Microsoft-Windows-TPM-WMI

51 events across 1 channel

Event IDTitleChannel
513TPM Owner Authorization information was backed up successfully to Active …System
514Failed to backup TPM Owner Authorization information to Active Directory Domain …System
515The Trusted Platform Module (TPM) hardware on this computer has failed to set …System
516Successfully sent physical presence request to clear the Trusted Platform …System
517Failed to send physical presence request to clear the Trusted Platform …System
518Failed to get isOwned status from Trusted Platform Module(TPM), proceeding to …System
519The TPM has been cleared.System
769TPM Owner Authorization configuration changed from '.System
1025The TPM was successfully provisioned and is now ready for use.System
1026The Trusted Platform Module (TPM) hardware on this computer cannot be …System
1027The Ownership of the Trusted Platform Module (TPM) hardware on this computer was …System
1028The NGC key generation task was successfully triggered.System
1029The triggering of the NGC key generation task failed.System
1030The NGC certificate enrollment task was successfully triggered.System
1031The triggering of the NGC certificate enrollment task failed.System
1032The Secure Boot update was not applied due to a known incompatibility with the …System
1033Potentially revoked boot manager was detected in EFI partition.System
1034Secure Boot Dbx update applied successfullySystem
1035Secure Boot Dbx update applied successfullySystem
1036Secure Boot Db update applied successfullySystem
1037Secure Boot Dbx update to revoke Microsoft Windows Production PCA 2011 is …System
1038Pre-attestation health checks confirm that the device is expected to pass …System
1039Pre-attestation health checks confirm that the device meets most attestation …System
1040Pre-attestation health checks confirm a critical component has failed, and the …System
1041Pre-attestation health check detailed information.System
1042Secure Boot Dbx update to revoke older Boot Manager SVNs is applied successfullySystem
1043Secure Boot KEK update applied successfullySystem
1044Secure Boot DB update to install Microsoft Option ROM UEFI CA 2023 certificate …System
1045Secure Boot DB update to install Microsoft UEFI CA 2023 certificate applied …System
1046Measured boot files deleted successfully.System
1047Measured boot file %1 was not deleted successfully due to error %2.System
1281This event triggers the TBS device identifier generation.System
1282The TBS device identifier has been generated.System
1283EK Certificate tool started.System
1284EK Certificate tool succeeded in %1 milliseconds.System
1285EK Certificate tool failed in %1 milliseconds with error %2.System
1537The Device Health Certificate was successfully provisioned from %1.System
1538The Device Health Certificate provisioning could not connect to %1.System
1539The Device Health Certificate could not be provisioned from %1.System
1793The Trusted Platform Module (TPM) hardware on this computer is scheduled to be …System
1794The Trusted Platform Module (TPM) firmware on this PC has a known security …System
1795The system firmware returned an error %1 when attempting to update a Secure Boot …System
1796The Secure Boot update failed to update a Secure Boot variable with error %1.System
1797The Secure Boot Dbx update failed to revoke Microsoft Windows Production PCA …System
1798The Secure Boot Dbx update failed as boot manager is not signed with the Windows …System
1799Boot Manager signed with Windows UEFI CA 2023 was installed successfullySystem
1800A reboot is required before installing the update.System
1801Secure Boot certificates have been updated but are not yet applied to the device …System
1802The Secure Boot update %1 was blocked due to a known firmware issue on the …System
1803A PK-signed Key Exchange Key (KEK) cannot be found for this device.System
1808This device has updated Secure Boot CA/keys.System

Event ID 513 — TPM Owner Authorization information was backed up successfully to Active Directory Domain Services.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

TPM Owner Authorization information was backed up successfully to Active Directory Domain Services.

Event ID 514 — Failed to backup TPM Owner Authorization information to Active Directory Domain Services.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Failed to backup TPM Owner Authorization information to Active Directory Domain Services.
Errorcode: %1
Check that your computer is connected to the domain.  If your computer is connected to the domain, have your Domain Administrator check that the Active Directory schema is appropriate for backup of Windows 8 TPM Owner Authorization information and that the current Computer object has write permission to the TPM object.  Installations of Windows Server 2008 R2 or before need a schema extension in order to be ready for backup of Windows 8 TPM Owner Authorization information.  Consult online documentation for more information about setting up Active Directory Domain Services for TPM.

Fields

NameDescription
ErrorCode

Event ID 515 — The Trusted Platform Module (TPM) hardware on this computer has failed to set its Dictionary Attack Parameters to legacy mode.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Trusted Platform Module (TPM) hardware on this computer has failed to set its Dictionary Attack Parameters to legacy mode.

Event ID 516 — Successfully sent physical presence request to clear the Trusted Platform Module(TPM).

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Successfully sent physical presence request to clear the Trusted Platform Module(TPM).

Event ID 517 — Failed to send physical presence request to clear the Trusted Platform Module(TPM).

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Failed to send physical presence request to clear the Trusted Platform Module(TPM).

Fields

NameDescription
HResult

Event ID 518 — Failed to get isOwned status from Trusted Platform Module(TPM), proceeding to clear TPM assuming that TPM is owned.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Failed to get isOwned status from Trusted Platform Module(TPM), proceeding to clear TPM assuming that TPM is owned. Error code:%1

Fields

NameDescription
HResult

Event ID 519 — The TPM has been cleared.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The TPM has been cleared. Reason: %1.

Fields

NameDescription
ClearReason

Event ID 769 — TPM Owner Authorization configuration changed from '.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

TPM Owner Authorization configuration changed from '%1' to '%2'.

Fields

NameDescription
OldOSManagedAuthLevel
NewOSManagedAuthLevel

Event ID 1025 — The TPM was successfully provisioned and is now ready for use.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The TPM was successfully provisioned and is now ready for use.

Event ID 1026 — The Trusted Platform Module (TPM) hardware on this computer cannot be provisioned for use automatically.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Trusted Platform Module (TPM) hardware on this computer cannot be provisioned for use automatically.  To set up the TPM interactively use the TPM management console (Start->tpm.msc) and use the action to make the TPM ready.

Error: %1
Additional Information: %2

Fields

NameDescription
ErrorCode
StatusInformation

Event ID 1027 — The Ownership of the Trusted Platform Module (TPM) hardware on this computer was successfully taken (TPM TakeOwnership command) by the system.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Ownership of the Trusted Platform Module (TPM) hardware on this computer was successfully taken (TPM TakeOwnership command) by the system.

Event ID 1028 — The NGC key generation task was successfully triggered.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The NGC key generation task was successfully triggered.

Event ID 1029 — The triggering of the NGC key generation task failed.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The triggering of the NGC key generation task failed.

Fields

NameDescription
ErrorCode

Event ID 1030 — The NGC certificate enrollment task was successfully triggered.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The NGC certificate enrollment task was successfully triggered.

Event ID 1031 — The triggering of the NGC certificate enrollment task failed.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The triggering of the NGC certificate enrollment task failed.

Fields

NameDescription
ErrorCode

Event ID 1032 — The Secure Boot update was not applied due to a known incompatibility with the current BitLocker configuration.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Secure Boot update was not applied due to a known incompatibility with the current BitLocker configuration.

Fields

NameDescription
UpdateType

Event ID 1033 — Potentially revoked boot manager was detected in EFI partition.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Potentially revoked boot manager was detected in EFI partition. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Fields

NameDescription
Path

Event ID 1034 — Secure Boot Dbx update applied successfully

Provider
Microsoft-Windows-TPM-WMI
Channel
System
Level
4
Samples
1

Message

Secure Boot Dbx update applied successfully

Example Event

system:
  provider: Microsoft-Windows-TPM-WMI
  guid: 7D5387B0-CBE0-11DA-A94D-0800200C9A66
  event_source_name: ''
  event_id: 1034
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 9223372036854775808
  time_created: '2023-11-05T22:27:36.527418+00:00'
  event_record_id: 1724
  correlation: {}
  execution:
    process_id: 1092
    thread_id: 956
  channel: System
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 1035 — Secure Boot Dbx update applied successfully

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Secure Boot Dbx update applied successfully

Event ID 1036 — Secure Boot Db update applied successfully

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Secure Boot Db update applied successfully

Event ID 1037 — Secure Boot Dbx update to revoke Microsoft Windows Production PCA 2011 is applied successfully

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Secure Boot Dbx update to revoke Microsoft Windows Production PCA 2011 is applied successfully

Event ID 1038 — Pre-attestation health checks confirm that the device is expected to pass attestation.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Pre-attestation health checks confirm that the device is expected to pass attestation.
 Please see %1 for detailed information on what checks were made.

Fields

NameDescription
Path

Event ID 1039 — Pre-attestation health checks confirm that the device meets most attestation criteria, but failing is still possible.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Pre-attestation health checks confirm that the device meets most attestation criteria, but failing is still possible.
 Please see %1 for detailed information on what checks were made.

Fields

NameDescription
Path

Event ID 1040 — Pre-attestation health checks confirm a critical component has failed, and the device is not expected to pass attestation.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Pre-attestation health checks confirm a critical component has failed, and the device is not expected to pass attestation.
 Please see %1 for detailed information on what checks were made.

Fields

NameDescription
Path

Event ID 1041 — Pre-attestation health check detailed information.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Pre-attestation health check detailed information: %1

Fields

NameDescription
Json

Event ID 1042 — Secure Boot Dbx update to revoke older Boot Manager SVNs is applied successfully

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Secure Boot Dbx update to revoke older Boot Manager SVNs is applied successfully

Event ID 1043 — Secure Boot KEK update applied successfully

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Secure Boot KEK update applied successfully

Event ID 1044 — Secure Boot DB update to install Microsoft Option ROM UEFI CA 2023 certificate applied successfully

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Secure Boot DB update to install Microsoft Option ROM UEFI CA 2023 certificate applied successfully

Event ID 1045 — Secure Boot DB update to install Microsoft UEFI CA 2023 certificate applied successfully

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Secure Boot DB update to install Microsoft UEFI CA 2023 certificate applied successfully

Event ID 1046 — Measured boot files deleted successfully.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Measured boot files deleted successfully. The following %1 files were deleted: %2

Fields

NameDescription
FilesCount
Files

Event ID 1047 — Measured boot file %1 was not deleted successfully due to error %2.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Measured boot file %1 was not deleted successfully due to error %2.

Fields

NameDescription
FileName
ErrorCode

Event ID 1281 — This event triggers the TBS device identifier generation.

Provider
Microsoft-Windows-TPM-WMI
Channel
System
Level
4
Samples
1

Message

This event triggers the TBS device identifier generation.

Example Event

system:
  provider: Microsoft-Windows-TPM-WMI
  guid: 7D5387B0-CBE0-11DA-A94D-0800200C9A66
  event_source_name: ''
  event_id: 1281
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 9223372036854775808
  time_created: '2022-04-07T16:48:26.716878+00:00'
  event_record_id: 346
  correlation: {}
  execution:
    process_id: 4332
    thread_id: 4368
  channel: System
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''

References

Event ID 1282 — The TBS device identifier has been generated.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The TBS device identifier has been generated.

Event ID 1283 — EK Certificate tool started.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

EK Certificate tool started.

Event ID 1284 — EK Certificate tool succeeded in %1 milliseconds.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

EK Certificate tool succeeded in %1 milliseconds.

Fields

NameDescription
Millisecondstaken

Event ID 1285 — EK Certificate tool failed in %1 milliseconds with error %2.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

EK Certificate tool failed in %1 milliseconds with error %2.

Fields

NameDescription
Millisecondstaken
ErrorCode

Event ID 1537 — The Device Health Certificate was successfully provisioned from %1.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Device Health Certificate was successfully provisioned from %1.

Fields

NameDescription
HealthAttestationServer

Event ID 1538 — The Device Health Certificate provisioning could not connect to %1.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Device Health Certificate provisioning could not connect to %1. %2

Fields

NameDescription
HealthAttestationServer
HResult

Event ID 1539 — The Device Health Certificate could not be provisioned from %1.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Device Health Certificate could not be provisioned from %1. HTTP status code %2: %3

Fields

NameDescription
HealthAttestationServer
HTTPStatus
ServerResponse

Event ID 1793 — The Trusted Platform Module (TPM) hardware on this computer is scheduled to be cleared by the system.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Trusted Platform Module (TPM) hardware on this computer is scheduled to be cleared by the system.

Event ID 1794 — The Trusted Platform Module (TPM) firmware on this PC has a known security problem.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Trusted Platform Module (TPM) firmware on this PC has a known security problem. Please contact your PC manufacturer to find out if an update is available. For more information please go to https://go.microsoft.com/fwlink/?linkid=852572

Event ID 1795 — The system firmware returned an error %1 when attempting to update a Secure Boot variable.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The system firmware returned an error %1 when attempting to update a Secure Boot variable. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Fields

NameDescription
HResult
UpdateType
DeviceAttributes
BucketId
BucketConfidenceLevel

Event ID 1796 — The Secure Boot update failed to update a Secure Boot variable with error %1.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Secure Boot update failed to update a Secure Boot variable with error %1. For more information, please see https://go.microsoft.com/fwlink/?linkid=2169931

Fields

NameDescription
UpdateType
HResult

Event ID 1797 — The Secure Boot Dbx update failed to revoke Microsoft Windows Production PCA 2011 as the Windows UEFI CA 2023 certificate is not present in Db

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Secure Boot update failed as the Windows UEFI CA 2023 certificate is not present in Db

Event ID 1798 — The Secure Boot Dbx update failed as boot manager is not signed with the Windows UEFI CA 2023 certificate.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Secure Boot Dbx update failed as boot manager is not signed with the Windows UEFI CA 2023 certificate

Event ID 1799 — Boot Manager signed with Windows UEFI CA 2023 was installed successfully

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Boot Manager signed with Windows UEFI CA 2023 was installed successfully

Event ID 1800 — A reboot is required before installing the update.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

A reboot is required before installing the Secure Boot update. Reason: %1

Fields

NameDescription
UpdateType

Event ID 1801 — Secure Boot certificates have been updated but are not yet applied to the device firmware.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

Secure Boot certificates have been updated but are not yet applied to the device firmware. Review the published guidance to complete the update and ensure full protection. This device signature information is included here.
DeviceAttributes: %1
BucketId: %2
BucketConfidenceLevel: %3
UpdateType: %4
For more information, please see https://go.microsoft.com/fwlink/?linkid=2301018.

Fields

NameDescription
DeviceAttributes
BucketId
BucketConfidenceLevel
UpdateType

Event ID 1802 — The Secure Boot update %1 was blocked due to a known firmware issue on the device.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

The Secure Boot update %1 was blocked due to a known firmware issue on the device. Check with your device vendor for a firmware update that addresses the issue. This device signature information is included here.
DeviceAttributes: %2
BucketId: %3
BucketConfidenceLevel: %4
SkipReason: %5.
For more information, please see https://go.microsoft.com/fwlink/?linkid=2339472

Fields

NameDescription
UpdateType
DeviceAttributes
BucketId
BucketConfidenceLevel
SkipReason

Event ID 1803 — A PK-signed Key Exchange Key (KEK) cannot be found for this device.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

A PK-signed Key Exchange Key (KEK) cannot be found for this device. Check with the device manufacturer for proper key provisioning.
This device signature information is included here.
DeviceAttributes: %1
BucketId: %2
BucketConfidenceLevel: %3.
For more information, please see https://go.microsoft.com/fwlink/?linkid=2339472

Fields

NameDescription
DeviceAttributes
BucketId
BucketConfidenceLevel

Event ID 1808 — This device has updated Secure Boot CA/keys.

Provider
Microsoft-Windows-TPM-WMI
Channel
System

Message

This device has updated Secure Boot CA/keys. This device signature information is included here.
DeviceAttributes: %1
BucketId: %2
BucketConfidenceLevel: %3
UpdateType: %4
For more information, please see https://go.microsoft.com/fwlink/?linkid=2301018.

Fields

NameDescription
DeviceAttributes
BucketId
BucketConfidenceLevel
UpdateType