Microsoft-Windows-Windows Defender › Event 1133

Event ID 1133 — ProductName has blocked an operation that your administrator doesn't allow.

Provider
Microsoft-Windows-Windows Defender
Channel
Operational

Description

ProductName has blocked an operation that your administrator doesn't allow.

Message #

%1 has blocked an operation that your administrator doesn't allow.
For more information please contact your IT administrator.
	Policy Version: %4
	Policy Rule ID: %5
	Enforcement Level: %6
	Timestamp: %8
	Action Type: %9
	Process: %10
	Source: %11
	Target: %12
	Session ID: %13
	User SID: %14
%Security intelligence Version: %15
	Engine Version: %16
	Product Version: %2

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
PolicyVersion UnicodeString
PolicyRuleId UnicodeString
EnforcementLevel UnicodeString
AuditReason UnicodeString
EventTimestamp UnicodeString
ActionType UnicodeString
Process UnicodeString
Source UnicodeString
Target UnicodeString
SessionId UnicodeString
UserSid UnicodeString
SignatureVersion UnicodeString
EngineVersion UnicodeString

References #