AD FS
Event ID 100: The Federation Service started successfully.
#Description
The Federation Service started successfully. The following service hosts have been added.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 100,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:03:54.297871+00:00",
"event_record_id": 34,
"correlation": {},
"execution": {
"process_id": 11528,
"thread_id": 11808
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "Federation Server Proxy ServiceHost\r\nhttps://adfs.ludus.domain:443/adfs/services/proxytrustpolicystoretransfer\r\n\r\nMSIS0014: AD FS 1.x Trust Information Service\r\nhttps://adfs.ludus.domain/adfs/fs/federationserverservice.asmx\r\n\r\nIssuance ServiceHost\r\nhttp://localhost:80/adfs/services/trust/mexsoap\r\nhttps://adfs.ludus.domain:443/adfs/services/trust/proxymex/\r\n\r\nIssuance ServiceHost\r\nhttp://localhost/adfs/services/trust/proxymexsoap\r\nhttps://adfs.ludus.domain:443/adfs/services/trust/proxymex/\r\n\r\nIssuance ServiceHost\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/windowstransport\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/certificatemixed\r\nhttps://certauth.adfs.ludus.domain/adfs/services/trust/2005/certificatetransport\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/usernamemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/kerberosmixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/issuedtokenmixedasymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/issuedtokenmixedsymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/kerberosmixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/certificatemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/usernamemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/issuedtokenmixedasymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/issuedtokenmixedsymmetricbasic256\r\nnet.tcp://localhost/adfs/services/trusttcp/windows\r\n\r\nSAML Metadata\r\nhttps://adfs.ludus.domain/FederationMetadata/2007-06/\r\n\r\nOther endpoints\r\n\r\nhttp://+:80/adfs/users/\r\nhttps://+:443/adfs/oauth2/authorize/\r\nhttps://+:443/adfs/ls/\r\nhttps://+:443/adfs/oauth2/logout/\r\nhttps://+:443/adfs/oauth2/token/\r\nhttps://+:443/adfs/certauth/oauth2/authorize/\r\nhttps://+:443/adfs/certauth/\r\nhttps://+:443/adfs/oauth2/\r\nhttps://+:443/adfs/oauth2/deviceauth/\r\nhttp://+:80/adfs/deviceflowresult/\r\nhttp://+:80/adfs/artifact/\r\nhttps://+:443/adfs/discovery/\r\nhttps://+:443/adfs/.well-known/\r\nhttps://+:443/.well-known/webfinger/\r\nhttps://+:443/adfs/userinfo/\r\nhttps://+:443/adfs/Proxy/EstablishTrust/\r\nhttps://+:443/adfs/backendproxytls/\r\nhttps://+:443/adfs/Proxy/\r\nhttp://+:80/adfs/Proxy/PrimaryWriter/\r\nhttps://+:443/adfs/portal/\r\nhttp://+:80/adfs/probe/\r\n"
}
}
},
"message": ""
}
Event ID 100: The Federation Service started successfully
#Description
The Federation Service started successfully. The following service hosts have been added.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 100,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T15:43:12.3574440+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 102: There was an error in enabling endpoints of Federation Service.
#Description
There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 102,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:11:11.158613+00:00",
"event_record_id": 292,
"correlation": {},
"execution": {
"process_id": 12444,
"thread_id": 11500
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "System.ServiceModel.FaultException`1[Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault]: ADMIN0012: OperationFault (Fault Detail is equal to Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault)."
}
}
},
"message": ""
}
Event ID 102: There was an error in enabling endpoints of Federation Service
#Description
There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 102,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:12:50.2286277+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "System.ServiceModel.FaultException`1[Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault]: ADMIN0012: OperationFault (Fault Detail is equal to Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault)."
}
}
Example keys not documented in the fields table: EventData
Event ID 103: The Federation Service stopped successfully.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 103,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:04:06.374579+00:00",
"event_record_id": 36,
"correlation": {},
"execution": {
"process_id": 11528,
"thread_id": 11808
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 103: The Federation Service stopped successfully
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 103,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T15:32:28.4194277+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 104: The artifact resolution service is not running
#Description
The artifact resolution service is not running. The service must be running to perform token replay detection.
Message #
Event ID 105: An error occurred loading an authentication provider
#Event ID 106: An authentication provider was successfully loaded: Identifier: 'Event.EventData', Context: 'data1'.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 106,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:03:54.076793+00:00",
"event_record_id": 8,
"correlation": {},
"execution": {
"process_id": 11528,
"thread_id": 11808
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"FormsAuthentication",
"Passive protocol pipeline"
]
}
}
},
"message": ""
}
Event ID 106: An authentication provider was successfully loaded: Identifier: 'data1', Context: 'data2'
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 106,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T15:43:12.3403827+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 111: The Federation Service encountered an error while processing the WS-Trust request
#Event ID 131: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.
#Event ID 131: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data
#Description
During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The configured value 'data2' could not be parsed as type 'data3'.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Event ID 132: During processing of the Federation Service configuration, the required element 'data1' was missing
#Event ID 133: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data
#Event ID 134: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data
#Description
During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' could not be found.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString |
Event ID 135: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data
#Description
During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' was not unique.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString |
Event ID 136: During processing of the Federation Service configuration, the Federation Service encountered a configuration error
#Event ID 143: The Federation Service was unable to create the federation metadata document as a result of an error
#Event ID 144: The Federation Service Proxy blocked an illegitimate request made by a client, as there was no matching endpoint registered at the proxy.
#Event ID 144: The Federation Service Proxy blocked an illegitimate request made by a client, as there was no matching endpoint registered at the proxy
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 147: A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any ...
#Event ID 147: A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any known claims provider trust
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 149: During processing of the Federation Service configuration, the attribute store 'Event.EventData' could not be loaded.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 149,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:07:31.694542+00:00",
"event_record_id": 90,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 8576
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"TestLDAPStore",
"Microsoft.IdentityServer.ClaimsPolicy.Engine.AttributeStore.Ldap.LdapAttributeStore, Microsoft.IdentityServer.ClaimsPolicy",
"POLICY3820: The configured connection value 'LDAP://localhost:389' for the 'TestLDAPStore' attribute store is not valid. It must be a valid LDAP:// Uri. Ex:LDAP://fabrikam.com/DC=fabrikam,DC=com"
]
}
}
},
"message": ""
}
Event ID 149: During processing of the Federation Service configuration, the attribute store 'data1' could not be loaded
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 149,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:10:24.1548560+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "TestLDAPStoreMicrosoft.IdentityServer.ClaimsPolicy.Engine.AttributeStore.Ldap.LdapAttributeStore, Microsoft.IdentityServer.ClaimsPolicyPOLICY3820: The configured connection value 'LDAP://localhost:389' for the 'TestLDAPStore' attribute store is not valid. It must be a valid LDAP:// Uri. Ex:LDAP://fabrikam.com/DC=fabrikam,DC=com"
}
}
Example keys not documented in the fields table: EventData
Event ID 155: The Federation Service was unable to listen at 'data1' for metadata document requests due to an unexpected error
#Event ID 156: Trust monitoring cycle initiated.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 156,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.122193+00:00",
"event_record_id": 75,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 11600
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 156: Trust monitoring cycle initiated
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 156,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-05-27T16:14:39.2381040+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 157: Trust monitoring cycle completed.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 157,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.147700+00:00",
"event_record_id": 78,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 11600
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 157: Trust monitoring cycle completed
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 157,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-05-27T16:14:39.2534333+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 159: The Federation Service encountered an error while writing to the following object in the configuration database
#Event ID 163: An error occurred during initialization of trust monitoring
#Event ID 164: An error occurred during a read operation from the configuration database
#Event ID 165: An error occurred during trust monitoring
#Event ID 166: Trust monitoring service encountered an error while parsing the metadata document from 'data1'
#Event ID 167: Trust monitoring service encountered an error while applying the data in the metadata document from 'data1'
#Event ID 168: The Federation Service encountered an error while retrieving the federation metadata document from 'data1'
#Event ID 171: The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes
#Event ID 173: The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes
#Event ID 174: Trust monitoring service detected changes in policy of 'data1', but did not automatically apply the changes on the trust partner
#Event ID 180: An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version 'data2' to Minor Version 'data3'
#Event ID 181: AD FS could not enable the new KDFv2 feature automatically because of missing Windows Updates on one or more nodes of the farm
#Message #
Event ID 182: AD FS enabled the new KDFv2 feature successfully
#Description
AD FS enabled the new KDFv2 feature successfully. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.
Message #
Event ID 184: A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identi...
#Event ID 184: A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identify any known relying party trust
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 186: The Federation Service could not fulfill the token-issuance request
#Event ID 187: AD FS server received a JWT token without nonce in the assertion and it was accepted based on the current configuration setting of EnforceNonceInJWT
#Event ID 188: AD FS server is not configured to reject JWT tokens that did not have nonce in the assertion.
#Message #
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 188,
"level": "Error",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T15:43:12.3532216+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 188: AD FS server is not configured to reject JWT tokens that did not have nonce in the assertion
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 188,
"level": "Error",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T15:43:12.3532216+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 189: AD FS server received an OAuth authorization request in the device code flow without a Cross Site Request Forgery (CSRF) protection code in the Use...
#Event ID 189: AD FS server received an OAuth authorization request in the device code flow without a Cross Site Request Forgery (CSRF) protection code in the UserCode cookie
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Event ID 193: The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type
#Event ID 197: The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of '%...
#Event ID 197: The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'data2' for the relying party 'data3'
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Event ID 198: The federation server proxy started successfully
#Event ID 199: The federation server proxy could not be started
#Event ID 200: The federation server proxy stopped successfully
#Event ID 201: The Federation Service data1 encountered an Access Denied error while trying to register one or more endpoint URLs
#Event ID 202: The Federation Service data1 could not be opened
#Event ID 203: The Federation Service data1 could not be shut down properly
#Event ID 204: The Federation Service data1 could not be closed
#Event ID 206: The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint addr...
#Event ID 206: The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint address
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 207: An attempt to write to the Security event log failed
#Event ID 208: An error occurred during an attempt to register the event source for the Security log
#Message #
Event ID 209: The Security log event source for the Federation Service could not be registered
#Event ID 215: The Federation Service at 'data1' did not return any WS-Trust endpoints to be published by the federation server proxy
#Event ID 217: A WS-Trust endpoint that was configured could not be opened
#Event ID 218: The federation server proxy received error code 'data2' while making a request to the Federation Service at 'data1'
#Event ID 220: The Federation Service configuration could not be loaded correctly from the AD FS configuration database.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 220,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:11:11.159207+00:00",
"event_record_id": 297,
"correlation": {},
"execution": {
"process_id": 12444,
"thread_id": 11500
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "ADMIN0012: OperationFault"
}
}
},
"message": ""
}
Event ID 220: The Federation Service configuration could not be loaded correctly from the AD FS configuration database
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 220,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:12:50.2296755+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "ADMIN0012: OperationFault"
}
}
Example keys not documented in the fields table: EventData
Event ID 221: A change to the token service configuration was detected, but there was an error reloading the changes to configuration.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 221,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:10:50.898809+00:00",
"event_record_id": 229,
"correlation": {},
"execution": {
"process_id": 12444,
"thread_id": 8536
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "ADMIN0012: OperationFault"
}
}
},
"message": ""
}
Event ID 221: A change to the token service configuration was detected, but there was an error reloading the changes to configuration
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 221,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:12:50.2295701+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "ADMIN0012: OperationFault"
}
}
Example keys not documented in the fields table: EventData
Event ID 222: The federation server proxy was unable to complete a request to the Federation Service at address 'data1' because of a time-out
#Event ID 223: Claim description could not be loaded correctly from the database
#Event ID 224: The federation server proxy configuration could not be updated with the latest configuration on the federation service
#Event ID 225: A change to the service configuration was detected, but there was an error reloading the changes to data1.
#Event ID 225: A change to the service configuration was detected, but there was an error reloading the changes to
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 230: The federation server proxy has detected congestion, caused by high latency response times, on the Federation Service
#Event ID 238: The Federation Service failed to find a domain controller for the domain data1.
#Event ID 238: The Federation Service failed to find a domain controller for the domain
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 244: The Federation Service was unable to listen at 'data1' for WS-MetadataExchange requests due to an unexpected error
#Event ID 245: The federation server proxy successfully retrieved and updated its configuration from the Federation Service 'data1'
#Event ID 246: The Federation Service encountered an error during an attempt to connect to a LDAP server at data1.
#Event ID 246: The Federation Service encountered an error during an attempt to connect to a LDAP server at
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString |
Event ID 247: The Federation Service encountered an error while connecting to a global catalog server at data1.
#Event ID 247: The Federation Service encountered an error while connecting to a global catalog server at
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString |
Event ID 248: The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1.
#Event ID 248: The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at
#Description
The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1. The error message is 'data2'.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 249: The certificate identified by thumbprint 'data1' could not be found in the certificate store
#Event ID 250: Expiration of the artifact failed.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 250,
"level": "Error",
"task": null,
"opcode": "Info",
"time_created": "2026-05-06T11:31:03.4208627+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 250: Expiration of the artifact failed
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 250,
"level": "Error",
"task": null,
"opcode": "Info",
"time_created": "2026-05-06T11:31:03.4208627+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 251: Attribute store 'Event.EventData' is loaded successfully.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 251,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:03:52.787344+00:00",
"event_record_id": 3,
"correlation": {},
"execution": {
"process_id": 11528,
"thread_id": 11808
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "Active Directory"
}
}
},
"message": ""
}
Event ID 251: Attribute store 'data1' is loaded successfully
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 251,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T15:43:10.8344846+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 252: The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service
#Event ID 253: AD FS proxy service failed to start a listener for the endpoint 'data1'
#Event ID 258: The relying party 'data1' is not configured with SAML Assertion Consumer Services
#Event ID 259: The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'.
#Event ID 259: The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'
#Description
The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 260: The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'.
#Event ID 260: The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'
#Description
The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 261: The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'.
#Event ID 261: The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'
#Description
The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 262: The artifact resolution request failed
#Event ID 273: The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'.
#Event ID 273: The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'
#Description
The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString |
Event ID 274: The federation server proxy encountered an error while trying to listen on one of the proxy endpoints
#Event ID 275: The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service data1.
#Event ID 275: The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 276: The federation server proxy was not able to authenticate to the Federation Service
#Event ID 277: The Federation Service encountered an unexpected exception and has shut down
#Event ID 278: The SAML artifact resolution endpoint is not configured or it is disabled.
#Message #
Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 278,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:03:53.726364+00:00",
"event_record_id": 4,
"correlation": {},
"execution": {
"process_id": 11528,
"thread_id": 11808
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 278: The SAML artifact resolution endpoint is not configured or it is disabled
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 278,
"level": "Warning",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T15:43:11.7775437+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 279: Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database
#Event ID 280: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service config...
#Event ID 280: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 281: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpo...
#Event ID 281: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 283: Unable to resolve the SAML artifact
#Event ID 284: Unable to resolve the SAML artifact
#Event ID 285: The SAML artifact was resolved, but the response is empty or does not contain expected assertions
#Event ID 286: Cannot connect to the artifact database
#Event ID 287: Cannot add the artifact to the artifact database
#Event ID 288: Cannot get the artifact from storage
#Event ID 289: Cannot remove the artifact from storage
#Event ID 290: Cannot set expiration for the artifacts in storage
#Event ID 291: The artifact resolution service could not be started
#Event ID 293: A SAML request for the required artifact was rejected because the artifact resolution service is not enabled
#Event ID 294: The SAML artifact resolution request specified an issuer that is not configured for the relying party
#Event ID 297: The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured
#Event ID 298: The Windows Hello for Business key receipt certificate background task will not run.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 298,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.107600+00:00",
"event_record_id": 71,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 13100
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "ServiceState.IsDrsInitialized is false."
}
}
},
"message": ""
}
Event ID 298: The Windows Hello for Business key receipt certificate background task will not run
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 298,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-05-27T16:31:52.8156192+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 302: The Federation Service could not authorize token issuance for caller 'data2' as subject 'data3' to the relying party 'data4'.
#Event ID 302: The Federation Service could not authorize token issuance for caller 'data2' as subject 'data3' to the relying party 'data4'
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString |
Event ID 303: The Federation Service encountered an error while processing the SAML authentication request
#Event ID 305: The Federation Service encountered an error while querying a LDAP server at data1.
#Event ID 305: The Federation Service encountered an error while querying a LDAP server at
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString |
Event ID 306: The Federation Service encountered an error while querying a global catalog server at data1.
#Event ID 306: The Federation Service encountered an error while querying a global catalog server at
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString |
Event ID 311: An attempt to update AD FS performance counters failed
#Event ID 315: An error occurred during an attempt to build the certificate chain for the claims provider trust 'data1' certificate identified by thumbprint 'data2'
#Event ID 316: An error occurred during an attempt to build the certificate chain for the relying party trust 'data1' certificate identified by thumbprint 'data2'
#Event ID 317: An error occurred during an attempt to build the certificate chain for the relying party trust 'Event.EventData' certificate identified by thumbprint 'data1'.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 317,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:09:23.681803+00:00",
"event_record_id": 208,
"correlation": {
"ActivityID": "88CEECE0-7882-41D3-9B05-08A1D8CE3B05"
},
"execution": {
"process_id": 13608,
"thread_id": 14296
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"https://testrp3.example.com/oauth",
"DB0FEA9B641F3814FC5168AE83EF7839AF1BB012",
"CheckChainExcludeRoot",
"The certificate is revoked.\r\n\r\n"
]
}
}
},
"message": ""
}
Event ID 317: An error occurred during an attempt to build the certificate chain for the relying party trust 'data1' certificate identified by thumbprint 'data2'
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 317,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:09:23.6818033+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "https://testrp3.example.com/oauthDB0FEA9B641F3814FC5168AE83EF7839AF1BB012CheckChainExcludeRootThe certificate is revoked.\n\n"
}
}
Example keys not documented in the fields table: EventData
Event ID 319: An error occurred while the certificate chain for the client certificate identified by thumbprint 'data1' was being built
#Event ID 320: The verification of the SAML message signature failed
#Event ID 321: The SAML authentication request had a NameID Policy that could not be satisfied
#Event ID 323: The Federation Service could not authorize token issuance for the caller 'data2' on behalf of the subject 'data3' to the relying party 'data4'.
#Event ID 325: The Federation Service could not authorize token issuance for caller 'data1'.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 325,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:07:37.248466+00:00",
"event_record_id": 96,
"correlation": {
"ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
},
"execution": {
"process_id": 9844,
"thread_id": 8576
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"a6f4ff0b-8776-43a4-9be1-6b9bf86e338f",
"ludus\\domainadmin\r\n",
"https://testrp1.example.com/saml",
"Microsoft.IdentityServer.Service.IssuancePipeline.CallerAuthorizationException: MSIS5007: The caller authorization failed for caller identity ludus\\domainadmin for relying party trust https://testrp1.example.com/saml.\r\n at Microsoft.IdentityModel.Threading.AsyncResult.End(IAsyncResult result)\r\n at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.ProcessCoreAsyncResult.End(IAsyncResult ar)\r\n at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.EndProcessCore(IAsyncResult ar, String requestAction, String responseAction, String trustNamespace)"
]
}
}
},
"message": ""
}
Event ID 325: The Federation Service could not authorize token issuance for caller 'data2'
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 325,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:09:23.9077724+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "2699b4ab-8f31-4d84-a931-f6e38783fc3bludus\\domainadmin\nhttps://testrp1.example.com/samlMicrosoft.IdentityServer.Service.IssuancePipeline.CallerAuthorizationException: MSIS5007: The caller authorization failed for caller identity ludus\\domainadmin for relying party trust https://testrp1.example.com/saml.\n at Microsoft.IdentityModel.Threading.AsyncResult.End(IAsyncResult result)\n at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.ProcessCoreAsyncResult.End(IAsyncResult ar)\n a..."
}
}
Example keys not documented in the fields table: EventData
Event ID 326: Failed to load the AD FS claims policy engine using policy type 'data1' User Action Make sure AD FS is installed correctly.
#Event ID 326: Failed to load the AD FS claims policy engine using policy type 'data1'
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 327: An error occurred during processing of the SAML logout request
#Event ID 328: The SAML artifact resolution request was resolved, but the response does not contain the expected assertions
#Event ID 329: The certificate that is identified by thumbprint 'data1' could not be decrypted using the keys for X
#Event ID 331: The certificate management service encountered an error during decryption of the keys
#Event ID 332: The certificate management service encountered an error during encryption of the keys
#Event ID 333: The certificate management service encountered an error during database access
#Event ID 334: Certificate rollover service needs to rollover data1 certificates urgently
#Event ID 335: task_0335
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 335,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:06:25.397047+00:00",
"event_record_id": 83,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 13020
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "MSIS10005: Certificate rollover service has added certificate with thumbprint '7D951E82355227B06C62677CAA93C92BCC9FD7BC' to 'Signing' certificate collection. See https://go.microsoft.com/fwlink/?linkid=861845 for more information."
}
}
},
"message": ""
}
Event ID 335
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 335,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:06:25.3970562+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "MSIS10004: Certificate rollover service has set certificate with thumbprint '7D951E82355227B06C62677CAA93C92BCC9FD7BC' as primary 'Signing' certificate. See https://go.microsoft.com/fwlink/?linkid=861845 for more information."
}
}
Example keys not documented in the fields table: EventData
Event ID 336: The certificate management cycle was initiated.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 336,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.117752+00:00",
"event_record_id": 72,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 13136
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 336: The certificate management cycle was initiated
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 336,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-05-27T16:14:39.2192666+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 337: The certificate management cycle was completed.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 337,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.300723+00:00",
"event_record_id": 81,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 13136
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 337: The certificate management cycle was completed
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 337,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-05-27T16:14:39.3938107+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 338: An error was encountered during certificate rollover
#Event ID 339: An error occurred during initialization of certificate rollover
#Event ID 341: The NotBefore attribute for the token has a value that is set to a future time
#Event ID 342: Token validation failed.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 342,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:07:36.815386+00:00",
"event_record_id": 95,
"correlation": {
"ActivityID": "FCDC6F25-76F3-4BC2-B0EB-7EFEBD19BD6C"
},
"execution": {
"process_id": 9844,
"thread_id": 11496
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"http://schemas.microsoft.com/ws/2006/05/identitymodel/tokens/UserName",
"fakeuser-The user name or password is incorrect",
"System.IdentityModel.Tokens.SecurityTokenValidationException: fakeuser ---> System.ComponentModel.Win32Exception: The user name or password is incorrect\r\n at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\r\n at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserInfo(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String authenticationType, String issuerName)\r\n at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUser(String domain, String username, String password, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String issuerName)\r\n at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)\r\n --- End of inner exception stack trace ---\r\n at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)\r\n at Microsoft.IdentityServer.Service.Tokens.MsisLocalCpUserNameSecurityTokenHandler.ValidateTokenInternal(UsernameAuthenticationContext usernameAuthenticationContext, SecurityToken token)\r\n at Microsoft.IdentityServer.Service.Tokens.MsisLocalCpUserNameSecurityTokenHandler.ValidateToken(SecurityToken token)\r\n\r\nSystem.ComponentModel.Win32Exception (0x80004005): The user name or password is incorrect\r\n at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\r\n at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserInfo(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String authenticationType, String issuerName)\r\n at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUser(String domain, String username, String password, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String issuerName)\r\n at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)"
]
}
}
},
"message": ""
}
Event ID 342: Token validation failed
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 342,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:07:36.8153864+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "http://schemas.microsoft.com/ws/2006/05/identitymodel/tokens/UserNamefakeuser-The user name or password is incorrectSystem.IdentityModel.Tokens.SecurityTokenValidationException: fakeuser ---> System.ComponentModel.Win32Exception: The user name or password is incorrect\n at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\n at Microsoft.IdentityServe..."
}
}
Example keys not documented in the fields table: EventData
Event ID 343: There was an error during initialization of synchronization
#Event ID 344: There was an error doing synchronization
#Event ID 345: There was a communication error during AD FS configuration database synchronization
#Event ID 346: There was an error during retrieving the configuration data for the secondary federation server
#Event ID 348: Synchronization of configuration data from the primary federation server 'data1' is completed
#Event ID 349: The administration service for the Federation Service started successfully.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 349,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:03:51.927998+00:00",
"event_record_id": 2,
"correlation": {},
"execution": {
"process_id": 11528,
"thread_id": 11808
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "Policy Administration ServiceHost\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nhttp://adfs.ludus.domain:80/adfs/services/policystoretransfer\r\nnet.tcp://localhost:1501/adfs/services/policystoretransfer\r\n\r\n"
}
}
},
"message": ""
}
Event ID 349: The administration service for the Federation Service started successfully
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 349,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T15:43:10.3652052+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 351: There was an error getting synchronization properties
#Event ID 352: A SQL operation in the AD FS configuration database with connection string Event.EventData failed.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 352,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:10:50.887915+00:00",
"event_record_id": 228,
"correlation": {},
"execution": {
"process_id": 12444,
"thread_id": 8536
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"Data Source=np:\\\\.\\pipe\\microsoft##wid\\tsql\\query;Initial Catalog=AdfsConfigurationV4;Integrated Security=True",
"Login failed for user 'ludus\\svc_adfs'."
]
}
}
},
"message": ""
}
Event ID 352: A SQL operation in the AD FS configuration database with connection string data1 failed
#Description
A SQL operation in the AD FS configuration database with connection string failed.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 352,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:12:50.2294719+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "Data Source=np:\\\\.\\pipe\\microsoft##wid\\tsql\\query;Initial Catalog=AdfsConfigurationV4;Integrated Security=TrueLogin failed for user 'ludus\\svc_adfs'."
}
}
Example keys not documented in the fields table: EventData
Event ID 353: Unable to resolve the SAML artifact
#Event ID 354: The artifact resolution service could not verify the request signature
#Event ID 356: Failed to register notification to the SQL database with the connection string data1 for cache type 'data2'
#Event ID 357: Successfully registered notification to the SQL database with the connection string data1.
#Event ID 357: Successfully registered notification to the SQL database with the connection string
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 358: Restarting Event.EventData.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 358,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:06:25.236927+00:00",
"event_record_id": 82,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 13020
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "Issuance ServiceHost"
}
}
},
"message": ""
}
Event ID 358: Restarting
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 358,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:06:25.5672417+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "Issuance ServiceHost"
}
}
Example keys not documented in the fields table: EventData
Event ID 359: An error occurred during an attempt to restart data1.
#Event ID 359: An error occurred during an attempt to restart
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 360: A request was made to a certificate transport endpoint, but the request did not include a client certificate
#Message #
Event ID 362: Encountered error during federation passive sign-out
#Event ID 363: A communication error occurred during an attempt to get a token from the Federation Service
#Event ID 364: Encountered error during federation passive request.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 364,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:08:52.936421+00:00",
"event_record_id": 109,
"correlation": {
"ActivityID": "E915B92E-2E46-4CB5-0900-0040080000F4"
},
"execution": {
"process_id": 9844,
"thread_id": 12680
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"OAuthAuthorizationProtocol",
"",
"Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \r\n at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\r\n at Microsoft.IdentityServer.Web.Protocols.ProtocolContext.Validate()\r\n at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationProtocolHandler.GetRequiredPipelineBehaviors(ProtocolContext pContext)\r\n at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context)\r\n\r\n"
]
}
}
},
"message": ""
}
Event ID 364: Encountered error during federation passive request
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 364,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:08:53.1123197+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "OAuthAuthorizationProtocolMicrosoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \n at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\n at Microsoft.IdentityServer.Web.Protocols.P..."
}
}
Example keys not documented in the fields table: EventData
Event ID 365: A token request was received for the relying party 'data1', but the request could not be fulfilled because the relying party trust is not enabled
#Event ID 366: A token was received from claims provider 'data1', but the token could not be validated because the claims provider trust is not enabled
#Event ID 367: The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federati...
#Event ID 368: The SAML Single Logout request does not correspond to the logged-in session participant
#Event ID 369: Processing TTP request failed with the following exception
#Event ID 370: Incoming TTP response is not valid
#Event ID 371: Cannot find certificate to validate message/token signature obtained from claims provider
#Event ID 372: Authentication Failed
#Event ID 373: The artifact request from the replying party is signed with a weaker signature algorithm
#Event ID 374: An error occurred while building the certificate chain for the claims provider trust 'data1' certificate identified by thumbprint 'data2'
#Event ID 375: Policy store synchronization initiated
#Event ID 376: An Error occurred while executing a query in SQL attribute store
#Event ID 377: A processing error occurred in an attribute store
#Event ID 378: SAML request is not signed with expected signature algorithm
#Event ID 379: A security token was rejected as the specified IssueInstant was before the allowed time frame
#Event ID 380: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data
#Event ID 381: An error occurred during an attempt to build the certificate chain for configuration certificate identified by thumbprint 'data1'
#Event ID 382: AD FS detected that the Federation Service has more than data1 data2 trusts configured and that the data in the AD FS configuration database for this Fed...
#Event ID 382: AD FS detected that the Federation Service has more than data1 data2 trusts configured and that the data in the AD FS configuration database for this Federation Service is stored and synchronized u...
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 383: The Web request failed because the web
#Event ID 384: The request to the Federation Service failed because the web
#Event ID 385: AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire s...
#Event ID 385: AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon
#Description
AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon. See additional details for more information.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 386: AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 386,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.125743+00:00",
"event_record_id": 76,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 9156
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 386: AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 386,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T20:13:14.5591807+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 387: AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD F...
#Event ID 387: AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 388: AD FS detected that all the service certificates have appropriate access given to the AD FS service account.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 388,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.126174+00:00",
"event_record_id": 77,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 11756
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 388: AD FS detected that all the service certificates have appropriate access given to the AD FS service account
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 388,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T15:44:12.3999854+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 389: AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon
#Event ID 390: AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 390,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.154591+00:00",
"event_record_id": 79,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 9156
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 390: AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 390,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T20:13:14.5760402+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 392: The federation server proxy was able to successfully renew its trust with the Federation Service
#Event ID 393: The federation server proxy could not establish a trust with the Federation Service
#Event ID 394: The federation server proxy could not renew its trust with the Federation Service
#Event ID 395: The trust between the federation server proxy and the Federation Service was established successfully using the account 'data1'
#Event ID 396: The trust between the federation server proxy and the Federation Service was renewed successfully
#Event ID 397: The federation server loaded the HTTP proxy configuration from WinHTTP settings.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 397,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:03:50.877782+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 11528,
"thread_id": 12484
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"",
"",
"",
"\r\n"
]
}
}
},
"message": ""
}
Event ID 397: The federation server loaded the HTTP proxy configuration from WinHTTP settings
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 397,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T15:43:09.5969961+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 398: AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived
#Event ID 399: AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 399,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.121989+00:00",
"event_record_id": 74,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 9156
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 399: AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 399,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-23T20:13:14.5561015+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 400: VSS writer permissions have been granted to user data1.
#Event ID 400: VSS writer permissions have been granted to user
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 401: VSS writer permissions have been revoked from user data1.
#Event ID 401: VSS writer permissions have been revoked from user
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 402: Failed to add some of the certificate claims
#Event ID 407: Password change failed for following user.
#Event ID 407: Password change failed for following user:
#Description
Password change failed for following user.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Event ID 414: An error occurred during processing of a token request
#Description
An error occurred during processing of a token request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString |
Event ID 416: Web configuration error:
#Description
Web configuration error.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 417: Unable to add the certificate claim data1.
#Event ID 418: The trust between the federation server proxy and the Federation Service was successfully renewed
#Event ID 419: Unable to renew the trust between the federation server proxy and the Federation Service
#Event ID 420: The trust between the federation server proxy and the Federation Service was successfully established
#Event ID 421: The trust between the federation server proxy and the Federation Service could not be established
#Event ID 432: Error handling request from proxy at data1.
#Event ID 432: Error handling request from proxy at
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 433: Error encountered while renewing trust with the federation server proxy
#Event ID 434: The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) will expire at data2 UTC
#Event ID 435: The primary AD FS token signing certificate ( thumbprint data1 ) will expire at data2 UTC
#Event ID 436: The primary AD FS token decryption certificate ( thumbprint data1 ) will expire at data2 UTC
#Event ID 437: Error encountered while checking for pending certificate rollovers
#Event ID 438: Error encountered while checking rollover status of the AD FS certificate authority issuer certificate
#Event ID 439: Error encountered while attempting to read an enrollment certificate from a template
#Event ID 440: A Certificate Authority Enrollment Certificate was found
#Event ID 441: A token with a bad token binding key was found
#Event ID 442: The CA enrollment certificate management cycle was initiated
#Event ID 443: The CA enrollment certificate management cycle was completed
#Event ID 444: Error encountered while checking status of the AD FS enrollment certificate
#Event ID 445: A token with no binding was received on a request which is token-binding-capable
#Event ID 446: An SSO token with no binding was received on a request which is token-binding-capable
#Event ID 447: Error encountered while attempting to update the configuration policy for the template data1.
#Event ID 447: Error encountered while attempting to update the configuration policy for the template
#Description
Error encountered while attempting to update the configuration policy for the template . If the template is published under machine policy, service might not be able to read it.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 448: Error encountered while attempting to add a leased task to the database
#Event ID 449: Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task
#Event ID 450: Error encountered while removing the expired items from the usercode cache
#Event ID 451: Following nodes have the reported heartbeat older than data1 UTC and will be deleted.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 451,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-07-03T05:43:30.289319+00:00",
"event_record_id": 1602,
"correlation": {},
"execution": {
"process_id": 3316,
"thread_id": 11880
},
"channel": "AD FS/Admin",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"6/26/2026 5:43:30 AM",
"JD-DC01-2022.ludus.domain"
]
}
}
},
"message": ""
}
Event ID 451: Following nodes have the reported heartbeat older than Event.EventData UTC and will be deleted
#Description
Following nodes have the reported heartbeat older than UTC and will be deleted.
Fields #
| Name | Description |
|---|---|
Event.EventData | |
data1 UnicodeString | |
data2 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2ffb687a-1571-4ace-8550-47ab5ccae2bc",
"event_source_name": "",
"event_id": 451,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-07-03T05:43:30.2893198+00:00",
"event_record_id": 1602,
"correlation": {
"ActivityID": "",
"RelatedActivityID": ""
},
"execution": {
"process_id": 3316,
"thread_id": 11880
},
"channel": "AD FS/Admin",
"computer": "JD-DC01-2022.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
}
},
"user_data": {
"Event": {
"EventData": "6/26/2026 5:43:30 AMJD-DC01-2022.ludus.domain"
}
},
"message": "Following nodes have the reported heartbeat older than 6/26/2026 5:43:30 AM UTC and will be deleted. \r\n\r\nJD-DC01-2022.ludus.domain"
}
Event ID 500: More information for the event entry with Instance ID data1.
#Description
More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString | |
data9 UnicodeString | |
data10 UnicodeString | |
data11 UnicodeString | |
data12 UnicodeString | |
data13 UnicodeString | |
data14 UnicodeString | |
data15 UnicodeString | |
data16 UnicodeString | |
data17 UnicodeString | |
data18 UnicodeString | |
data19 UnicodeString | |
data20 UnicodeString | |
data21 UnicodeString |
Event ID 500: More information for the event entry with Instance ID
#Description
More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString | |
data9 UnicodeString | |
data10 UnicodeString | |
data11 UnicodeString | |
data12 UnicodeString | |
data13 UnicodeString | |
data14 UnicodeString | |
data15 UnicodeString | |
data16 UnicodeString | |
data17 UnicodeString | |
data18 UnicodeString | |
data19 UnicodeString | |
data20 UnicodeString | |
data21 UnicodeString |
Event ID 501: More information for the event entry with Instance ID Event.EventData.
#Description
More information for the event entry with Instance ID Event.EventData. There may be more events with the same Instance ID with more information.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString | |
data9 UnicodeString | |
data10 UnicodeString | |
data11 UnicodeString | |
data12 UnicodeString | |
data13 UnicodeString | |
data14 UnicodeString | |
data15 UnicodeString | |
data16 UnicodeString | |
data17 UnicodeString | |
data18 UnicodeString | |
data19 UnicodeString | |
data20 UnicodeString | |
data21 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 501,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:07:37.250884+00:00",
"event_record_id": 97,
"correlation": {
"ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
},
"execution": {
"process_id": 9844,
"thread_id": 8576
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"a6f4ff0b-8776-43a4-9be1-6b9bf86e338f",
"http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname",
"ludus\\domainadmin",
"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name",
"ludus\\domainadmin",
"http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid",
"S-1-5-21-1006758700-2167138679-1475694448-1105",
"http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
"S-1-5-21-1006758700-2167138679-1475694448-572",
"http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
"S-1-5-21-1006758700-2167138679-1475694448-1149",
"http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
"S-1-18-1",
"http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
"S-1-5-21-1006758700-2167138679-1475694448-519",
"http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
"S-1-5-21-1006758700-2167138679-1475694448-518",
"http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
"S-1-5-21-1006758700-2167138679-1475694448-512",
"http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
"S-1-5-21-1006758700-2167138679-1475694448-520"
]
}
}
},
"message": ""
}
Event ID 501: More information for the event entry with Instance ID
#Description
More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString | |
data9 UnicodeString | |
data10 UnicodeString | |
data11 UnicodeString | |
data12 UnicodeString | |
data13 UnicodeString | |
data14 UnicodeString | |
data15 UnicodeString | |
data16 UnicodeString | |
data17 UnicodeString | |
data18 UnicodeString | |
data19 UnicodeString | |
data20 UnicodeString | |
data21 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 501,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:09:23.9078077+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "2699b4ab-8f31-4d84-a931-f6e38783fc3bhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/implicitupndomainadmin@ludus.domainhttp://schemas.microsoft.com/ws/2014/01/identity/claims/accountstoreAD AUTHORITYhttp://schemas.microsoft.com/ws/2014/01/identity/claims/anchorclaimtypehttp://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"
}
}
Example keys not documented in the fields table: EventData
Event ID 502: More information for the event entry with Instance ID data1.
#Description
More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString | |
data9 UnicodeString | |
data10 UnicodeString | |
data11 UnicodeString | |
data12 UnicodeString | |
data13 UnicodeString | |
data14 UnicodeString | |
data15 UnicodeString | |
data16 UnicodeString | |
data17 UnicodeString | |
data18 UnicodeString | |
data19 UnicodeString | |
data20 UnicodeString | |
data21 UnicodeString |
Event ID 502: More information for the event entry with Instance ID
#Description
More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString | |
data9 UnicodeString | |
data10 UnicodeString | |
data11 UnicodeString | |
data12 UnicodeString | |
data13 UnicodeString | |
data14 UnicodeString | |
data15 UnicodeString | |
data16 UnicodeString | |
data17 UnicodeString | |
data18 UnicodeString | |
data19 UnicodeString | |
data20 UnicodeString | |
data21 UnicodeString |
Event ID 503: More information for the event entry with Instance ID data1.
#Description
More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString | |
data9 UnicodeString | |
data10 UnicodeString | |
data11 UnicodeString | |
data12 UnicodeString | |
data13 UnicodeString | |
data14 UnicodeString | |
data15 UnicodeString | |
data16 UnicodeString | |
data17 UnicodeString | |
data18 UnicodeString | |
data19 UnicodeString | |
data20 UnicodeString | |
data21 UnicodeString |
Event ID 503: More information for the event entry with Instance ID
#Description
More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString | |
data9 UnicodeString | |
data10 UnicodeString | |
data11 UnicodeString | |
data12 UnicodeString | |
data13 UnicodeString | |
data14 UnicodeString | |
data15 UnicodeString | |
data16 UnicodeString | |
data17 UnicodeString | |
data18 UnicodeString | |
data19 UnicodeString | |
data20 UnicodeString | |
data21 UnicodeString |
Event ID 504: The following update was successful to the application proxy store on the federation server
#Event ID 505: The following update attempt to the application proxy store on the federation server failed
#Event ID 506: The following update attempt to the application proxy relying party trust on the federation server succeeded
#Event ID 507: The following update attempt to the application proxy relying party trust on the federation server failed
#Event ID 508: The following update attempt to the relying party trust on the federation server succeeded
#Event ID 509: The following update attempt to the relying party trust on the federation server failed
#Event ID 510: More information for the event entry with Instance ID data1.
#Description
More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString | |
data9 UnicodeString | |
data10 UnicodeString | |
data11 UnicodeString | |
data12 UnicodeString | |
data13 UnicodeString | |
data14 UnicodeString | |
data15 UnicodeString | |
data16 UnicodeString | |
data17 UnicodeString | |
data18 UnicodeString | |
data19 UnicodeString | |
data20 UnicodeString | |
data21 UnicodeString |
Event ID 510: More information for the event entry with Instance ID
#Description
More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString | |
data8 UnicodeString | |
data9 UnicodeString | |
data10 UnicodeString | |
data11 UnicodeString | |
data12 UnicodeString | |
data13 UnicodeString | |
data14 UnicodeString | |
data15 UnicodeString | |
data16 UnicodeString | |
data17 UnicodeString | |
data18 UnicodeString | |
data19 UnicodeString | |
data20 UnicodeString | |
data21 UnicodeString |
Event ID 511: The incoming sign-in request is not allowed due to an invalid Federation Service configuration
#Event ID 521: The request for the relying party token resulted in a failure
#Event ID 530: AD FS could not read the local claims provider trusts from the AD FS configuration
#Event ID 531: AD FS could not read the local claims provider trusts from the AD FS configuration
#Event ID 540: The Federation Service was was unable to return the OAuth discovery document as a result of an error
#Event ID 541: An invalid value was found during processing of the proxy configuration data from the AD FS server
#Event ID 542: There was an error during heartbeat
#Event ID 543: There was an error during heartbeat communicating to primary federation server
#Event ID 544: Heartbeat is not performed because primary server does not support heartbeat
#Event ID 545: Heartbeat is performed at primary server.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 545,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:03:56.798717+00:00",
"event_record_id": 35,
"correlation": {
"ActivityID": "0D26E79C-B333-000D-9A2E-270D33B3DC01"
},
"execution": {
"process_id": 8080,
"thread_id": 11896
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "localhost"
}
}
},
"message": ""
}
Event ID 545: Heartbeat is performed at primary server
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 545,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:13:59.8735895+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "localhost"
}
}
Example keys not documented in the fields table: EventData
Event ID 546: A current tenant certificate for Azure MFA was not found
#Event ID 547: The tenant certificate for Azure MFA has been renewed
#Event ID 548: The tenant certificate for Azure MFA will expire soon
#Event ID 549: The tenant certificate for Azure MFA has expired
#Event ID 550: The data1 primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1)
#Event ID 551: An error occurred during processing of an OAuth logout request
#Event ID 552: The session cookies were successfully deleted using the OAuth logout path.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 552,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:08:53.219831+00:00",
"event_record_id": 114,
"correlation": {
"ActivityID": "26B7203E-F387-4B80-0E00-0040080000F4"
},
"execution": {
"process_id": 9844,
"thread_id": 12680
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 552: The session cookies were successfully deleted using the OAuth logout path
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 552,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:08:53.2198315+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": ""
}
}
Example keys not documented in the fields table: EventData
Event ID 553: The specified redirect URL was validated successfully
#Event ID 554: The specified redirect URL did not match any of the OAuth client's redirect URIs.
#Description
The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 554,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:08:53.228256+00:00",
"event_record_id": 115,
"correlation": {
"ActivityID": "26B7203E-F387-4B80-0E00-0040080000F4"
},
"execution": {
"process_id": 9844,
"thread_id": 12680
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "https://localhost"
}
}
},
"message": ""
}
Event ID 554: The specified redirect URL did not match any of the OAuth client's redirect URIs
#Description
The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected.
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 554,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:08:53.2282562+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "https://localhost"
}
}
Example keys not documented in the fields table: EventData
Event ID 555: The Windows Hello for Business key receipt could not be verified
#Event ID 556: Error encountered while attempting to select a master node for the account store
#Event ID 557: An error occured while trying to communicate with the account store rest service on node data1.
#Event ID 557: An error occured while trying to communicate with the account store rest service on node
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 558: Syncronization of the Account Activity data failed
#Event ID 559: Device authentication using PKeyAuth failed
#Event ID 560: User data1 could not be found in the account database
#Event ID 561: Authorization failed when connecting to the account store endpoint on server data1.
#Event ID 561: Authorization failed when connecting to the account store endpoint on server
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 562: An error occurred when communcating with the account store endpoint on server data1.
#Event ID 562: An error occurred when communcating with the account store endpoint on server
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString |
Event ID 563: An error occurred while calculating extranet lockout status
#Event ID 565: An error occurred while attemtping to update the database schema for Adfs smart lockout
#Description
An error occurred while attemtping to update the database schema for Adfs smart lockout. See https://go.microsoft.com/fwlink/?linkid=864556 for more information.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Event ID 566: An error occurred during processing of an OAuth device code request
#Event ID 568: An error occurred during processing of an OAuth device auth request with the provided usercode: data1.
#Event ID 568: An error occurred during processing of an OAuth device auth request with the provided usercode:
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString |
Event ID 570: Active Directory trust enumeration was unable to enumerate one of more domains due to the following error
#Event ID 571: Enumeration of the Active Directory domains failed
#Event ID 572: The Active Directory suffix from this username is not trusted by this ADFS server
#Event ID 573: The following error was generated by a threat detection module
#Event ID 574: A threat detection module failed to load
#Event ID 575: The following threat detection module was successfully loaded.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 575,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:03:53.739665+00:00",
"event_record_id": 5,
"correlation": {},
"execution": {
"process_id": 11528,
"thread_id": 11808
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"BannedIpProvider",
"",
"Microsoft.IdentityServer.Service.AccountPolicy.BannedIpProvider, Microsoft.IdentityServer.Service, Version=10.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"
]
}
}
},
"message": ""
}
Event ID 575: The following threat detection module was successfully loaded
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 575,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-05-24T22:33:03.4173770+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 576: An unexpected error was returned from a threat detection module
#Event ID 1000: An error occurred during processing of a token request.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:07:37.253680+00:00",
"event_record_id": 101,
"correlation": {
"ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
},
"execution": {
"process_id": 9844,
"thread_id": 8576
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": [
"ludus\\domainadmin\r\n",
"",
"",
"https://testrp1.example.com/saml",
""
]
}
}
},
"message": ""
}
Event ID 1000: An error occurred during processing of a token request
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 1000,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:09:23.9078230+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "ludus\\domainadmin\nhttps://testrp1.example.com/saml"
}
}
Example keys not documented in the fields table: EventData
Event ID 1020: Encountered error during OAuth authorization request.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 1020,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:08:52.935997+00:00",
"event_record_id": 108,
"correlation": {
"ActivityID": "E915B92E-2E46-4CB5-0900-0040080000F4"
},
"execution": {
"process_id": 9844,
"thread_id": 12680
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \r\n at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\r\n\r\n"
}
}
},
"message": ""
}
Event ID 1020: Encountered error during OAuth authorization request
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 1020,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:08:53.1122569+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \n at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\n\n"
}
}
Example keys not documented in the fields table: EventData
Event ID 1021: Encountered error during OAuth token request.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 1021,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:07:36.668080+00:00",
"event_record_id": 94,
"correlation": {
"ActivityID": "43EBE48F-E201-482C-1500-00400A0000FF"
},
"execution": {
"process_id": 9844,
"thread_id": 8576
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": {
"Data": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9241: Received invalid OAuth access token request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'nonexistent'. \r\n at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthTokenRequestContext.ValidateCore()\r\n at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthClientCredentialsContext.ValidateCore()\r\n\r\n"
}
}
},
"message": ""
}
Event ID 1021: Encountered error during OAuth token request
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString |
Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 1021,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-03-13T23:08:52.9024091+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS"
},
"event_data": {
"EventData": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9300: Received invalid OAuth client credentials request. The received client is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client: 'fake'. \n at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthUsernamePasswordContext.ValidateCore()\n\n"
}
}
Example keys not documented in the fields table: EventData
Event ID 1080: An error occurred while processing WebFinger request
#Event ID 1100: The Federation Service could not authorize a request to one of the REST endpoints
#Event ID 1109: The Federation Service failed to connect to the LDAP account store to authenticate user data2.
#Event ID 1109: The Federation Service failed to connect to the LDAP account store to authenticate user
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString |
Event ID 1110: The Federation Service failed to connect to the primary LDAP account store to authenticate user data2.
#Event ID 1110: The Federation Service failed to connect to the primary LDAP account store to authenticate user
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString |
Event ID 1111: The Federation Service failed to connect to all LDAP account stores to authenticate user data2.
#Event ID 1111: The Federation Service failed to connect to all LDAP account stores to authenticate user
#Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
data7 UnicodeString |
Event ID 1112: The Federation Service failed to connect to the Ldap server
#Event ID 1113: Client Json Web Key Set (JWKS) synchronization initiated.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 1113,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.121414+00:00",
"event_record_id": 73,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 10760
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 1113: Client Json Web Key Set (JWKS) synchronization initiated
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 1113,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-05-27T16:14:39.2438903+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 1114: Client Json Web Key Set (JWKS) synchronization completed.
#Fields #
| Name | Description |
|---|---|
Event.EventData |
Example Event #
{
"system": {
"provider": "AD FS",
"guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
"event_source_name": "",
"event_id": 1114,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2026-03-13T23:05:10.154935+00:00",
"event_record_id": 80,
"correlation": {},
"execution": {
"process_id": 9844,
"thread_id": 10760
},
"channel": "AD FS/Admin",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"user_data": {
"Event": {
"EventData": null
}
},
"message": ""
}
Event ID 1114: Client Json Web Key Set (JWKS) synchronization completed
#Example Event #
{
"system": {
"provider": "AD FS",
"event_id": 1114,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-05-27T16:14:39.2578083+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "AD FS/Admin"
},
"event_data": {
"EventData": null
}
}
Example keys not documented in the fields table: EventData
Event ID 1115: The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from 'data1'
#Event ID 1116: An error occurred during a read operation from the configuration database
#Event ID 1117: An error occurred during monitoring of the following client's Json Web Key Set (JWKS)
#Event ID 1118: An error occurred during monitoring of clients'Json Web Key Set (JWKS)
#Event ID 1130: There was an error establishing or renewing the proxy trust
#Provenance
ETW provider GUID 2ffb687a-1571-4ace-8550-47ab5ccae2bc
Defined in Microsoft.IdentityServer.NativeResources.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 5.00, captured 2026-06-02