.

Message #

The RD Gateway server certificate was changed. No user action is required.

Event ID 3001 — The RD Gateway server certificate cannot be changed.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The RD Gateway server certificate cannot be changed. The following error occurred: "%2". Verify the certificate and try changing the certificate again.

Message #

The RD Gateway server certificate cannot be changed. The following error occurred: "%2". Verify the certificate and try changing the certificate again.

Event ID 4001 — The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured (non-default) HTTPS port of the Remote Desktop Gateway has been modified.

Event ID 4002 — The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured.

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Message #

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured (non-default) HTTPS port of Remote Desktop Gateway could not be modified.

Event ID 4003 — The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP po...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP port of the Remote Desktop Gateway has been modified.

Message #

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP port of the Remote Desktop Gateway has been modified.

Event ID 4004 — The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP po...

Provider
Microsoft-Windows-TerminalServices-Gateway
Channel
Admin

Description

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP port of Remote Desktop Gateway could not be modified.

Message #

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP port of Remote Desktop Gateway could not be modified.