AD FS

EventTitleChannelSampleRule
100The Federation Service started successfully.AdminYN
100The Federation Service started successfullyUnknownYN
102There was an error in enabling endpoints of Federation Service.AdminYN
102There was an error in enabling endpoints of Federation ServiceUnknownYN
103The Federation Service stopped successfully.AdminYN
103The Federation Service stopped successfullyUnknownYN
104The artifact resolution service is not runningAdmin, UnknownNN
105An error occurred loading an authentication providerAdmin, UnknownNN
106An authentication provider was successfully loaded: Identifier: …AdminYN
106An authentication provider was successfully loaded: Identifier: 'data1', …UnknownYN
111The Federation Service encountered an error while processing the WS-Trust …Admin, UnknownNN
131During processing of the Federation Service configuration, the element 'data1' …AdminNN
131During processing of the Federation Service configuration, the element 'data1' …UnknownNN
132During processing of the Federation Service configuration, the required element …Admin, UnknownNN
133During processing of the Federation Service configuration, the element 'data1' …Admin, UnknownNN
134During processing of the Federation Service configuration, the element 'data1' …Admin, UnknownNN
135During processing of the Federation Service configuration, the element 'data1' …Admin, UnknownNN
136During processing of the Federation Service configuration, the Federation …Admin, UnknownNN
143The Federation Service was unable to create the federation metadata document as …Admin, UnknownNN
144The Federation Service Proxy blocked an illegitimate request made by a client, …AdminNN
144The Federation Service Proxy blocked an illegitimate request made by a client, …UnknownNN
147A token was received from a claims provider identified by the key 'data1', but …AdminNN
147A token was received from a claims provider identified by the key 'data1', but …UnknownNN
149During processing of the Federation Service configuration, the attribute store …AdminYN
149During processing of the Federation Service configuration, the attribute store …UnknownYN
155The Federation Service was unable to listen at 'data1' for metadata document …Admin, UnknownNN
156Trust monitoring cycle initiated.AdminYN
156Trust monitoring cycle initiatedUnknownYN
157Trust monitoring cycle completed.AdminYN
157Trust monitoring cycle completedUnknownYN
159The Federation Service encountered an error while writing to the following …Admin, UnknownNN
163An error occurred during initialization of trust monitoringAdmin, UnknownNN
164An error occurred during a read operation from the configuration databaseAdmin, UnknownNN
165An error occurred during trust monitoringAdmin, UnknownNN
166Trust monitoring service encountered an error while parsing the metadata …Admin, UnknownNN
167Trust monitoring service encountered an error while applying the data in the …Admin, UnknownNN
168The Federation Service encountered an error while retrieving the federation …Admin, UnknownNN
171The trust monitoring service automatically updated the trust of 'data1' …Admin, UnknownNN
173The trust monitoring service automatically updated the trust of 'data1' …Admin, UnknownNN
174Trust monitoring service detected changes in policy of 'data1', but did not …Admin, UnknownNN
180An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version …Admin, UnknownNN
181AD FS could not enable the new KDFv2 feature automatically because of missing …Admin, UnknownNN
182AD FS enabled the new KDFv2 feature successfullyAdmin, UnknownNN
183KDFv2 feature is disabled on AD FS farmAdmin, UnknownNN
184A token request was received for a relying party identified by the key 'data1', …AdminNN
184A token request was received for a relying party identified by the key 'data1', …UnknownNN
186The Federation Service could not fulfill the token-issuance requestAdmin, UnknownNN
187AD FS server received a JWT token without nonce in the assertion and it was …Admin, UnknownNN
188AD FS server is not configured to reject JWT tokens that did not have nonce in …AdminYN
188AD FS server is not configured to reject JWT tokens that did not have nonce in …UnknownYN
189AD FS server received an OAuth authorization request in the device code flow …AdminNN
189AD FS server received an OAuth authorization request in the device code flow …UnknownNN
193The Federation Service could not satisfy a token request because the relying …Admin, UnknownNN
197The Federation Service could not satisfy a token request because the …AdminNN
197The Federation Service could not satisfy a token request because the …UnknownNN
198The federation server proxy started successfullyAdmin, UnknownNN
199The federation server proxy could not be startedAdmin, UnknownNN
200The federation server proxy stopped successfullyAdmin, UnknownNN
201The Federation Service data1 encountered an Access Denied error while trying to …Admin, UnknownNN
202The Federation Service data1 could not be openedAdmin, UnknownNN
203The Federation Service data1 could not be shut down properlyAdmin, UnknownNN
204The Federation Service data1 could not be closedAdmin, UnknownNN
206The Federation Service could not fulfill the token-issuance request because the …AdminNN
206The Federation Service could not fulfill the token-issuance request because the …UnknownNN
207An attempt to write to the Security event log failedAdmin, UnknownNN
208An error occurred during an attempt to register the event source for the …Admin, UnknownNN
209The Security log event source for the Federation Service could not be registeredAdmin, UnknownNN
215The Federation Service at 'data1' did not return any WS-Trust endpoints to be …Admin, UnknownNN
217A WS-Trust endpoint that was configured could not be openedAdmin, UnknownNN
218The federation server proxy received error code 'data2' while making a request …Admin, UnknownNN
220The Federation Service configuration could not be loaded correctly from the AD …AdminYN
220The Federation Service configuration could not be loaded correctly from the AD …UnknownYN
221A change to the token service configuration was detected, but there was an error …AdminYN
221A change to the token service configuration was detected, but there was an error …UnknownYN
222The federation server proxy was unable to complete a request to the Federation …Admin, UnknownNN
223Claim description could not be loaded correctly from the databaseAdmin, UnknownNN
224The federation server proxy configuration could not be updated with the latest …Admin, UnknownNN
225A change to the service configuration was detected, but there was an error …AdminNN
225A change to the service configuration was detected, but there was an error …UnknownNN
230The federation server proxy has detected congestion, caused by high latency …Admin, UnknownNN
238The Federation Service failed to find a domain controller for the domain data1.AdminNN
238The Federation Service failed to find a domain controller for the domainUnknownNN
244The Federation Service was unable to listen at 'data1' for WS-MetadataExchange …Admin, UnknownNN
245The federation server proxy successfully retrieved and updated its configuration …Admin, UnknownNN
246The Federation Service encountered an error during an attempt to connect to a …AdminNN
246The Federation Service encountered an error during an attempt to connect to a …UnknownNN
247The Federation Service encountered an error while connecting to a global catalog …AdminNN
247The Federation Service encountered an error while connecting to a global catalog …UnknownNN
248The federation server proxy was not able to retrieve the list of endpoints from …AdminNN
248The federation server proxy was not able to retrieve the list of endpoints from …UnknownNN
249The certificate identified by thumbprint 'data1' could not be found in the …Admin, UnknownNN
250Expiration of the artifact failed.AdminYN
250Expiration of the artifact failedUnknownYN
251Attribute store 'Event.EventData' is loaded successfully.AdminYN
251Attribute store 'data1' is loaded successfullyUnknownYN
252The AD FS proxy service made changes to the endpoints it is listening on based …Admin, UnknownNN
253AD FS proxy service failed to start a listener for the endpoint 'data1'Admin, UnknownNN
258The relying party 'data1' is not configured with SAML Assertion Consumer …Admin, UnknownNN
259The request specified an Assertion Consumer Service index 'data1' that is not …AdminNN
259The request specified an Assertion Consumer Service index 'data1' that is not …UnknownNN
260The request specified an Assertion Consumer Service protocol binding 'data1' …AdminNN
260The request specified an Assertion Consumer Service protocol binding 'data1' …UnknownNN
261The request specified an Assertion Consumer Service URL 'data1' that is not …AdminNN
261The request specified an Assertion Consumer Service URL 'data1' that is not …UnknownNN
262The artifact resolution request failedAdmin, UnknownNN
273The request specified an assertion consumer service that is not configured or …AdminNN
273The request specified an assertion consumer service that is not configured or …UnknownNN
274The federation server proxy encountered an error while trying to listen on one …Admin, UnknownNN
275The federation server proxy could not establish a trust relationship for the SSL …AdminNN
275The federation server proxy could not establish a trust relationship for the SSL …UnknownNN
276The federation server proxy was not able to authenticate to the Federation …Admin, UnknownNN
277The Federation Service encountered an unexpected exception and has shut downAdmin, UnknownNN
278The SAML artifact resolution endpoint is not configured or it is disabled.AdminYN
278The SAML artifact resolution endpoint is not configured or it is disabledUnknownYN
279Unable to find a claims provider trust for SAML artifact resolution in the AD FS …Admin, UnknownNN
280Unable to resolve the SAML artifact from the claims provider because the claims …AdminNN
280Unable to resolve the SAML artifact from the claims provider because the claims …UnknownNN
281Unable to resolve the SAML artifact from the claims provider because the claims …AdminNN
281Unable to resolve the SAML artifact from the claims provider because the claims …UnknownNN
283Unable to resolve the SAML artifactAdmin, UnknownNN
284Unable to resolve the SAML artifactAdmin, UnknownNN
285The SAML artifact was resolved, but the response is empty or does not contain …Admin, UnknownNN
286Cannot connect to the artifact databaseAdmin, UnknownNN
287Cannot add the artifact to the artifact databaseAdmin, UnknownNN
288Cannot get the artifact from storageAdmin, UnknownNN
289Cannot remove the artifact from storageAdmin, UnknownNN
290Cannot set expiration for the artifacts in storageAdmin, UnknownNN
291The artifact resolution service could not be startedAdmin, UnknownNN
293A SAML request for the required artifact was rejected because the artifact …Admin, UnknownNN
294The SAML artifact resolution request specified an issuer that is not configured …Admin, UnknownNN
297The SAML artifact resolution request required an artifact resolution service …Admin, UnknownNN
298The Windows Hello for Business key receipt certificate background task will not …AdminYN
298The Windows Hello for Business key receipt certificate background task will not …UnknownYN
302The Federation Service could not authorize token issuance for caller 'data2' as …AdminNN
302The Federation Service could not authorize token issuance for caller 'data2' as …UnknownNN
303The Federation Service encountered an error while processing the SAML …Admin, UnknownNN
305The Federation Service encountered an error while querying a LDAP server at …AdminNN
305The Federation Service encountered an error while querying a LDAP server atUnknownNN
306The Federation Service encountered an error while querying a global catalog …AdminNN
306The Federation Service encountered an error while querying a global catalog …UnknownNN
311An attempt to update AD FS performance counters failedAdmin, UnknownNN
315An error occurred during an attempt to build the certificate chain for the …Admin, UnknownNN
316An error occurred during an attempt to build the certificate chain for the …Admin, UnknownNN
317An error occurred during an attempt to build the certificate chain for the …AdminYN
317An error occurred during an attempt to build the certificate chain for the …UnknownYN
319An error occurred while the certificate chain for the client certificate …Admin, UnknownNN
320The verification of the SAML message signature failedAdmin, UnknownNN
321The SAML authentication request had a NameID Policy that could not be satisfiedAdmin, UnknownNN
323The Federation Service could not authorize token issuance for the caller 'data2' …AdminNN
323The Federation Service could not authorize token issuance for the caller …UnknownNN
325The Federation Service could not authorize token issuance for caller 'data1'.AdminYN
325The Federation Service could not authorize token issuance for caller 'data2'UnknownYN
326Failed to load the AD FS claims policy engine using policy type 'data1' User …AdminNN
326Failed to load the AD FS claims policy engine using policy type 'data1'UnknownNN
327An error occurred during processing of the SAML logout requestAdmin, UnknownNN
328The SAML artifact resolution request was resolved, but the response does not …Admin, UnknownNN
329The certificate that is identified by thumbprint 'data1' could not be decrypted …Admin, UnknownNN
331The certificate management service encountered an error during decryption of the …Admin, UnknownNN
332The certificate management service encountered an error during encryption of the …Admin, UnknownNN
333The certificate management service encountered an error during database accessAdmin, UnknownNN
334Certificate rollover service needs to rollover data1 certificates urgentlyAdmin, UnknownNN
335task_0335AdminYN
335Event ID 335UnknownYN
336The certificate management cycle was initiated.AdminYN
336The certificate management cycle was initiatedUnknownYN
337The certificate management cycle was completed.AdminYN
337The certificate management cycle was completedUnknownYN
338An error was encountered during certificate rolloverAdmin, UnknownNN
339An error occurred during initialization of certificate rolloverAdmin, UnknownNN
341The NotBefore attribute for the token has a value that is set to a future timeAdmin, UnknownNN
342Token validation failed.AdminYN
342Token validation failedUnknownYN
343There was an error during initialization of synchronizationAdmin, UnknownNN
344There was an error doing synchronizationAdmin, UnknownNN
345There was a communication error during AD FS configuration database …Admin, UnknownNN
346There was an error during retrieving the configuration data for the secondary …Admin, UnknownNN
348Synchronization of configuration data from the primary federation server 'data1' …Admin, UnknownNN
349The administration service for the Federation Service started successfully.AdminYN
349The administration service for the Federation Service started successfullyUnknownYN
351There was an error getting synchronization propertiesAdmin, UnknownNN
352A SQL operation in the AD FS configuration database with connection string …AdminYN
352A SQL operation in the AD FS configuration database with connection string data1 …UnknownYN
353Unable to resolve the SAML artifactAdmin, UnknownNN
354The artifact resolution service could not verify the request signatureAdmin, UnknownNN
356Failed to register notification to the SQL database with the connection string …Admin, UnknownNN
357Successfully registered notification to the SQL database with the connection …AdminNN
357Successfully registered notification to the SQL database with the connection …UnknownNN
358Restarting Event.EventData.AdminYN
358RestartingUnknownYN
359An error occurred during an attempt to restart data1.AdminNN
359An error occurred during an attempt to restartUnknownNN
360A request was made to a certificate transport endpoint, but the request did not …Admin, UnknownNN
362Encountered error during federation passive sign-outAdmin, UnknownNN
363A communication error occurred during an attempt to get a token from the …Admin, UnknownNN
364Encountered error during federation passive request.AdminYN
364Encountered error during federation passive requestUnknownYN
365A token request was received for the relying party 'data1', but the request …Admin, UnknownNN
366A token was received from claims provider 'data1', but the token could not be …Admin, UnknownNN
367The audience restriction was not valid because the specified audience identifier …AdminNN
367The audience restriction was not valid because the specified audience identifier …UnknownNN
368The SAML Single Logout request does not correspond to the logged-in session …Admin, UnknownNN
369Processing TTP request failed with the following exceptionAdmin, UnknownNN
370Incoming TTP response is not validAdmin, UnknownNN
371Cannot find certificate to validate message/token signature obtained from claims …Admin, UnknownNN
372Authentication FailedAdmin, UnknownNN
373The artifact request from the replying party is signed with a weaker signature …Admin, UnknownNN
374An error occurred while building the certificate chain for the claims provider …Admin, UnknownNN
375Policy store synchronization initiatedAdmin, UnknownNN
376An Error occurred while executing a query in SQL attribute storeAdmin, UnknownNN
377A processing error occurred in an attribute storeAdmin, UnknownNN
378SAML request is not signed with expected signature algorithmAdmin, UnknownNN
379A security token was rejected as the specified IssueInstant was before the …Admin, UnknownNN
380During processing of the Federation Service configuration, the element 'data1' …Admin, UnknownNN
381An error occurred during an attempt to build the certificate chain for …Admin, UnknownNN
382AD FS detected that the Federation Service has more than data1 data2 trusts …AdminNN
382AD FS detected that the Federation Service has more than data1 data2 trusts …UnknownNN
383The Web request failed because the webAdmin, UnknownNN
384The request to the Federation Service failed because the webAdmin, UnknownNN
385AD FS detected that one or more certificates in AD FS configuration database …AdminNN
385AD FS detected that one or more certificates in AD FS configuration database …UnknownNN
386AD FS detected that none of the service certificates that are configured to be …AdminYN
386AD FS detected that none of the service certificates that are configured to be …UnknownYN
387AD FS detected that one or more of the certificates specified in the Federation …AdminNN
387AD FS detected that one or more of the certificates specified in the Federation …UnknownNN
388AD FS detected that all the service certificates have appropriate access given …AdminYN
388AD FS detected that all the service certificates have appropriate access given …UnknownYN
389AD FS detected that one or more of your trusts require their certificates to be …Admin, UnknownNN
390AD FS detected that none of the partner certificates that are configured to be …AdminYN
390AD FS detected that none of the partner certificates that are configured to be …UnknownYN
392The federation server proxy was able to successfully renew its trust with the …Admin, UnknownNN
393The federation server proxy could not establish a trust with the Federation …Admin, UnknownNN
394The federation server proxy could not renew its trust with the Federation …Admin, UnknownNN
395The trust between the federation server proxy and the Federation Service was …Admin, UnknownNN
396The trust between the federation server proxy and the Federation Service was …Admin, UnknownNN
397The federation server loaded the HTTP proxy configuration from WinHTTP settings.AdminYN
397The federation server loaded the HTTP proxy configuration from WinHTTP settingsUnknownYN
398AD FS detected that one or more certificates in the AD FS configuration database …Admin, UnknownNN
399AD FS detected that none of the service certificates that are configured to be …AdminYN
399AD FS detected that none of the service certificates that are configured to be …UnknownYN
400VSS writer permissions have been granted to user data1.AdminNN
400VSS writer permissions have been granted to userUnknownNN
401VSS writer permissions have been revoked from user data1.AdminNN
401VSS writer permissions have been revoked from userUnknownNN
402Failed to add some of the certificate claimsAdmin, UnknownNN
407Password change failed for following user.AdminNN
407Password change failed for following user:UnknownNN
414An error occurred during processing of a token requestAdmin, UnknownNN
415task_0415AdminNN
415Event ID 415UnknownNN
416Web configuration error: data1.AdminNN
416Web configuration error:UnknownNN
417Unable to add the certificate claim data1.AdminNN
417Unable to add the certificate claimUnknownNN
418The trust between the federation server proxy and the Federation Service was …Admin, UnknownNN
419Unable to renew the trust between the federation server proxy and the Federation …Admin, UnknownNN
420The trust between the federation server proxy and the Federation Service was …Admin, UnknownNN
421The trust between the federation server proxy and the Federation Service could …Admin, UnknownNN
432Error handling request from proxy at data1.AdminNN
432Error handling request from proxy atUnknownNN
433Error encountered while renewing trust with the federation server proxyAdmin, UnknownNN
434The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) …Admin, UnknownNN
435The primary AD FS token signing certificate ( thumbprint data1 ) will expire at …Admin, UnknownNN
436The primary AD FS token decryption certificate ( thumbprint data1 ) will expire …Admin, UnknownNN
437Error encountered while checking for pending certificate rolloversAdmin, UnknownNN
438Error encountered while checking rollover status of the AD FS certificate …Admin, UnknownNN
439Error encountered while attempting to read an enrollment certificate from a …Admin, UnknownNN
440A Certificate Authority Enrollment Certificate was foundAdmin, UnknownNN
441A token with a bad token binding key was foundAdmin, UnknownNN
442The CA enrollment certificate management cycle was initiatedAdmin, UnknownNN
443The CA enrollment certificate management cycle was completedAdmin, UnknownNN
444Error encountered while checking status of the AD FS enrollment certificateAdmin, UnknownNN
445A token with no binding was received on a request which is token-binding-capableAdmin, UnknownNN
446An SSO token with no binding was received on a request which is …Admin, UnknownNN
447Error encountered while attempting to update the configuration policy for the …AdminNN
447Error encountered while attempting to update the configuration policy for the …UnknownNN
448Error encountered while attempting to add a leased task to the databaseAdmin, UnknownNN
449Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask …Admin, UnknownNN
450Error encountered while removing the expired items from the usercode cacheAdmin, UnknownNN
451Following nodes have the reported heartbeat older than data1 UTC and will be …AdminYN
451Following nodes have the reported heartbeat older than Event.EventData UTC and …UnknownYN
452task_0452AdminNN
452Event ID 452UnknownNN
500More information for the event entry with Instance ID data1.AdminNN
500More information for the event entry with Instance IDUnknownNN
501More information for the event entry with Instance ID Event.EventData.AdminYN
501More information for the event entry with Instance IDUnknownYN
502More information for the event entry with Instance ID data1.AdminNN
502More information for the event entry with Instance IDUnknownNN
503More information for the event entry with Instance ID data1.AdminNN
503More information for the event entry with Instance IDUnknownNN
504The following update was successful to the application proxy store on the …Admin, UnknownNN
505The following update attempt to the application proxy store on the federation …Admin, UnknownNN
506The following update attempt to the application proxy relying party trust on the …Admin, UnknownNN
507The following update attempt to the application proxy relying party trust on the …Admin, UnknownNN
508The following update attempt to the relying party trust on the federation server …Admin, UnknownNN
509The following update attempt to the relying party trust on the federation server …Admin, UnknownNN
510More information for the event entry with Instance ID data1.AdminNN
510More information for the event entry with Instance IDUnknownNN
511The incoming sign-in request is not allowed due to an invalid Federation Service …Admin, UnknownNN
517The incoming sign-in request is not allowed due to an invalid Federation Service …Admin, UnknownNN
521The request for the relying party token resulted in a failureAdmin, UnknownNN
530AD FS could not read the local claims provider trusts from the AD FS …Admin, UnknownNN
531AD FS could not read the local claims provider trusts from the AD FS …Admin, UnknownNN
540The Federation Service was was unable to return the OAuth discovery document as …Admin, UnknownNN
541An invalid value was found during processing of the proxy configuration data …Admin, UnknownNN
542There was an error during heartbeatAdmin, UnknownNN
543There was an error during heartbeat communicating to primary federation serverAdmin, UnknownNN
544Heartbeat is not performed because primary server does not support heartbeatAdmin, UnknownNN
545Heartbeat is performed at primary server.AdminYN
545Heartbeat is performed at primary serverUnknownYN
546A current tenant certificate for Azure MFA was not foundAdmin, UnknownNN
547The tenant certificate for Azure MFA has been renewedAdmin, UnknownNN
548The tenant certificate for Azure MFA will expire soonAdmin, UnknownNN
549The tenant certificate for Azure MFA has expiredAdmin, UnknownNN
550The data1 primary certificate cannot be used because the KeySpec must have a …Admin, UnknownNN
551An error occurred during processing of an OAuth logout requestAdmin, UnknownNN
552The session cookies were successfully deleted using the OAuth logout path.AdminYN
552The session cookies were successfully deleted using the OAuth logout pathUnknownYN
553The specified redirect URL was validated successfullyAdmin, UnknownNN
554The specified redirect URL did not match any of the OAuth client's redirect …AdminYN
554The specified redirect URL did not match any of the OAuth client's redirect URIsUnknownYN
555The Windows Hello for Business key receipt could not be verifiedAdmin, UnknownNN
556Error encountered while attempting to select a master node for the account storeAdmin, UnknownNN
557An error occured while trying to communicate with the account store rest service …AdminNN
557An error occured while trying to communicate with the account store rest service …UnknownNN
558Syncronization of the Account Activity data failedAdmin, UnknownNN
559Device authentication using PKeyAuth failedAdmin, UnknownNN
560User data1 could not be found in the account databaseAdmin, UnknownNN
561Authorization failed when connecting to the account store endpoint on server …AdminNN
561Authorization failed when connecting to the account store endpoint on serverUnknownNN
562An error occurred when communcating with the account store endpoint on server …AdminNN
562An error occurred when communcating with the account store endpoint on serverUnknownNN
563An error occurred while calculating extranet lockout statusAdmin, UnknownNN
564The banned IP list found in MicrosoftAdmin, UnknownNN
565An error occurred while attemtping to update the database schema for Adfs smart …Admin, UnknownNN
566An error occurred during processing of an OAuth device code requestAdmin, UnknownNN
568An error occurred during processing of an OAuth device auth request with the …AdminNN
568An error occurred during processing of an OAuth device auth request with the …UnknownNN
570Active Directory trust enumeration was unable to enumerate one of more domains …Admin, UnknownNN
571Enumeration of the Active Directory domains failedAdmin, UnknownNN
572The Active Directory suffix from this username is not trusted by this ADFS …Admin, UnknownNN
573The following error was generated by a threat detection moduleAdmin, UnknownNN
574A threat detection module failed to loadAdmin, UnknownNN
575The following threat detection module was successfully loaded.AdminYN
575The following threat detection module was successfully loadedUnknownYN
576An unexpected error was returned from a threat detection moduleAdmin, UnknownNN
1000An error occurred during processing of a token request.AdminYN
1000An error occurred during processing of a token requestUnknownYN
1020Encountered error during OAuth authorization request.AdminYN
1020Encountered error during OAuth authorization requestUnknownYN
1021Encountered error during OAuth token request.AdminYN
1021Encountered error during OAuth token requestUnknownYN
1080An error occurred while processing WebFinger requestAdmin, UnknownNN
1100The Federation Service could not authorize a request to one of the REST …Admin, UnknownNN
1109The Federation Service failed to connect to the LDAP account store to …AdminNN
1109The Federation Service failed to connect to the LDAP account store to …UnknownNN
1110The Federation Service failed to connect to the primary LDAP account store to …AdminNN
1110The Federation Service failed to connect to the primary LDAP account store to …UnknownNN
1111The Federation Service failed to connect to all LDAP account stores to …AdminNN
1111The Federation Service failed to connect to all LDAP account stores to …UnknownNN
1112The Federation Service failed to connect to the Ldap serverAdmin, UnknownNN
1113Client Json Web Key Set (JWKS) synchronization initiated.AdminYN
1113Client Json Web Key Set (JWKS) synchronization initiatedUnknownYN
1114Client Json Web Key Set (JWKS) synchronization completed.AdminYN
1114Client Json Web Key Set (JWKS) synchronization completedUnknownYN
1115The Federation Service encountered an error while retrieving the Json Web Key …Admin, UnknownNN
1116An error occurred during a read operation from the configuration databaseAdmin, UnknownNN
1117An error occurred during monitoring of the following client's Json Web Key Set …Admin, UnknownNN
1118An error occurred during monitoring of clients'Json Web Key Set (JWKS)Admin, UnknownNN
1130There was an error establishing or renewing the proxy trustAdmin, UnknownNN
1131There was an error establishing or renewing the trust between the proxy and STSAdmin, UnknownNN

Event ID 100: The Federation Service started successfully.

#
Channel
Admin
Level
Informational

Description

The Federation Service started successfully. The following service hosts have been added.

Message #

The Federation Service started successfully. The following service hosts have been added: 
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:54.297871+00:00",
    "event_record_id": 34,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Federation Server Proxy ServiceHost\r\nhttps://adfs.ludus.domain:443/adfs/services/proxytrustpolicystoretransfer\r\n\r\nMSIS0014: AD FS 1.x Trust Information Service\r\nhttps://adfs.ludus.domain/adfs/fs/federationserverservice.asmx\r\n\r\nIssuance ServiceHost\r\nhttp://localhost:80/adfs/services/trust/mexsoap\r\nhttps://adfs.ludus.domain:443/adfs/services/trust/proxymex/\r\n\r\nIssuance ServiceHost\r\nhttp://localhost/adfs/services/trust/proxymexsoap\r\nhttps://adfs.ludus.domain:443/adfs/services/trust/proxymex/\r\n\r\nIssuance ServiceHost\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/windowstransport\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/certificatemixed\r\nhttps://certauth.adfs.ludus.domain/adfs/services/trust/2005/certificatetransport\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/usernamemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/kerberosmixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/issuedtokenmixedasymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/issuedtokenmixedsymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/kerberosmixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/certificatemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/usernamemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/issuedtokenmixedasymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/issuedtokenmixedsymmetricbasic256\r\nnet.tcp://localhost/adfs/services/trusttcp/windows\r\n\r\nSAML Metadata\r\nhttps://adfs.ludus.domain/FederationMetadata/2007-06/\r\n\r\nOther endpoints\r\n\r\nhttp://+:80/adfs/users/\r\nhttps://+:443/adfs/oauth2/authorize/\r\nhttps://+:443/adfs/ls/\r\nhttps://+:443/adfs/oauth2/logout/\r\nhttps://+:443/adfs/oauth2/token/\r\nhttps://+:443/adfs/certauth/oauth2/authorize/\r\nhttps://+:443/adfs/certauth/\r\nhttps://+:443/adfs/oauth2/\r\nhttps://+:443/adfs/oauth2/deviceauth/\r\nhttp://+:80/adfs/deviceflowresult/\r\nhttp://+:80/adfs/artifact/\r\nhttps://+:443/adfs/discovery/\r\nhttps://+:443/adfs/.well-known/\r\nhttps://+:443/.well-known/webfinger/\r\nhttps://+:443/adfs/userinfo/\r\nhttps://+:443/adfs/Proxy/EstablishTrust/\r\nhttps://+:443/adfs/backendproxytls/\r\nhttps://+:443/adfs/Proxy/\r\nhttp://+:80/adfs/Proxy/PrimaryWriter/\r\nhttps://+:443/adfs/portal/\r\nhttp://+:80/adfs/probe/\r\n"
      }
    }
  },
  "message": ""
}

Event ID 100: The Federation Service started successfully

#
Channel
Unknown

Description

The Federation Service started successfully. The following service hosts have been added.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 100,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:12.3574440+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 102: There was an error in enabling endpoints of Federation Service.

#
Channel
Admin
Level
Error

Description

There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Message #

There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service. 

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 102,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:11:11.158613+00:00",
    "event_record_id": 292,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 11500
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "System.ServiceModel.FaultException`1[Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault]: ADMIN0012: OperationFault (Fault Detail is equal to Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault)."
      }
    }
  },
  "message": ""
}

Event ID 102: There was an error in enabling endpoints of Federation Service

#
Channel
Unknown
Level
2

Description

There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 102,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:12:50.2286277+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "System.ServiceModel.FaultException`1[Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault]: ADMIN0012: OperationFault (Fault Detail is equal to Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault)."
  }
}

Example keys not documented in the fields table: EventData

Event ID 103: The Federation Service stopped successfully.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 103,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:04:06.374579+00:00",
    "event_record_id": 36,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 103: The Federation Service stopped successfully

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 103,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:32:28.4194277+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 104: The artifact resolution service is not running

#
Channel
Admin, Unknown

Description

The artifact resolution service is not running. The service must be running to perform token replay detection.

Message #

The artifact resolution service is not running. The service must be running to perform token replay detection. 

User Action 
Make sure that the artifact resolution service is configured properly. Or disable token replay detection by using the Set-ADFSProperties cmdlet with the PreventTokenReplays parameter in Windows PowerShell for AD FS.

Event ID 105: An error occurred loading an authentication provider

#
Channel
Admin, Unknown

Description

An error occurred loading an authentication provider. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Message #

An error occurred loading an authentication provider. Fix configuration errors using PowerShell cmdlets and restart the Federation Service. 
Identifier: %1 
Context: %2 

Additional Data 
Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 106: An authentication provider was successfully loaded: Identifier: 'Event.EventData', Context: 'data1'.

#
Channel
Admin
Level
Informational

Message #

An authentication provider was successfully loaded: Identifier: '%1', Context: '%2'

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 106,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:54.076793+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "FormsAuthentication",
          "Passive protocol pipeline"
        ]
      }
    }
  },
  "message": ""
}

Event ID 106: An authentication provider was successfully loaded: Identifier: 'data1', Context: 'data2'

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 106,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:12.3403827+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 111: The Federation Service encountered an error while processing the WS-Trust request

#
Channel
Admin, Unknown

Message #

The Federation Service encountered an error while processing the WS-Trust request. 
Request type: %1 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 131: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

#
Channel
Admin

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The configured value 'data2' could not be parsed as type 'data3'.

Message #

During processing of the Federation Service  configuration, the element '%1' was found to have invalid data. The configured value '%2' could not be parsed as type '%3'. 
Element: %1 
Value: %2 
Type: %3 

The Federation Service will not be able to start until this configuration element is corrected. 

User Action 
Correct the specified configuration element to conform to the given type.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 131: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data

#
Channel
Unknown

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The configured value 'data2' could not be parsed as type 'data3'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 132: During processing of the Federation Service configuration, the required element 'data1' was missing

#
Channel
Admin, Unknown

Message #

During processing of the Federation Service configuration, the required element '%1' was missing. 
Element: %1 

The Federation Service will not be able to start until this configuration element is configured. 

User Action 
Configure the specified configuration element using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString

Event ID 133: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data

#
Channel
Admin, Unknown

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The private key for the certificate that was configured could not be accessed. The following are the values of the certificate: 
Element: %1 
Subject: %2 
Thumbprint: %3 
storeName: %4 
storeLocation: %5 
Federation Service identity: %6 

The Federation Service will not be able to start until this configuration element is corrected. 

This condition can occur when the certificate is found in the specified store but there is a problem accessing the certificate's private key. Common causes for this condition include the following: 
(1) The certificate was installed from a source that did not include the private key, such as a .cer or .p7b file. 
(2) The certificate's private key was imported (for example, from a .pfx file) into a store that is different from the store specified above. 
(3) The certificate was generated as part of a certificate request that did not specify the "Machine Key" option. 
(4) The Federation Service identity '%6' has not been granted read access to the certificate's private key. 

User Action 
If the certificate was imported from a source with no private key, choose a certificate that does have a private key, or import the certificate again from a source that includes the private key (for example, a .pfx file). 

If the certificate was imported in a user context, verify that the store specified above matches the store the certificate was imported into. 

If the certificate was generated by a certificate request that did not specify the "Machine Key" option and the key is marked as exportable, export the certificate with a private key from the user store to a .pfx file and import it again directly into the store specified in the configuration file. If the key is not marked as exportable, request a new certificate using the "Machine Key" option. 

If the Federation Service identity has not been granted read access to the certificate's private key, correct this condition using the Certificates  snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 134: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data

#
Channel
Admin, Unknown

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' could not be found.

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The certificate that was identified by the findValue '%2' could not be found. 
Element: %1 
storeName: %3 
storeLocation: %4 
x509FindType: %5 
findValue: %2 

The Federation Service will not be able to start until this configuration element is corrected. 

This condition occurs when the findValue that is specified does not match any certificate in the specified store. Common causes for this condition include the following: 
(1) The certificate with the specified findValue is from a store that is different from the configured store. 
(2) The certificate was deleted from the store after configuration. 

User Action 
If the certificate exists in a different store, find the location using the certificates snap-in and correct the configuration appropriately. 

If the certificate has been deleted, configure a different certificate.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 135: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data

#
Channel
Admin, Unknown

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' was not unique.

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The certificate that was identified by the findValue '%2' was not unique. 
Element: %1 
storeName: %3 
storeLocation: %4 
x509FindType: %5 
findValue: %2 

The Federation Service will not be able to start until this configuration element is corrected. 

This condition can occur when the certificate is found in the specified store but there is more than one certificate that matches the findValue. 

User Action 
If the certificate was identified by name and there are multiple certificates of the same name, configure the certificate using the certificate thumbprint.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 136: During processing of the Federation Service configuration, the Federation Service encountered a configuration error

#
Channel
Admin, Unknown

Message #

During processing of the Federation Service configuration, the Federation Service encountered a configuration error. 

%1 

Additional Data 
%2 

The Federation Service will not be able to start until this error has been corrected. 

User Action 
Correct the specified configuration error using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 143: The Federation Service was unable to create the federation metadata document as a result of an error

#
Channel
Admin, Unknown

Message #

The Federation Service was unable to create the federation metadata document as a result of an error. 
Document Path: %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 144: The Federation Service Proxy blocked an illegitimate request made by a client, as there was no matching endpoint registered at the proxy.

#
Channel
Admin

Message #

The Federation Service Proxy blocked an illegitimate request made by a client, as there was no matching  endpoint registered at the proxy. This could point to a DNS misconfiguration, a partially configured application  published through the proxy, or a malicious request. 
Url Path: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 144: The Federation Service Proxy blocked an illegitimate request made by a client, as there was no matching endpoint registered at the proxy

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 147: A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any ...

#
Channel
Admin

Description

A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any known claims provider trust.

Message #

A token was received from a claims provider identified by the key '%1', but the token could not be validated because the key does not identify any known claims provider trust. 
Key: %1 

This request failed. 

User Action 
If this key represents the certificate thumbprint of a claims provider trust, verify that it  matches the signing certificate of the claims provider trust in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 147: A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any known claims provider trust

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 149: During processing of the Federation Service configuration, the attribute store 'Event.EventData' could not be loaded.

#
Channel
Admin
Level
Error

Message #

During processing of the Federation Service configuration, the attribute store '%1' could not be loaded.  
Attribute store type: %2 

User Action 
If you are using a custom attribute store, verify that the custom attribute store is configured using AD FS Management snap-in. 

Additional Data 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 149,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:31.694542+00:00",
    "event_record_id": 90,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "TestLDAPStore",
          "Microsoft.IdentityServer.ClaimsPolicy.Engine.AttributeStore.Ldap.LdapAttributeStore, Microsoft.IdentityServer.ClaimsPolicy",
          "POLICY3820: The configured connection value 'LDAP://localhost:389' for the 'TestLDAPStore' attribute store is not valid. It must be a valid LDAP:// Uri. Ex:LDAP://fabrikam.com/DC=fabrikam,DC=com"
        ]
      }
    }
  },
  "message": ""
}

Event ID 149: During processing of the Federation Service configuration, the attribute store 'data1' could not be loaded

#
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 149,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:10:24.1548560+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "TestLDAPStoreMicrosoft.IdentityServer.ClaimsPolicy.Engine.AttributeStore.Ldap.LdapAttributeStore, Microsoft.IdentityServer.ClaimsPolicyPOLICY3820: The configured connection value 'LDAP://localhost:389' for the 'TestLDAPStore' attribute store is not valid. It must be a valid LDAP:// Uri. Ex:LDAP://fabrikam.com/DC=fabrikam,DC=com"
  }
}

Example keys not documented in the fields table: EventData

Event ID 155: The Federation Service was unable to listen at 'data1' for metadata document requests due to an unexpected error

#
Channel
Admin, Unknown

Message #

The Federation Service was unable to listen at '%1' for metadata document requests due to an unexpected error. 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 156: Trust monitoring cycle initiated.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 156,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.122193+00:00",
    "event_record_id": 75,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 11600
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 156: Trust monitoring cycle initiated

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 156,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.2381040+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 157: Trust monitoring cycle completed.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 157,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.147700+00:00",
    "event_record_id": 78,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 11600
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 157: Trust monitoring cycle completed

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 157,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.2534333+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 159: The Federation Service encountered an error while writing to the following object in the configuration database

#
Channel
Admin, Unknown

Message #

The Federation Service encountered an error while writing to the following object in the configuration database. 

Object Type: 
%1 

Name: 
%2 

Metadata document URL: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 163: An error occurred during initialization of trust monitoring

#
Channel
Admin, Unknown

Description

An error occurred during initialization of trust monitoring. Trust monitoring against the published partner configuration will be disabled for the lifetime of this service.

Message #

An error occurred during initialization of trust monitoring. Trust monitoring against the published partner configuration will be disabled for the lifetime of this service. 

Additional Data 

Exception details: 
%1 

User Action 
If you want to try to start the trust monitoring service again, restart the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 164: An error occurred during a read operation from the configuration database

#
Channel
Admin, Unknown

Message #

An error occurred during a read operation from the configuration database. Trust monitoring was shut down and will be tried again after an amount of time that corresponds to the trust monitoring interval. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 165: An error occurred during trust monitoring

#
Channel
Admin, Unknown

Description

An error occurred during trust monitoring. The trust monitoring cycle was shut down.

Message #

An error occurred during trust monitoring. The trust monitoring cycle was shut down. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 166: Trust monitoring service encountered an error while parsing the metadata document from 'data1'

#
Channel
Admin, Unknown

Description

Trust monitoring service encountered an error while parsing the metadata document from 'data1'. Trust monitoring failed for.

Message #

Trust monitoring service encountered an error while parsing the metadata document from '%1'. Trust monitoring failed for: 

Object Type: 
%2 

Name: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 167: Trust monitoring service encountered an error while applying the data in the metadata document from 'data1'

#
Channel
Admin, Unknown

Description

Trust monitoring service encountered an error while applying the data in the metadata document from 'data1'. Trust monitoring failed for.

Message #

Trust monitoring service encountered an error while applying the data in the metadata document from '%1'. Trust monitoring failed for: 

Object Type: 
%2 

Name: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 168: The Federation Service encountered an error while retrieving the federation metadata document from 'data1'

#
Channel
Admin, Unknown

Description

The Federation Service encountered an error while retrieving the federation metadata document from 'data1'. The monitoring for the following trusts failed.

Message #

The Federation Service encountered an error while retrieving the federation metadata document from '%1'. The monitoring for the following trusts failed: 

Claims providers: 
%2 

Relying parties: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5 

User Action 
Make sure federation metadata URL is accessible. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 171: The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes

#
Channel
Admin, Unknown

Message #

The trust monitoring service automatically updated the trust of '%1' successfully with the partner's published changes.

Fields #

NameDescription
data1 UnicodeString

Event ID 173: The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes

#
Channel
Admin, Unknown

Message #

The trust monitoring service automatically updated the trust of '%1' successfully with the partner's published changes. 

Additional Data 
Warnings: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 174: Trust monitoring service detected changes in policy of 'data1', but did not automatically apply the changes on the trust partner

#
Channel
Admin, Unknown

Message #

Trust monitoring service detected changes in policy of '%1', but did not automatically apply the changes on the trust partner. 

Additional Data 
Warnings: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 180: An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version 'data2' to Minor Version 'data3'

#
Channel
Admin, Unknown

Message #

An error occurred while upgrading FarmBehaviorLevel '%1' from Minor Version '%2' to Minor Version '%3'. 

Additional Data 
Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 181: AD FS could not enable the new KDFv2 feature automatically because of missing Windows Updates on one or more nodes of the farm

#
Channel
Admin, Unknown

Message #

AD FS could not enable the new KDFv2 feature automatically because of missing Windows Updates on one or more nodes of the farm. Please make sure that all the farm nodes are patched with the latest Windows Updates. AD FS checks regularly for the required updates to enable the new KDFv2 feature. An event 182 will be logged when a check is successful. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 182: AD FS enabled the new KDFv2 feature successfully

#
Channel
Admin, Unknown

Description

AD FS enabled the new KDFv2 feature successfully. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Message #

AD FS enabled the new KDFv2 feature successfully. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 183: KDFv2 feature is disabled on AD FS farm

#
Channel
Admin, Unknown

Message #

KDFv2 feature is disabled on AD FS farm. Please make sure that all the farm nodes are patched with latest Windows Updates and the KDFv2 feature is enabled to enhance the security of the farm. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 184: A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identi...

#
Channel
Admin

Description

A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identify any known relying party trust.

Message #

A token request was received for a relying party identified by the key '%1', but the request could not be fulfilled because the key does not identify any known relying party trust. 
Key: %1 

This request failed. 

User Action 
If this key represents a URI for which a token should be issued, verify that its prefix matches the relying party trust that is configured in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 184: A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identify any known relying party trust

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 186: The Federation Service could not fulfill the token-issuance request

#
Channel
Admin, Unknown

Message #

The Federation Service could not fulfill the token-issuance request. More than  one claim based on SamlNameIdentifierClaimResource was produced after the issuance  transform rules were applies for relying party '%2'. See event 500 with the same Instance ID for claims after application of issuance transform rules. 

Additional Data 
Instance ID: %1 

User Action 
Ensure that the issuance transform rules that are configured for the relying party do not result in multiple claims based on SamlNameIdentifierClaimResource.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 187: AD FS server received a JWT token without nonce in the assertion and it was accepted based on the current configuration setting of EnforceNonceInJWT

#
Channel
Admin, Unknown

Message #

AD FS server received a JWT token without nonce in the assertion and it was accepted based on the current configuration setting of EnforceNonceInJWT. However, it indicates a potential replay of the JWT token by a malicious client or the possibility that the client is not patched with latest Windows Updates. Please make sure to update the EnforceNonceInJWT setting to reject all such JWT tokens after patching the clients with latest Windows Updates. 
For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2238156. 

Additional Data 
    Client IP: %1 
    User Agent: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 188: AD FS server is not configured to reject JWT tokens that did not have nonce in the assertion.

#
Channel
Admin

Message #

AD FS server is not configured to reject JWT tokens that did not have nonce in the assertion. The corresponding setting (EnforceNonceInJWT) should be enabled for security reasons after making sure that all the clients are patched with the latest Windows Updates. 
The event 187 indicates the instances where AD FS received such tokens and accepted due to the current setting of EnforceNonceInJWT. 
For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2238156.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 188,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:12.3532216+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 188: AD FS server is not configured to reject JWT tokens that did not have nonce in the assertion

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 188,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:12.3532216+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 189: AD FS server received an OAuth authorization request in the device code flow without a Cross Site Request Forgery (CSRF) protection code in the Use...

#
Channel
Admin

Message #

AD FS server received an OAuth authorization request in the device code flow without a Cross Site Request Forgery (CSRF) protection code in the UserCode cookie. This indicates that the AD FS server that issued the UserCode cookie has not  been patched with the latest Windows security updates. It is recommended to install the latest Windows security updates  on all the AD FS servers of the farm in order to be protected from CSRF attacks. Your environment is currently vulnerable  to the CSRF attacks in OAuth device code flow due to one or more unpatched AD FS servers. 

Additional Data 
    Usercode: %1 
    Client IP: %2 
    User Agent: %3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 189: AD FS server received an OAuth authorization request in the device code flow without a Cross Site Request Forgery (CSRF) protection code in the UserCode cookie

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 193: The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type

#
Channel
Admin, Unknown

Message #

The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type. 
Comparison type: %1 
Desired authentication type(s): %2 
Relying party: %3 

This request failed. 

User Action 
Use the AD FS PowerShell commands to configure the authentication context order property. 
Ensure that the relying party is configured to request the correct authentication type.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 197: The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of '%...

#
Channel
Admin

Description

The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'data2' for the relying party 'data3'.

Message #

The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of '%2' for the relying party '%3'. 
Authentication type: %1 
Desired authentication type(s): %2 
Relying party: %3 

This request failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 197: The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'data2' for the relying party 'data3'

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 198: The federation server proxy started successfully

#
Channel
Admin, Unknown

Event ID 199: The federation server proxy could not be started

#
Channel
Admin, Unknown

Message #

The federation server proxy could not be started. 
Reason: %1 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 200: The federation server proxy stopped successfully

#
Channel
Admin, Unknown

Event ID 201: The Federation Service data1 encountered an Access Denied error while trying to register one or more endpoint URLs

#
Channel
Admin, Unknown

Message #

The Federation Service %1 encountered an Access Denied error while trying to register one or more endpoint URLs. This condition typically occurs when the ACL for the endpoint URL is missing or the HTTP namespace in the ACL is not a prefix match of the endpoint URL. 

 The %1 could not be opened. 

User Action 
Ensure that a valid ACL for each of the URLs has been configured on this computer. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 202: The Federation Service data1 could not be opened

#
Channel
Admin, Unknown

Message #

The Federation Service %1 could not be opened. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 203: The Federation Service data1 could not be shut down properly

#
Channel
Admin, Unknown

Message #

The Federation Service %1 could not be shut down properly. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 204: The Federation Service data1 could not be closed

#
Channel
Admin, Unknown

Message #

The Federation Service %1 could not be closed. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 206: The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint addr...

#
Channel
Admin

Description

The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint address.

Message #

The Federation Service could not fulfill the token-issuance request because the relying party '%1' is missing a WS-Federation Passive endpoint address. 
Relying party: %1 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure a WS-Federation Passive endpoint on this relying party.

Fields #

NameDescription
data1 UnicodeString

Event ID 206: The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint address

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 207: An attempt to write to the Security event log failed

#
Channel
Admin, Unknown

Message #

An attempt to write to the Security event log failed. 

Additional Data 
Windows error code: %1 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 208: An error occurred during an attempt to register the event source for the Security log

#
Channel
Admin, Unknown

Message #

An error occurred during an attempt to register the event source for the Security log.  

User Action 
Ensure that the Federation Service has the correct permissions to write to the Security log.

Event ID 209: The Security log event source for the Federation Service could not be registered

#
Channel
Admin, Unknown

Message #

The Security log event source for the Federation Service could not be registered. 

Additional Data 
Windows error code: %1 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 215: The Federation Service at 'data1' did not return any WS-Trust endpoints to be published by the federation server proxy

#
Channel
Admin, Unknown

Message #

The Federation Service at '%1' did not return any WS-Trust endpoints to be published by the federation server proxy. 

User Action 
If you want to publish WS-Trust endpoints to the federation server proxy, make sure that the endpoints are enabled for proxy use on the federation server.

Fields #

NameDescription
data1 UnicodeString

Event ID 217: A WS-Trust endpoint that was configured could not be opened

#
Channel
Admin, Unknown

Message #

A WS-Trust endpoint that was configured could not be opened. 

Additional Data 
Address: %1 
Mode: %2 

Error: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 218: The federation server proxy received error code 'data2' while making a request to the Federation Service at 'data1'

#
Channel
Admin, Unknown

Description

The federation server proxy received error code 'data2' while making a request to the Federation Service at 'data1'. This could mean that the Federation Service is not started on the remote host.

Message #

The federation server proxy received error code '%2' while making a request to the Federation Service at '%1'. This could mean that the Federation Service is not started on the remote host. 

User Action 
Verify that the Federation Service is running on the remote host.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 220: The Federation Service configuration could not be loaded correctly from the AD FS configuration database.

#
Channel
Admin
Level
Error

Message #

The Federation Service configuration could not be loaded correctly from the AD FS configuration database. 

Additional Data 
Error:  
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 220,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:11:11.159207+00:00",
    "event_record_id": 297,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 11500
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "ADMIN0012: OperationFault"
      }
    }
  },
  "message": ""
}

Event ID 220: The Federation Service configuration could not be loaded correctly from the AD FS configuration database

#
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 220,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:12:50.2296755+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "ADMIN0012: OperationFault"
  }
}

Example keys not documented in the fields table: EventData

Event ID 221: A change to the token service configuration was detected, but there was an error reloading the changes to configuration.

#
Channel
Admin
Level
Error

Message #

A change to the token service configuration was detected, but there was an error reloading the changes to configuration. 

Additional Data 
Error:  
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 221,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:10:50.898809+00:00",
    "event_record_id": 229,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 8536
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "ADMIN0012: OperationFault"
      }
    }
  },
  "message": ""
}

Event ID 221: A change to the token service configuration was detected, but there was an error reloading the changes to configuration

#
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 221,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:12:50.2295701+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "ADMIN0012: OperationFault"
  }
}

Example keys not documented in the fields table: EventData

Event ID 222: The federation server proxy was unable to complete a request to the Federation Service at address 'data1' because of a time-out

#
Channel
Admin, Unknown

Description

The federation server proxy was unable to complete a request to the Federation Service at address 'data1' because of a time-out. This might mean that the Federation Service is currently unavailable.

Message #

The federation server proxy was unable to complete a request to the Federation Service at address '%1' because of a time-out. This might mean that the Federation Service is currently unavailable. 

User Action 
Verify that the Federation Service is running.

Fields #

NameDescription
data1 UnicodeString

Event ID 223: Claim description could not be loaded correctly from the database

#
Channel
Admin, Unknown

Message #

Claim description could not be loaded correctly from the database. 

Additional Data 
Error:  
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 224: The federation server proxy configuration could not be updated with the latest configuration on the federation service

#
Channel
Admin, Unknown

Message #

The federation server proxy configuration could not be updated with the latest configuration on the federation service. 

Additional Data 
Error:  
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 225: A change to the service configuration was detected, but there was an error reloading the changes to data1.

#
Channel
Admin

Message #

A change to the service configuration was detected, but there was an error reloading the changes to %1. 

Additional Data 
Error:  
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 225: A change to the service configuration was detected, but there was an error reloading the changes to

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 230: The federation server proxy has detected congestion, caused by high latency response times, on the Federation Service

#
Channel
Admin, Unknown

Message #

The federation server proxy has detected congestion, caused by high latency response times, on the Federation Service. The load might be above the Federation Service operating capacity, or there might be network connectivity issues. Request throttling has been enforced to limit the number of concurrent requests to the following size: %1. 

User Action 
Verify that the Federation Service is operating within its operating capacity. 
Verify that the Federation Service is not experiencing network outages.

Fields #

NameDescription
data1 UnicodeString

Event ID 238: The Federation Service failed to find a domain controller for the domain data1.

#
Channel
Admin

Message #

The Federation Service failed to find a domain controller for the domain %1. 

Additional Data 
Domain Name: %1 
Error: %2 

User Action 
Use Nltest to determine why DC locator is failing. Nltest is part of the Windows Support Tools.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 238: The Federation Service failed to find a domain controller for the domain

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 244: The Federation Service was unable to listen at 'data1' for WS-MetadataExchange requests due to an unexpected error

#
Channel
Admin, Unknown

Message #

The Federation Service was unable to listen at '%1' for WS-MetadataExchange requests due to an unexpected error. 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 245: The federation server proxy successfully retrieved and updated its configuration from the Federation Service 'data1'

#
Channel
Admin, Unknown

Message #

The federation server proxy successfully retrieved and updated its configuration from the Federation Service '%1'.

Fields #

NameDescription
data1 UnicodeString

Event ID 246: The Federation Service encountered an error during an attempt to connect to a LDAP server at data1.

#
Channel
Admin

Message #

The Federation Service encountered an error during an attempt to connect to a LDAP server at %1. 

Additional Data 
Domain Name: %1 
LDAP server hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from LDAP server (if available): %7 
Exception Details: 
 %8 

User Action 
 Check the network connectivity to the LDAP server. Also, check whether the LDAP server is configured properly.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 246: The Federation Service encountered an error during an attempt to connect to a LDAP server at

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 247: The Federation Service encountered an error while connecting to a global catalog server at data1.

#
Channel
Admin

Message #

The Federation Service encountered an error while connecting to a global catalog server at %1. 

Additional Data 
Domain Name: %1 
Global Catalog hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from server (if available): %7 
Exception Details: 
 
 %8 

User Action 
Troubleshoot the network connectivity to the global catalog server. Also, verify that the global catalog server is configured properly.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 247: The Federation Service encountered an error while connecting to a global catalog server at

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 248: The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1.

#
Channel
Admin

Description

The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1. The error message is 'data2'.

Message #

The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at %1. The error message is '%2'. 

User Action 
Make sure that the Federation Service is running. Troubleshoot network connectivity. If the trust between the federation server proxy and the Federation Service is lost, run the Federation Server Proxy Configuration Wizard again.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 248: The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at

#
Channel
Unknown

Description

The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1. The error message is 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 249: The certificate identified by thumbprint 'data1' could not be found in the certificate store

#
Channel
Admin, Unknown

Message #

The certificate identified by thumbprint '%1' could not be found in the certificate store.  In certificate rollover scenarios, this can potentially cause a failure when the Federation Service is signing or decrypting using this certificate. 

User Action 
Ensure that the certificate that is identified by thumbprint '%1' has been added to the Localmachine "My" store and that it is accessible by the service account of the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 250: Expiration of the artifact failed.

#
Channel
Admin

Message #

Expiration of the artifact failed. 

Additional Data 
Exception message: 
%1 

User Action 
Ensure that the artifact storage server is configured properly. Troubleshoot network connectivity to the artifact storage server.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 250,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-06T11:31:03.4208627+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 250: Expiration of the artifact failed

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 250,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-06T11:31:03.4208627+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 251: Attribute store 'Event.EventData' is loaded successfully.

#
Channel
Admin
Level
Informational

Message #

Attribute store '%1' is loaded successfully.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 251,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:52.787344+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Active Directory"
      }
    }
  },
  "message": ""
}

Event ID 251: Attribute store 'data1' is loaded successfully

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 251,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:10.8344846+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 252: The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service

#
Channel
Admin, Unknown

Message #

The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service. 

Endpoints added: 
%1 

Endpoints removed: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 253: AD FS proxy service failed to start a listener for the endpoint 'data1'

#
Channel
Admin, Unknown

Message #

AD FS proxy service failed to start a listener for the endpoint '%1' 
Exceptiondetails: 
%2 

User action: Ensure that no conflicting SSL bindings are configured for the specified endpoint.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 258: The relying party 'data1' is not configured with SAML Assertion Consumer Services

#
Channel
Admin, Unknown

Message #

The relying party '%1' is not configured with SAML Assertion Consumer Services. 
Relying party: %1 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure one or more Assertion Consumer Services for this relying party.

Fields #

NameDescription
data1 UnicodeString

Event ID 259: The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'.

#
Channel
Admin

Message #

The request specified an Assertion Consumer Service index '%1' that is not  configured on the relying party '%2'. 
Assertion Consumer Service index: %1 
Relying party: %2 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an Assertion Consumer Service with the specified index for this relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 259: The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'

#
Channel
Unknown

Description

The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 260: The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'.

#
Channel
Admin

Message #

The request specified an Assertion Consumer Service protocol binding '%1' that is not  configured on the relying party '%2'. 
Assertion Consumer Service protocol binding: %1 
Relying party: %2 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an Assertion Consumer Service with the specified protocol binding for this relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 260: The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'

#
Channel
Unknown

Description

The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 261: The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'.

#
Channel
Admin

Message #

The request specified an Assertion Consumer Service URL '%1' that is not  configured on the relying party '%2'. 
Assertion Consumer Service URL: %1 
Relying party: %2 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an Assertion Consumer Service with the specified URL for this relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 261: The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'

#
Channel
Unknown

Description

The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 262: The artifact resolution request failed

#
Channel
Admin, Unknown

Message #

The artifact resolution request failed. 

Additional Data 
Exception message: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 273: The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'.

#
Channel
Admin

Message #

The request specified an assertion consumer service  that is not  configured or not supported on the relying party '%4'. 
Request parameters: '%1', '%2', '%3' 
Relying party: %4 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an assertion consumer service with the specified parameters for this relying party. Also, check whether the artifact resolution service is enabled if the SAML artifact is requested.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 273: The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'

#
Channel
Unknown

Description

The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 274: The federation server proxy encountered an error while trying to listen on one of the proxy endpoints

#
Channel
Admin, Unknown

Message #

The federation server proxy encountered an error while trying to listen on one of the proxy endpoints.  The federation server proxy will not be able to start until it can listen on all required proxy endpoints. 
Proxy Endpoints: 
 
%1 

User Action 
Ensure that the permissions on the URLs of the proxy endpoints allow the federation server proxy security account (the default is Network Service) to listen on them.

Fields #

NameDescription
data1 UnicodeString

Event ID 275: The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service data1.

#
Channel
Admin

Message #

The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service %1. 
Error Message: 
%2 

User Action 
Ensure that the SSL certificate for Federation Service '%1' is valid and trusted by the federation server proxy.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 275: The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 276: The federation server proxy was not able to authenticate to the Federation Service

#
Channel
Admin, Unknown

Message #

The federation server proxy was not able to authenticate to the Federation Service. 

User Action 
Ensure that the proxy is trusted by the Federation Service. To do this, log on to the proxy computer with the host name that is identified in the certificate subject name and re-establish trust between the proxy and the Federation Service using the Install-WebApplicationProxy cmdlet. 

Additional Data 

Certificate details: 

Subject Name: 
%1 

Thumbprint: 
%2 

NotBefore Time: 
%3 

NotAfter Time: 
%4 

Client endpoint: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 277: The Federation Service encountered an unexpected exception and has shut down

#
Channel
Admin, Unknown

Message #

The Federation Service encountered an unexpected exception and has shut down. 

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 278: The SAML artifact resolution endpoint is not configured or it is disabled.

#
Channel
Admin
Level
Warning

Message #

The SAML artifact resolution endpoint is not configured or it is disabled. 

User Action 
If SAML artifact resolution is required, use the AD FS Management snap-in to configure or enable the SAML artifact resolution endpoint.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 278,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:53.726364+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 278: The SAML artifact resolution endpoint is not configured or it is disabled

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 278,
    "level": "Warning",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:11.7775437+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 279: Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database

#
Channel
Admin, Unknown

Message #

Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database.  
SAML artifact: %1 

This request failed. 

User Action 
Verify that a claims provider trust exists in the AD FS configuration database. 
Make sure that the data for the claims provider trust is up to date.

Fields #

NameDescription
data1 UnicodeString

Event ID 280: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service config...

#
Channel
Admin

Description

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured.

Message #

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured.  
Claims provider trust: %1 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Add the artifact resolution service endpoint to the claims provider trust.

Fields #

NameDescription
data1 UnicodeString

Event ID 280: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 281: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpo...

#
Channel
Admin

Description

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured.

Message #

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured.  
Claims provider trust: %1 
Required endpoint index: %2 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Use the AD FS Management snap-in to configure the artifact resolution endpoint with the  specified index.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 281: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 283: Unable to resolve the SAML artifact

#
Channel
Admin, Unknown

Description

Unable to resolve the SAML artifact. The artifact resolution request to the claims provider failed. See inner exception for more details.

Message #

Unable to resolve the SAML artifact. The artifact resolution request to the claims provider failed. See inner exception for more details. 
SAML Artifact: %1 
Claims provider: %2 
Inner exception: 
%3 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Verify network connectivity. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 284: Unable to resolve the SAML artifact

#
Channel
Admin, Unknown

Description

Unable to resolve the SAML artifact. A malformed response was received from the claims provider. See inner exception for more details.

Message #

Unable to resolve the SAML artifact. A malformed response was received from the claims provider. See inner exception for more details. 
SAML artifact: %1 
Claims provider: %2 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 285: The SAML artifact was resolved, but the response is empty or does not contain expected assertions

#
Channel
Admin, Unknown

Message #

The SAML artifact was resolved, but the response is empty or does not contain expected assertions. 
SAML artifact: %1 
Claims provider: %2 

This request failed. 

User Action 
For more information, contact the claims provider.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 286: Cannot connect to the artifact database

#
Channel
Admin, Unknown

Message #

Cannot connect to the artifact database. 
Connection string: %1 
Error message: 

%2 

User Action 
Ensure that the artifact database is configured properly. Use the Set-ADFSProperties cmdlet with the ArtifactDbConnection parameter in the Windows PowerShell for AD FS to modify the connection string, if necessary. 
Troubleshoot the connectivity to the artifact storage .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 287: Cannot add the artifact to the artifact database

#
Channel
Admin, Unknown

Description

Cannot add the artifact to the artifact database. See exception message for more details.

Message #

Cannot add the artifact to the artifact database. See exception message for more details. 
Artifact ID: %1 
Inner exception details: 
%2 

User Action 
Ensure that the artifact database is configured properly.  
Troubleshoot the connectivity to the artifact database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 288: Cannot get the artifact from storage

#
Channel
Admin, Unknown

Description

Cannot get the artifact from storage. See exception message for more details.

Message #

Cannot get the artifact from storage. See exception message for more details. 
ArtifactId: %1 
Inner exception details: 
%2 

User Action 
Ensure that the artifact storage in the AD FS configuration database is configured properly.  
Troubleshoot connectivity to the artifact storage in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 289: Cannot remove the artifact from storage

#
Channel
Admin, Unknown

Description

Cannot remove the artifact from storage. See inner exception message for more details.

Message #

Cannot remove the artifact from storage. See inner exception message for more details. 
ArtifactId: %1 
Inner exception details: 
%2 

User Action 
Ensure that the artifact storage in the AD FS configuration database is configured properly.  
Troubleshoot connectivity to the artifact storage in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 290: Cannot set expiration for the artifacts in storage

#
Channel
Admin, Unknown

Description

Cannot set expiration for the artifacts in storage. See inner exception message for more details.

Message #

Cannot set expiration for the artifacts in storage. See inner exception message for more details. 
Inner exception details: 
%1 

User Action 
Ensure that the artifact storage in the AD FS configuration database is configured properly.  
Troubleshoot connectivity to the artifact storage in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 291: The artifact resolution service could not be started

#
Channel
Admin, Unknown

Message #

The artifact resolution service could not be started. 

Additional Data 
Exception details: 
%1 

User Action 
Make sure artifact resolution service is properly configured.

Fields #

NameDescription
data1 UnicodeString

Event ID 293: A SAML request for the required artifact was rejected because the artifact resolution service is not enabled

#
Channel
Admin, Unknown

Message #

A SAML request for the required artifact was rejected because the artifact resolution service is not enabled. 
Relying party: %1 

This request failed. 

User Action 
Enable the artifact resolution service. 
Use the AD FS Management snap-in to configure or enable the SAML artifact resolution endpoint.

Fields #

NameDescription
data1 UnicodeString

Event ID 294: The SAML artifact resolution request specified an issuer that is not configured for the relying party

#
Channel
Admin, Unknown

Message #

The SAML artifact resolution request specified an issuer that is not configured for the relying party. 
Relying party: %1 
Artifact resolution request issuer: %2 

This artifact resolution request failed. 

User Action 
Ensure that the relying party is configured properly using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 297: The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured

#
Channel
Admin, Unknown

Message #

The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured. 
Endpoint index: %1 
Configured endpoint index: %2 

This artifact resolution request failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 298: The Windows Hello for Business key receipt certificate background task will not run.

#
Channel
Admin
Level
Informational

Message #

The Windows Hello for Business key receipt certificate background task will not run. 

Additional Information: %1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 298,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.107600+00:00",
    "event_record_id": 71,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13100
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "ServiceState.IsDrsInitialized is false."
      }
    }
  },
  "message": ""
}

Event ID 298: The Windows Hello for Business key receipt certificate background task will not run

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 298,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:31:52.8156192+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 302: The Federation Service could not authorize token issuance for caller 'data2' as subject 'data3' to the relying party 'data4'.

#
Channel
Admin

Message #

The Federation Service could  not authorize token issuance for caller '%2' as subject '%3' to the relying party '%4'. See event 501 with the same Instance ID for caller identity. See event 503 with the same Instance ID for ActAs identity, if any. 

Additional Data 
Instance ID: %1 
Relying party: %4 
Exception details: 
%5 
User Action 
Use the AD FS Management snap-in to ensure that the caller is authorized to act as the subject to the relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 302: The Federation Service could not authorize token issuance for caller 'data2' as subject 'data3' to the relying party 'data4'

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 303: The Federation Service encountered an error while processing the SAML authentication request

#
Channel
Admin, Unknown

Message #

The Federation Service encountered an error while processing the SAML authentication request. 

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 305: The Federation Service encountered an error while querying a LDAP server at data1.

#
Channel
Admin

Message #

The Federation Service encountered an error while querying a LDAP server at %1. 

Additional Data 
Domain name: %1 
LDAP server hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from LDAP server (if available): %7 
Exception Details: 
 %8

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 305: The Federation Service encountered an error while querying a LDAP server at

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 306: The Federation Service encountered an error while querying a global catalog server at data1.

#
Channel
Admin

Message #

The Federation Service encountered an error while querying a global catalog server at %1. 

Additional Data 
Domain name: %1 
Global catalog server hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from server (if available): %7 
Exception Details: 
 
 %8

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 306: The Federation Service encountered an error while querying a global catalog server at

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 311: An attempt to update AD FS performance counters failed

#
Channel
Admin, Unknown

Message #

An attempt to update AD FS performance counters failed.  

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 315: An error occurred during an attempt to build the certificate chain for the claims provider trust 'data1' certificate identified by thumbprint 'data2'

#
Channel
Admin, Unknown

Message #

An error occurred during an attempt to build the certificate chain for the claims provider trust '%1' certificate identified by thumbprint '%2'. Possible causes are that the certificate has been revoked, the certificate chain could not be verified as specified by the claims provider trust's signing certificate revocation settings or certificate is not within its validity period. 

You can use Windows PowerShell commands for AD FS to configure the revocation settings for the claims provider trust's signing certificate. 
Claims provider trust's signing certificate revocation settings: %3 
The following errors occurred while building the certificate chain:  
%4 

User Action: 
Ensure that the claims provider trust's signing certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 316: An error occurred during an attempt to build the certificate chain for the relying party trust 'data1' certificate identified by thumbprint 'data2'

#
Channel
Admin, Unknown

Message #

An error occurred during an attempt to build the certificate chain for the relying party trust '%1' certificate identified by thumbprint '%2'. Possible causes are that the certificate has been revoked, the certificate chain could not be verified as specified by the relying party trust's signing certificate revocation settings or certificate is not within its validity period. 

You can use Windows PowerShell commands for AD FS to configure the revocation settings for the relying party signing certificate. 
Relying party trust's signing certificate revocation settings: %3 
The following errors occurred while building the certificate chain:  
%4 

User Action: 
Ensure that the relying party trust's signing certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 317: An error occurred during an attempt to build the certificate chain for the relying party trust 'Event.EventData' certificate identified by thumbprint 'data1'.

#
Channel
Admin
Level
Error

Message #

An error occurred during an attempt to build the certificate chain for the relying party trust '%1' certificate identified by thumbprint '%2'. Possible causes are that the certificate has been revoked, the certificate chain could not be verified as specified by the relying party trust's encryption certificate revocation settings or certificate is not within its validity period. 

You can use Windows PowerShell commands for AD FS to configure the revocation settings for the relying party encryption certificate. 
Relying party trust's encryption certificate revocation settings: %3 
The following errors occurred while building the certificate chain:  
%4 

User Action: 
Ensure that the relying party trust's encryption certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 317,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:09:23.681803+00:00",
    "event_record_id": 208,
    "correlation": {
      "ActivityID": "88CEECE0-7882-41D3-9B05-08A1D8CE3B05"
    },
    "execution": {
      "process_id": 13608,
      "thread_id": 14296
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "https://testrp3.example.com/oauth",
          "DB0FEA9B641F3814FC5168AE83EF7839AF1BB012",
          "CheckChainExcludeRoot",
          "The certificate is revoked.\r\n\r\n"
        ]
      }
    }
  },
  "message": ""
}

Event ID 317: An error occurred during an attempt to build the certificate chain for the relying party trust 'data1' certificate identified by thumbprint 'data2'

#
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 317,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:09:23.6818033+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "https://testrp3.example.com/oauthDB0FEA9B641F3814FC5168AE83EF7839AF1BB012CheckChainExcludeRootThe certificate is revoked.\n\n"
  }
}

Example keys not documented in the fields table: EventData

Event ID 319: An error occurred while the certificate chain for the client certificate identified by thumbprint 'data1' was being built

#
Channel
Admin, Unknown

Message #

An error occurred while the certificate chain for the client certificate identified by thumbprint '%1' was being built. The certificate chain could not be built. The certificate has been revoked, the certificate chain could not be verified as specified by the encryption certificate revocation settings or certificate is not within its validity period. 

You can use the Set-ADFSProperties cmdlet with the ProxyCertRevocationCheck parameter in Windows PowerShell for AD FS to configure the client certificate revocation settings. 
Client Certificate Revocation Settings: %2 
The following errors occurred while building the certificate chain:  
%3 

User Action: 
Ensure that the client certificate is valid and has not been revoked. 
Ensure that the Federation Service can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 320: The verification of the SAML message signature failed

#
Channel
Admin, Unknown

Message #

The verification of the SAML message signature failed. 
Message issuer: %1 
Exception details: 
%2 

This request failed. 

User Action 
Verify that the message issuer configuration in the AD FS configuration database is up to date. 
Configure the signing certificate for the specified issuer. 
Verify that the issuer's certificate is up to date. 
Verify the issuer and server message signing requirements.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 321: The SAML authentication request had a NameID Policy that could not be satisfied

#
Channel
Admin, Unknown

Message #

The SAML authentication request had a NameID Policy that could not be satisfied. 
Requestor: %1 
Name identifier format: %2 
SPNameQualifier: %3 
Exception details: 
%4 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure the configuration that emits the required name identifier.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 323: The Federation Service could not authorize token issuance for the caller 'data2' on behalf of the subject 'data3' to the relying party 'data4'.

#
Channel
Admin

Message #

The Federation Service could  not authorize token issuance for the caller '%2' on behalf of the subject '%3' to the relying party '%4'. See event 501 with the same Instance ID for caller identity. See event 502 with the same Instance ID for OnBehalfOf identity, if any. 

Additional Data 
Instance ID: %1 
Exception details: 
%5 
User Action 
Use the Windows PowerShell Get-ADFSClaimsProviderTrust or Get-ADFSRelyingPartyTrust cmdlet to ensure the caller is authorized on behalf of the subject to the relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 323: The Federation Service could not authorize token issuance for the caller 'data2' on behalf of the subject 'data3' to the relying party 'data4'

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 325: The Federation Service could not authorize token issuance for caller 'data1'.

#
Channel
Admin
Level
Error

Message #

The Federation Service could not authorize token issuance for caller '%2'. The caller is not authorized to request a token for the relying party '%3'. See event 501 with the same Instance ID for caller identity. 

Additional Data 
Instance ID: %1 
Relying party: %3 
Exception details: 
%4 
User Action 
Use the AD FS Management snap-in to ensure that the caller is authorized to request a token for the relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 325,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:37.248466+00:00",
    "event_record_id": 96,
    "correlation": {
      "ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "a6f4ff0b-8776-43a4-9be1-6b9bf86e338f",
          "ludus\\domainadmin\r\n",
          "https://testrp1.example.com/saml",
          "Microsoft.IdentityServer.Service.IssuancePipeline.CallerAuthorizationException: MSIS5007: The caller authorization failed for caller identity ludus\\domainadmin for relying party trust https://testrp1.example.com/saml.\r\n   at Microsoft.IdentityModel.Threading.AsyncResult.End(IAsyncResult result)\r\n   at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.ProcessCoreAsyncResult.End(IAsyncResult ar)\r\n   at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.EndProcessCore(IAsyncResult ar, String requestAction, String responseAction, String trustNamespace)"
        ]
      }
    }
  },
  "message": ""
}

Event ID 325: The Federation Service could not authorize token issuance for caller 'data2'

#
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 325,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:09:23.9077724+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "2699b4ab-8f31-4d84-a931-f6e38783fc3bludus\\domainadmin\nhttps://testrp1.example.com/samlMicrosoft.IdentityServer.Service.IssuancePipeline.CallerAuthorizationException: MSIS5007: The caller authorization failed for caller identity ludus\\domainadmin for relying party trust https://testrp1.example.com/saml.\n   at Microsoft.IdentityModel.Threading.AsyncResult.End(IAsyncResult result)\n   at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.ProcessCoreAsyncResult.End(IAsyncResult ar)\n   a..."
  }
}

Example keys not documented in the fields table: EventData

Event ID 326: Failed to load the AD FS claims policy engine using policy type 'data1' User Action Make sure AD FS is installed correctly.

#
Channel
Admin

Description

Failed to load the AD FS claims policy engine using policy type 'data1'.

Message #

Failed to load the AD FS claims policy engine using policy type '%1' 

User Action 
Make sure AD FS is installed correctly.

Fields #

NameDescription
data1 UnicodeString

Event ID 326: Failed to load the AD FS claims policy engine using policy type 'data1'

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 327: An error occurred during processing of the SAML logout request

#
Channel
Admin, Unknown

Message #

An error occurred during processing of the SAML logout request. 

Additional Data 
Caller identity: %1 
Logout initiator identity: %2 
Error message: %3 
Exception details: %4 
User Action 
Ensure that the single logout service is configured properly for this relying party trust or claims provider trust in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 328: The SAML artifact resolution request was resolved, but the response does not contain the expected assertions

#
Channel
Admin, Unknown

Message #

The SAML artifact resolution request was resolved, but the response does not contain the expected assertions. 

Additional Data: 
SAML artifact: %1 
Status code: %2 
SubStatus code: %3 
Status message: %4 

This request failed. 

User Action 
Contact the claims provider for more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 329: The certificate that is identified by thumbprint 'data1' could not be decrypted using the keys for X

#
Channel
Admin, Unknown

Description

The certificate that is identified by thumbprint 'data1' could not be decrypted using the keys for X.509 certificate private key sharing.

Message #

The certificate that is identified by thumbprint '%1' could not be decrypted using the keys for X.509 certificate private key sharing. 

Additional Data: 
X.509 certificate private key sharing diagnosis: %2 

User Action 
You may have to restore all Active Directory objects underneath the specified distinguished name in the diagnostic information above for X.509 certificate private key sharing.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 331: The certificate management service encountered an error during decryption of the keys

#
Channel
Admin, Unknown

Message #

The certificate management service encountered an error during decryption of the keys. 
storeName: %2 
storeLocation: %1 
x509FindType: %4 
findValue: %3 

Additional Data: 
X.509 certificate private key sharing diagnosis: %5  

User Action 
You may have to restore all Active Directory objects underneath the distinguished name that is specified in the diagnosis for X.509 certificate private key sharing above.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 332: The certificate management service encountered an error during encryption of the keys

#
Channel
Admin, Unknown

Message #

The certificate management service encountered an error during encryption of the keys. 
Subject: %1 
Diagnosis: %2 

User Action 
You may have to restore all Active Directory objects underneath the distinguished name that is specified in the diagnosis above for X.509 certificate private key sharing.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 333: The certificate management service encountered an error during database access

#
Channel
Admin, Unknown

Message #

The certificate management service encountered an error during database access. 

Additional Data: 
Diagnosis: %1 

User Action 
Confirm that the SQL store is online.

Fields #

NameDescription
data1 UnicodeString

Event ID 334: Certificate rollover service needs to rollover data1 certificates urgently

#
Channel
Admin, Unknown

Description

Certificate rollover service needs to rollover data1 certificates urgently. Partners will not be able to apply the update in time.

Message #

Certificate rollover service needs to rollover %1 certificates urgently. Partners will not be able to apply the update in time.

Fields #

NameDescription
data1 UnicodeString

Event ID 335: task_0335

#
Channel
Admin
Level
Warning

Message #

%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 335,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:06:25.397047+00:00",
    "event_record_id": 83,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13020
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "MSIS10005: Certificate rollover service has added certificate with thumbprint '7D951E82355227B06C62677CAA93C92BCC9FD7BC' to 'Signing' certificate collection. See https://go.microsoft.com/fwlink/?linkid=861845 for more information."
      }
    }
  },
  "message": ""
}

Event ID 335

#
Channel
Unknown
Level
3

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 335,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:06:25.3970562+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "MSIS10004: Certificate rollover service has set certificate with thumbprint '7D951E82355227B06C62677CAA93C92BCC9FD7BC' as primary 'Signing' certificate. See https://go.microsoft.com/fwlink/?linkid=861845 for more information."
  }
}

Example keys not documented in the fields table: EventData

Event ID 336: The certificate management cycle was initiated.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 336,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.117752+00:00",
    "event_record_id": 72,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13136
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 336: The certificate management cycle was initiated

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 336,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.2192666+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 337: The certificate management cycle was completed.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 337,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.300723+00:00",
    "event_record_id": 81,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13136
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 337: The certificate management cycle was completed

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 337,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.3938107+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 338: An error was encountered during certificate rollover

#
Channel
Admin, Unknown

Description

An error was encountered during certificate rollover. The monitoring cycle was shut down.

Message #

An error was encountered during certificate rollover. The monitoring cycle was shut down. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 339: An error occurred during initialization of certificate rollover

#
Channel
Admin, Unknown

Description

An error occurred during initialization of certificate rollover. Certificates will not be rolled over.

Message #

An error occurred during initialization of certificate rollover. Certificates will not be rolled over. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 341: The NotBefore attribute for the token has a value that is set to a future time

#
Channel
Admin, Unknown

Description

The NotBefore attribute for the token has a value that is set to a future time. See inner exception for more details.

Message #

The NotBefore attribute for the token has a value that is set to a future time. See inner exception for more details. 

Additional Data 

Token Type: 
%1 

Exception details: 
%2 

This request failed. 

User Action 
Verify that system clock is synchronized.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 342: Token validation failed.

#
Channel
Admin
Level
Error

Message #

Token validation failed.  

Additional Data 

Token Type: 
%1 
%Error message: 
%2 

Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 342,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:36.815386+00:00",
    "event_record_id": 95,
    "correlation": {
      "ActivityID": "FCDC6F25-76F3-4BC2-B0EB-7EFEBD19BD6C"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 11496
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "http://schemas.microsoft.com/ws/2006/05/identitymodel/tokens/UserName",
          "fakeuser-The user name or password is incorrect",
          "System.IdentityModel.Tokens.SecurityTokenValidationException: fakeuser ---> System.ComponentModel.Win32Exception: The user name or password is incorrect\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserInfo(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String authenticationType, String issuerName)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUser(String domain, String username, String password, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String issuerName)\r\n   at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)\r\n   --- End of inner exception stack trace ---\r\n   at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)\r\n   at Microsoft.IdentityServer.Service.Tokens.MsisLocalCpUserNameSecurityTokenHandler.ValidateTokenInternal(UsernameAuthenticationContext usernameAuthenticationContext, SecurityToken token)\r\n   at Microsoft.IdentityServer.Service.Tokens.MsisLocalCpUserNameSecurityTokenHandler.ValidateToken(SecurityToken token)\r\n\r\nSystem.ComponentModel.Win32Exception (0x80004005): The user name or password is incorrect\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserInfo(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String authenticationType, String issuerName)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUser(String domain, String username, String password, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String issuerName)\r\n   at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)"
        ]
      }
    }
  },
  "message": ""
}

Event ID 342: Token validation failed

#
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 342,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:07:36.8153864+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "http://schemas.microsoft.com/ws/2006/05/identitymodel/tokens/UserNamefakeuser-The user name or password is incorrectSystem.IdentityModel.Tokens.SecurityTokenValidationException: fakeuser ---> System.ComponentModel.Win32Exception: The user name or password is incorrect\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\n   at Microsoft.IdentityServe..."
  }
}

Example keys not documented in the fields table: EventData

Event ID 343: There was an error during initialization of synchronization

#
Channel
Admin, Unknown

Description

There was an error during initialization of synchronization. Synchronization of data from the primary federation server to the secondary federation server will not occur.

Message #

There was an error during initialization of synchronization. Synchronization of data from the primary federation server to the secondary federation server will not occur. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 344: There was an error doing synchronization

#
Channel
Admin, Unknown

Description

There was an error doing synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.

Message #

There was an error doing synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur. 

Additional data 

Exception details: 
%1 

User Action 
 Make sure the primary federation server is available or the service account identity of this machine matches the service account identity of the primary federation server.

Fields #

NameDescription
data1 UnicodeString

Event ID 345: There was a communication error during AD FS configuration database synchronization

#
Channel
Admin, Unknown

Description

There was a communication error during AD FS configuration database synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.

Message #

There was a communication error during AD FS configuration database synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur. 

Additional Data 

Master Name : %1 
Endpoint Uri : %2 
Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 346: There was an error during retrieving the configuration data for the secondary federation server

#
Channel
Admin, Unknown

Message #

There was an error during retrieving the configuration data for the secondary federation server. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 348: Synchronization of configuration data from the primary federation server 'data1' is completed

#
Channel
Admin, Unknown

Description

Synchronization of configuration data from the primary federation server 'data1' is completed. data2 objects were added. data3 objects were deleted.

Message #

Synchronization of configuration data from the primary federation server '%1' is completed. %2 objects were added. %3 objects were deleted.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 349: The administration service for the Federation Service started successfully.

#
Channel
Admin
Level
Informational

Message #

The administration service for the Federation Service started successfully. You can now use the Windows Powershell commands for AD FS to modify the Federation Service configuration. The following service hosts have been added: 
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 349,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:51.927998+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Policy Administration ServiceHost\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nhttp://adfs.ludus.domain:80/adfs/services/policystoretransfer\r\nnet.tcp://localhost:1501/adfs/services/policystoretransfer\r\n\r\n"
      }
    }
  },
  "message": ""
}

Event ID 349: The administration service for the Federation Service started successfully

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 349,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:10.3652052+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 351: There was an error getting synchronization properties

#
Channel
Admin, Unknown

Message #

There was an error getting synchronization properties. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 352: A SQL operation in the AD FS configuration database with connection string Event.EventData failed.

#
Channel
Admin
Level
Error

Message #

A SQL operation in the AD FS configuration database with connection string %1 failed.  

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 352,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:10:50.887915+00:00",
    "event_record_id": 228,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 8536
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "Data Source=np:\\\\.\\pipe\\microsoft##wid\\tsql\\query;Initial Catalog=AdfsConfigurationV4;Integrated Security=True",
          "Login failed for user 'ludus\\svc_adfs'."
        ]
      }
    }
  },
  "message": ""
}

Event ID 352: A SQL operation in the AD FS configuration database with connection string data1 failed

#
Channel
Unknown
Level
2

Description

A SQL operation in the AD FS configuration database with connection string failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 352,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:12:50.2294719+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "Data Source=np:\\\\.\\pipe\\microsoft##wid\\tsql\\query;Initial Catalog=AdfsConfigurationV4;Integrated Security=TrueLogin failed for user 'ludus\\svc_adfs'."
  }
}

Example keys not documented in the fields table: EventData

Event ID 353: Unable to resolve the SAML artifact

#
Channel
Admin, Unknown

Description

Unable to resolve the SAML artifact. Verification of the artifact response signature failed.

Message #

Unable to resolve the SAML artifact. Verification of the artifact response signature failed. 
Claims provider: %1 
Exception details: 
%2 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Verify that the claims provider trust's signing certificate is up to date.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 354: The artifact resolution service could not verify the request signature

#
Channel
Admin, Unknown

Message #

The artifact resolution service could not verify the request signature. 

Additional Data 
Exception details: 
%1 

User action: 
Verify that the relying party trust in the AD FS configuration database is up to date. 
Configure the relying party certificate for request signing. 
Verify that relying party certificate is up to date.

Fields #

NameDescription
data1 UnicodeString

Event ID 356: Failed to register notification to the SQL database with the connection string data1 for cache type 'data2'

#
Channel
Admin, Unknown

Description

Failed to register notification to the SQL database with the connection string data1 for cache type 'data2'. Changes to settings may not take effect until the Federation Service restarts.

Message #

Failed to register notification to the SQL database with the connection string %1 for cache type '%2'. Changes to settings may not take effect until the Federation Service restarts. 

Additional Data 

Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 357: Successfully registered notification to the SQL database with the connection string data1.

#
Channel
Admin

Message #

Successfully registered notification to the SQL database with the connection string %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 357: Successfully registered notification to the SQL database with the connection string

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 358: Restarting Event.EventData.

#
Channel
Admin
Level
Warning

Message #

Restarting %1. This restart is necessary because a change was detected in the certificates that this service host uses. Requests that are served by endpoints of this service host may fail during restart.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 358,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:06:25.236927+00:00",
    "event_record_id": 82,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13020
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Issuance ServiceHost"
      }
    }
  },
  "message": ""
}

Event ID 358: Restarting

#
Channel
Unknown
Level
3

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 358,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:06:25.5672417+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "Issuance ServiceHost"
  }
}

Example keys not documented in the fields table: EventData

Event ID 359: An error occurred during an attempt to restart data1.

#
Channel
Admin

Message #

An error occurred during an attempt to restart %1. 

Additional Data 

Exception details: 
%2 

User Action 
 Restart the Federation Service to recover from the error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 359: An error occurred during an attempt to restart

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 360: A request was made to a certificate transport endpoint, but the request did not include a client certificate

#
Channel
Admin, Unknown

Message #

A request was made to a certificate transport endpoint, but the request did not include a client certificate. This could be because the root CA certificate that issued the client certificate is not in the Trust CA certificate store or because the client certificate is expired. 

User Action: 
Ensure that the CA that issued the client certificate in this request has its certificate in the Trusted Root Certificate Authority store on the Local Computer. 
Ensure that the client certificate is not expired.

Event ID 362: Encountered error during federation passive sign-out

#
Channel
Admin, Unknown

Message #

Encountered error during federation passive sign-out. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 363: A communication error occurred during an attempt to get a token from the Federation Service

#
Channel
Admin, Unknown

Description

A communication error occurred during an attempt to get a token from the Federation Service. Make sure that the Federation Service is running.

Message #

A communication error occurred during an attempt to get a token from the Federation Service. Make sure that the Federation Service is running. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 364: Encountered error during federation passive request.

#
Channel
Admin
Level
Error

Message #

Encountered error during federation passive request. 

Additional Data 

Protocol Name: 
%1 

Relying Party: 
%2 

Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 364,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:52.936421+00:00",
    "event_record_id": 109,
    "correlation": {
      "ActivityID": "E915B92E-2E46-4CB5-0900-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "OAuthAuthorizationProtocol",
          "",
          "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\r\n   at Microsoft.IdentityServer.Web.Protocols.ProtocolContext.Validate()\r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationProtocolHandler.GetRequiredPipelineBehaviors(ProtocolContext pContext)\r\n   at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context)\r\n\r\n"
        ]
      }
    }
  },
  "message": ""
}

Event ID 364: Encountered error during federation passive request

#
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 364,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:08:53.1123197+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "OAuthAuthorizationProtocolMicrosoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\n   at Microsoft.IdentityServer.Web.Protocols.P..."
  }
}

Example keys not documented in the fields table: EventData

Event ID 365: A token request was received for the relying party 'data1', but the request could not be fulfilled because the relying party trust is not enabled

#
Channel
Admin, Unknown

Message #

A token request was received for the relying party '%1', but the request could not be fulfilled because the relying party trust is not enabled. 
Relying party: %1 

This request failed. 

User Action 
If this relying party trust should be enabled, enable it by using the AD FS Management snap-in or Windows PowerShell for AD FS.

Fields #

NameDescription
data1 UnicodeString

Event ID 366: A token was received from claims provider 'data1', but the token could not be validated because the claims provider trust is not enabled

#
Channel
Admin, Unknown

Message #

A token was received from claims provider '%1', but the token could not be validated because the claims provider trust is not enabled. 
Claims provider: %1 

This request failed. 

User Action 
If this claims provider trust should be enabled, enable it by using the AD FS Management snap-in or Windows PowerShell for AD FS.

Fields #

NameDescription
data1 UnicodeString

Event ID 367: The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federati...

#
Channel
Admin

Description

The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federation Service.

Message #

The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federation Service. 

User Action 
See the exception details for the audience identifier that failed validation. If the audience identifier identifies this Federation Service, add the audience identifier to the acceptable identifiers list by using Windows PowerShell for AD FS.  Note that the audience identifier is used to verify whether the token was sent to this Federation Service. If you think that the audience identifier does not identify your Federation Service, adding it to the acceptable identifiers list may open a security vulnerability in your system. 

Additional Data 

Token Type: 
%1 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 367: The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federation Service

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 368: The SAML Single Logout request does not correspond to the logged-in session participant

#
Channel
Admin, Unknown

Message #

The SAML Single Logout request does not correspond to the logged-in session participant. 
Requestor: %1 
Request name identifier: %2 
Logged-in session participants: 
%3  

This request failed. 

User Action 
Verify that the claim provider trust or the relying party trust configuration is up to date. If the name identifier in the request is different from the name identifier in the session only by NameQualifier or SPNameQualifier, check and correct the name identifier policy issuance rule using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 369: Processing TTP request failed with the following exception

#
Channel
Admin, Unknown

Message #

Processing TTP request failed with the following exception. 

Additional Data 

Exception details: 
%1 

User Action 
Ensure that user has enabled cookies in browser settings.

Fields #

NameDescription
data1 UnicodeString

Event ID 370: Incoming TTP response is not valid

#
Channel
Admin, Unknown

Description

Incoming TTP response is not valid. Processing response failed with following exception.

Message #

Incoming TTP response is not valid. Processing response failed with following exception. 

Additional Data 

Exception details: 
%1 

User Action 
Ensure that partner federation provider is configured properly to send valid TTP response.

Fields #

NameDescription
data1 UnicodeString

Event ID 371: Cannot find certificate to validate message/token signature obtained from claims provider

#
Channel
Admin, Unknown

Message #

Cannot find certificate to validate message/token signature obtained from claims provider. 
Claims provider: %1 

This request failed. 

User Action 
Check that Claim Provider Trust configuration is up to date.

Fields #

NameDescription
data1 UnicodeString

Event ID 372: Authentication Failed

#
Channel
Admin, Unknown

Description

Authentication Failed. The token used to authenticate the user is signed using a weaker signature algorithm than expected.

Message #

Authentication Failed. The token used to authenticate the user is signed using a weaker signature algorithm than expected. 

Additional Data 
 Token Type: %1 
 Issuer: %2 
 Actual token signature algorithm: %3 
 Expected token signature algorithm: %4  

User Action 
Check that Claim Provider is configured to accept tokens with expected signature algorithm.  
Use the AD FS PowerShell commands to configure the signature algorithm property.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 373: The artifact request from the replying party is signed with a weaker signature algorithm

#
Channel
Admin, Unknown

Message #

The artifact request from the replying party is signed with a weaker signature algorithm. 

Additional Data 
Relying party identity: %1 
Actual message signature algorithm: %2 
Expected message signature algorithm: %3 

User action: 
Check that relying party is configured to accept artifact resolution request with expected signature algorithm. 
Use the AD FS PowerShell commands to configure the signature algorithm property.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 374: An error occurred while building the certificate chain for the claims provider trust 'data1' certificate identified by thumbprint 'data2'

#
Channel
Admin, Unknown

Message #

An error occurred while building the certificate chain for the claims provider trust '%1' certificate identified by thumbprint '%2'.  The certificate chain could not be built, the certificate has been revoked, or the certificate chain could not be verified as specified by the claims provider trust's encryption certificate revocation settings. 

AD FS powershell commands can be used to configure the claims provider trust encryption certificate revocation settings. 
Claims Provider Trust Encryption Certificate Revocation Settings: %3 
The following errors occurred while building the certificate chain:  
%4 
User Action: 
Ensure that the claims provider trust's encryption certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 375: Policy store synchronization initiated

#
Channel
Admin, Unknown

Event ID 376: An Error occurred while executing a query in SQL attribute store

#
Channel
Admin, Unknown

Message #

An Error occurred while executing a query in SQL attribute store. 

Additional Data 
 Connection information: %1 
 Query: %2 
 Parameters: %3 

User Action 
Examine the exception details to take one or more of the following actions if applicable. 
  Verify that the connection string to the SQL attribute store is valid. 
  Make sure that the SQL attribute store can be reached by the connection string and the SQL attribute store exists. 
  Verify that the SQL query and parameters are valid. 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 377: A processing error occurred in an attribute store

#
Channel
Admin, Unknown

Message #

A processing error occurred in an attribute store. 

User Action 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 378: SAML request is not signed with expected signature algorithm

#
Channel
Admin, Unknown

Description

SAML request is not signed with expected signature algorithm. SAML request is signed with signature algorithm data1 . Expected signature algorithm is data2.

Message #

SAML request is not signed with expected signature algorithm. SAML request is signed with signature algorithm %1 . Expected signature algorithm is %2 

User Action: 
Verify that signature algorithm for the partner is configured as expected.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 379: A security token was rejected as the specified IssueInstant was before the allowed time frame

#
Channel
Admin, Unknown

Message #

A security token was rejected as the specified IssueInstant was before the allowed time frame. 

Token Type: 
%1 

User Action: 
 To allow tokens for a larger timeframe, use the AD FS PowerShell commands to adjust the value of the ReplayCacheExpirationInterval.

Fields #

NameDescription
data1 UnicodeString

Event ID 380: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data

#
Channel
Admin, Unknown

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The certificate that was configured could not be used. The certificate has been revoked, the certificate chain could not be verified or certificate is not within its validity period. The following are the values of the certificate: 
Element: %1 
Subject: %2 
Thumbprint: %3 

The Federation Service will not be able to start until this configuration element is corrected. 

User Action 
Verify whether the certificate chain for the certificate configured has been revoked by its certificate authority. 
If the certificate has been revoked or expired, the AD FS service must be issued a new certificate.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 381: An error occurred during an attempt to build the certificate chain for configuration certificate identified by thumbprint 'data1'

#
Channel
Admin, Unknown

Message #

An error occurred during an attempt to build the certificate chain for configuration certificate identified by thumbprint '%1'. Possible causes are that the certificate has been revoked or certificate is not within its validity period. 
The following errors occurred while building the certificate chain:  
%2 

User Action: 
Ensure that the certificate is valid and has not been revoked or expired.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 382: AD FS detected that the Federation Service has more than data1 data2 trusts configured and that the data in the AD FS configuration database for this Fed...

#
Channel
Admin

Message #

AD FS detected that the Federation Service has more than %1 %2 trusts configured and that the data in the AD FS configuration database for this Federation Service is stored and synchronized using Windows Internal Database technology. The overall performance of data synchronization between configuration databases that are stored locally on federation servers across the farm will degrade as you add more than %1 trusts when you use the Windows Internal Database to store the AD FS configuration database. 

User Action: 
To improve synchronization performance across your federation server farm, we recommend that you migrate the data in the AD FS configuration database to SQL server. For more information about how to do this, see AD FS Operations Guide (http://go.microsoft.com/fwlink/?LinkId=181189).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 382: AD FS detected that the Federation Service has more than data1 data2 trusts configured and that the data in the AD FS configuration database for this Federation Service is stored and synchronized u...

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 383: The Web request failed because the web

#
Channel
Admin, Unknown

Description

The Web request failed because the web.config file is malformed.

Message #

The Web request failed because the web.config file is malformed. 

User Action: 
Fix the malformed data in the web.config file. 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 384: The request to the Federation Service failed because the web

#
Channel
Admin, Unknown

Description

The request to the Federation Service failed because the web.config file has an invalid configuration for 'data1' that the Federation Service does not support.

Message #

The request to the Federation Service failed because the web.config file has an invalid  configuration for '%1' that the Federation Service does not support. 

User Action: Ensure that the configuration of the property '%1' is supported by the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 385: AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire s...

#
Channel
Admin

Description

AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon. See additional details for more information.

Message #

AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon. See additional details for more information 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 385: AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon

#
Channel
Unknown

Description

AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon. See additional details for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 386: AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 386,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.125743+00:00",
    "event_record_id": 76,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 9156
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 386: AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 386,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T20:13:14.5591807+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 387: AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD F...

#
Channel
Admin

Description

AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service.

Message #

AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service. 

User Action: Ensure that the AD FS service account has read permissions on the certificate private keys. 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 387: AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 388: AD FS detected that all the service certificates have appropriate access given to the AD FS service account.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 388,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.126174+00:00",
    "event_record_id": 77,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 11756
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 388: AD FS detected that all the service certificates have appropriate access given to the AD FS service account

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 388,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:44:12.3999854+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 389: AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon

#
Channel
Admin, Unknown

Description

AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon. See additional details for more information.

Message #

AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon. See additional details for more information 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 390: AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 390,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.154591+00:00",
    "event_record_id": 79,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 9156
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 390: AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 390,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T20:13:14.5760402+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 392: The federation server proxy was able to successfully renew its trust with the Federation Service

#
Channel
Admin, Unknown

Message #

The federation server proxy was able to successfully renew its trust with the Federation Service.  

Proxy trust certificate subject: %1. 
Proxy trust certificate old thumbprint: %2. 
Proxy trust certificate new thumbprint: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 393: The federation server proxy could not establish a trust with the Federation Service

#
Channel
Admin, Unknown

Message #

The federation server proxy could not establish a trust with the Federation Service. 

Additional Data 
Exception details: 
%1 

User Action 
Ensure that the credentials being used to establish a trust between the federation server proxy and the Federation Service are valid and that the Federation Service can be reached.

Fields #

NameDescription
data1 UnicodeString

Event ID 394: The federation server proxy could not renew its trust with the Federation Service

#
Channel
Admin, Unknown

Message #

The federation server proxy could not renew its trust with the Federation Service.  

Additional Data 
Exception details: 
%1 

User Action 
Ensure that the federation server proxy is trusted by the Federation Service. If the trust does not exist or has been revoked, establish a trust between the proxy and the Federation Service using the Federation Service Proxy Configuration Wizard by logging on to the proxy computer.

Fields #

NameDescription
data1 UnicodeString

Event ID 395: The trust between the federation server proxy and the Federation Service was established successfully using the account 'data1'

#
Channel
Admin, Unknown

Message #

The trust between the federation server proxy and the Federation Service was established successfully using the account '%1'. 

Proxy trust certificate subject: %2. 
Proxy trust certificate thumbprint: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 396: The trust between the federation server proxy and the Federation Service was renewed successfully

#
Channel
Admin, Unknown

Message #

The trust between the federation server proxy and the Federation Service was renewed successfully. 

Proxy trust certificate subject: %1. 
Proxy trust certificate old thumbprint: %2. 
Proxy trust certificate new thumbprint: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 397: The federation server loaded the HTTP proxy configuration from WinHTTP settings.

#
Channel
Admin
Level
Informational

Message #

The federation server loaded the HTTP proxy configuration from WinHTTP settings. 

HTTP Proxy: %1 
HTTPS Proxy: %2 
Bypass proxy for local addresses: %3 
Bypass proxy for addresses: %4 

To learn more about how to set the HTTP proxy settings for the federation server, see http://go.microsoft.com/fwlink/?LinkId=182180.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 397,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:50.877782+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 12484
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "",
          "",
          "",
          "\r\n"
        ]
      }
    }
  },
  "message": ""
}

Event ID 397: The federation server loaded the HTTP proxy configuration from WinHTTP settings

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 397,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:09.5969961+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 398: AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived

#
Channel
Admin, Unknown

Message #

AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived. 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 399: AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 399,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.121989+00:00",
    "event_record_id": 74,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 9156
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 399: AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 399,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T20:13:14.5561015+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 400: VSS writer permissions have been granted to user data1.

#
Channel
Admin

Message #

VSS writer permissions have been granted to user %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 400: VSS writer permissions have been granted to user

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 401: VSS writer permissions have been revoked from user data1.

#
Channel
Admin

Message #

VSS writer permissions have been revoked from user %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 401: VSS writer permissions have been revoked from user

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 402: Failed to add some of the certificate claims

#
Channel
Admin, Unknown

Event ID 407: Password change failed for following user.

#
Channel
Admin

Message #

Password change failed for following user: 

Additional Data 

User: 
%1 

Server on which password change was attempted: 
%2 
Error details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 407: Password change failed for following user:

#
Channel
Unknown

Description

Password change failed for following user.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 414: An error occurred during processing of a token request

#
Channel
Admin, Unknown

Description

An error occurred during processing of a token request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.

Message #

An error occurred during processing of a token request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.  

Additional Data 

Activity ID:
 %1 

Target Relying Party:
 %2 

Is Application Proxy Configured:
 %3 

Is Request From the Extranet:
 %4 

User action: 
Use the Activity ID data in this message to search and correlate the data to events in the Event log using Event Viewer. This Activity ID will also be shown as additional information in the error page when an error occurs in the federation passive Web application.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 415: task_0415

#
Channel
Admin

Message #

%1

Fields #

NameDescription
data1 UnicodeString

Event ID 415

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 416: Web configuration error: data1.

#
Channel
Admin

Message #

Web configuration error: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 416: Web configuration error:

#
Channel
Unknown

Description

Web configuration error.

Fields #

NameDescription
data1 UnicodeString

Event ID 417: Unable to add the certificate claim data1.

#
Channel
Admin

Message #

Unable to add the certificate claim %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 417: Unable to add the certificate claim

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 418: The trust between the federation server proxy and the Federation Service was successfully renewed

#
Channel
Admin, Unknown

Message #

The trust between the federation server proxy and the Federation Service was successfully renewed. 

Additional Data 

Server from which request was made: 
%1 
Certificate Subject: 
%2 
Old Certificate Thumbprint: 
%3 
New Certificate Thumbprint: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 419: Unable to renew the trust between the federation server proxy and the Federation Service

#
Channel
Admin, Unknown

Message #

Unable to renew the trust between the federation server proxy and the Federation Service. 

Additional Data 

Server from which request was made: 
%1 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 420: The trust between the federation server proxy and the Federation Service was successfully established

#
Channel
Admin, Unknown

Message #

The trust between the federation server proxy and the Federation Service was successfully established. 

Additional Data 

User: 
%1 

Server from which request was made: 
%2 
Certificate Subject: 
%3 
Certificate Thumbprint: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 421: The trust between the federation server proxy and the Federation Service could not be established

#
Channel
Admin, Unknown

Message #

The trust between the federation server proxy and the Federation Service could not be established. 

Additional Data 

User: 
%1 

Server from which request was made: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 432: Error handling request from proxy at data1.

#
Channel
Admin

Message #

Error handling request from proxy at %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 432: Error handling request from proxy at

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 433: Error encountered while renewing trust with the federation server proxy

#
Channel
Admin, Unknown

Message #

Error encountered while renewing trust with the federation server proxy.  

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 434: The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) will expire at data2 UTC

#
Channel
Admin, Unknown

Message #

The primary AD FS certificate authority issuer certificate ( thumbprint %1 ) will expire at %2 UTC. 
The certificate rollover service will roll over to the current secondary ( thumbprint %3 ) at %4 UTC. 
To avoid certificate issuance service interruption, ensure that the current secondary certificate ( thumbprint %3 ) is installed in Active Directory before the rollover occurs at %4 UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 435: The primary AD FS token signing certificate ( thumbprint data1 ) will expire at data2 UTC

#
Channel
Admin, Unknown

Message #

The primary AD FS token signing certificate ( thumbprint %1 ) will expire at %2 UTC. 
The certificate rollover service will roll over to the current secondary ( thumbprint %3 ) at %4 UTC. 
Relying parties that rely on federation metadata will be notified automatically; any relying parties that do not rely on federation metadata must be informed of the new certificate before the rollover at %4 UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 436: The primary AD FS token decryption certificate ( thumbprint data1 ) will expire at data2 UTC

#
Channel
Admin, Unknown

Message #

The primary AD FS token decryption certificate ( thumbprint %1 ) will expire at %2 UTC. 
The certificate rollover service will roll over to the current secondary ( thumbprint %3 ) at %4 UTC. 
Identity providers that rely on federation metadata will be notified automatically; any identity providers that send encrypted tokens to AD FS and do not rely on federation metadata must be informed of the new certificate before the expiration at %2 UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 437: Error encountered while checking for pending certificate rollovers

#
Channel
Admin, Unknown

Message #

Error encountered while checking for pending certificate rollovers. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC. 
If this issue persists, AD FS will not be able to advise of pending certificate rollover events. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 438: Error encountered while checking rollover status of the AD FS certificate authority issuer certificate

#
Channel
Admin, Unknown

Message #

Error encountered while checking rollover status of the AD FS certificate authority issuer certificate. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC.  Future runs may occur on other farm nodes if AD FS is running in a farm configuration. 
If this issue persists, the AD FS certificate authority issuer certificate cannot be rolled over successfully when it nears expiry. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 439: Error encountered while attempting to read an enrollment certificate from a template

#
Channel
Admin, Unknown

Message #

Error encountered while attempting to read an enrollment certificate from a template. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 440: A Certificate Authority Enrollment Certificate was found

#
Channel
Admin, Unknown

Message #

A Certificate Authority Enrollment Certificate was found. 

Additional Data 

Certificate Thumbprint: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 441: A token with a bad token binding key was found

#
Channel
Admin, Unknown

Message #

A token with a bad token binding key was found. 

Additional Data 

User: %1 
Target RP: %2 
Client IP: %3 
Token Binding ID: %4 
Request Provided ID: %5 
Request Referred ID: %6

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 442: The CA enrollment certificate management cycle was initiated

#
Channel
Admin, Unknown

Event ID 443: The CA enrollment certificate management cycle was completed

#
Channel
Admin, Unknown

Event ID 444: Error encountered while checking status of the AD FS enrollment certificate

#
Channel
Admin, Unknown

Message #

Error encountered while checking status of the AD FS enrollment certificate. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC. 
If this issue persists, the AD FS will not be able to enroll certificate. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 445: A token with no binding was received on a request which is token-binding-capable

#
Channel
Admin, Unknown

Message #

A token with no binding was received on a request which is token-binding-capable.  
This could be evidence of a possible downgrade attack, or it could mean the token originally came from a server that doesn't support token binding. 

Additional Data 

User: %1 
Target RP: %2 
Client IP: %3 
Request Provided ID: %4 
Request Referred ID: %5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 446: An SSO token with no binding was received on a request which is token-binding-capable

#
Channel
Admin, Unknown

Description

An SSO token with no binding was received on a request which is token-binding-capable. This is evidence of a possible downgrade attack.

Message #

An SSO token with no binding was received on a request which is token-binding-capable. This is evidence of a possible downgrade attack.  

Additional Data 

User: %1 
Target RP: %2 
Client IP: %3 
Request Provided ID: %4 
Request Referred ID: %5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 447: Error encountered while attempting to update the configuration policy for the template data1.

#
Channel
Admin

Description

Error encountered while attempting to update the configuration policy for the template data1. If the template is published under machine policy, service might not be able to read it.

Message #

Error encountered while attempting to update the configuration policy for the template %1. If the template is published under machine policy, service might not be able to read it. 
See https://go.microsoft.com/fwlink/?linkid=852318 for more information. 

Exception details: UpdateMachinePolicyConfigurationForTemplate returned error: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 447: Error encountered while attempting to update the configuration policy for the template

#
Channel
Unknown

Description

Error encountered while attempting to update the configuration policy for the template . If the template is published under machine policy, service might not be able to read it.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 448: Error encountered while attempting to add a leased task to the database

#
Channel
Admin, Unknown

Message #

Error encountered while attempting to add a leased task to the database. 

Additional Data: 

Task name: %1 
Error: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 449: Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task

#
Channel
Admin, Unknown

Message #

Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task. 

Additional Data: 

Error: %1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 450: Error encountered while removing the expired items from the usercode cache

#
Channel
Admin, Unknown

Message #

Error encountered while removing the expired items from the usercode cache. 

Additional Data: 

Error: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 451: Following nodes have the reported heartbeat older than data1 UTC and will be deleted.

#
Channel
Admin
Level
Informational

Message #

Following nodes have the reported heartbeat older than %1 UTC and will be deleted. 

%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 451,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-07-03T05:43:30.289319+00:00",
    "event_record_id": 1602,
    "correlation": {},
    "execution": {
      "process_id": 3316,
      "thread_id": 11880
    },
    "channel": "AD FS/Admin",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "6/26/2026 5:43:30 AM",
          "JD-DC01-2022.ludus.domain"
        ]
      }
    }
  },
  "message": ""
}

Event ID 451: Following nodes have the reported heartbeat older than Event.EventData UTC and will be deleted

#
Channel
Unknown
Level
4

Description

Following nodes have the reported heartbeat older than UTC and will be deleted.

Fields #

NameDescription
Event.EventData
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2ffb687a-1571-4ace-8550-47ab5ccae2bc",
    "event_source_name": "",
    "event_id": 451,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-07-03T05:43:30.2893198+00:00",
    "event_record_id": 1602,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 3316,
      "thread_id": 11880
    },
    "channel": "AD FS/Admin",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": "6/26/2026 5:43:30 AMJD-DC01-2022.ludus.domain"
    }
  },
  "message": "Following nodes have the reported heartbeat older than 6/26/2026 5:43:30 AM UTC and will be deleted. \r\n\r\nJD-DC01-2022.ludus.domain"
}

Event ID 452: task_0452

#
Channel
Admin

Message #

%1

Fields #

NameDescription
data1 UnicodeString

Event ID 452

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 500: More information for the event entry with Instance ID data1.

#
Channel
Admin

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID:  
%1 
 

Issued identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 500: More information for the event entry with Instance ID

#
Channel
Unknown

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 501: More information for the event entry with Instance ID Event.EventData.

#
Channel
Admin
Level
Informational

Description

More information for the event entry with Instance ID Event.EventData. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID: 
%1 
 
Caller identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 501,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:37.250884+00:00",
    "event_record_id": 97,
    "correlation": {
      "ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "a6f4ff0b-8776-43a4-9be1-6b9bf86e338f",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname",
          "ludus\\domainadmin",
          "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name",
          "ludus\\domainadmin",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid",
          "S-1-5-21-1006758700-2167138679-1475694448-1105",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-572",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-1149",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-18-1",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-519",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-518",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-512",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-520"
        ]
      }
    }
  },
  "message": ""
}

Event ID 501: More information for the event entry with Instance ID

#
Channel
Unknown
Level
4

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 501,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:09:23.9078077+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "2699b4ab-8f31-4d84-a931-f6e38783fc3bhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/implicitupndomainadmin@ludus.domainhttp://schemas.microsoft.com/ws/2014/01/identity/claims/accountstoreAD AUTHORITYhttp://schemas.microsoft.com/ws/2014/01/identity/claims/anchorclaimtypehttp://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"
  }
}

Example keys not documented in the fields table: EventData

Event ID 502: More information for the event entry with Instance ID data1.

#
Channel
Admin

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID: 
%1 
 
OnBehalfOf identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 502: More information for the event entry with Instance ID

#
Channel
Unknown

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 503: More information for the event entry with Instance ID data1.

#
Channel
Admin

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID: 
%1 
 
ActAs identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 503: More information for the event entry with Instance ID

#
Channel
Unknown

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 504: The following update was successful to the application proxy store on the federation server

#
Channel
Admin, Unknown

Message #

The following update was successful to the application proxy store on the federation server. 

Authentication information:  
%1 

HTTP method:  
%2 

Key: 
%3 

Value: 
%4 

Version: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 505: The following update attempt to the application proxy store on the federation server failed

#
Channel
Admin, Unknown

Message #

The following update attempt to the application proxy store on the federation server failed. 

Authentication information:  
%1 

HTTP method:  
%2 

Key: 
%3 

Value: 
%4 

Version: 
%5 

Error information: 
%6

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 506: The following update attempt to the application proxy relying party trust on the federation server succeeded

#
Channel
Admin, Unknown

Message #

The following update attempt to the application proxy relying party trust on the federation server succeeded. 

Authentication information:  
%1 

HTTP method:  
%2 

Identifier: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 507: The following update attempt to the application proxy relying party trust on the federation server failed

#
Channel
Admin, Unknown

Message #

The following update attempt to the application proxy relying party trust on the federation server failed. 

Authentication information:  
%1 

HTTP method:  
%2 

Identifier: 
%3 

Error information: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 508: The following update attempt to the relying party trust on the federation server succeeded

#
Channel
Admin, Unknown

Message #

The following update attempt to the relying party trust on the federation server succeeded. 

Authentication information:  
%1 

HTTP method:  
%2 

Relying party trust identifier: 
%3 

Internal Url: 
%4 

External Url: 
%5 

Published identifier: 
%6

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 509: The following update attempt to the relying party trust on the federation server failed

#
Channel
Admin, Unknown

Message #

The following update attempt to the relying party trust on the federation server failed. 

Authentication information:  
%1 

HTTP method:  
%2 

Relying party trust identifier: 
%3 

Internal url: 
%4 

External url: 
%5 

Published identifier: 
%6 

Error information: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 510: More information for the event entry with Instance ID data1.

#
Channel
Admin
Collection Priority
Recommended (ASD)

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 
 
Instance ID:  
%1 
 
Details: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 510: More information for the event entry with Instance ID

#
Channel
Unknown
Collection Priority
Recommended (ASD)

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 511: The incoming sign-in request is not allowed due to an invalid Federation Service configuration

#
Channel
Admin, Unknown

Message #

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.  

Request url: 
 %1 

User Action:
 Examine the Federation Service configuration and take the following actions: 
  Verify that the sign-in request has all the required parameters and is formatted correctly. 
  Verify that a web application proxy relying party trust exists, is enabled, and has identifiers which match the sign-in request parameters. 
  Verify that the target relying party trust object exists, is published through the web application proxy, and has identifiers which match the sign-in request parameters.

Fields #

NameDescription
data1 UnicodeString

Event ID 517: The incoming sign-in request is not allowed due to an invalid Federation Service configuration

#
Channel
Admin, Unknown

Message #

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.  

Request url: 
 %1 

User Action:
 Verify that either an enabled web application proxy relying party trust exists in your Federation Service configuration or that the target relying party trust object is not published through a web application proxy.

Fields #

NameDescription
data1 UnicodeString

Event ID 521: The request for the relying party token resulted in a failure

#
Channel
Admin, Unknown

Message #

The request for the relying party token resulted in a failure. 

Authentication information:  
%1 

HTTP method: 
%2 

Username:  
%3 

Password presented:  
%4 

Realm: 
%5 

Application realm:  
%6 

Device registration certificate thumbprint:  
%7 

User certificate thumbprint:  
%8 

Error information: 
%9 

User action: 
Examine the request and verify that at least one of the following parameter sets are present. 
  Username and password 
  Username, password, and device registration certificate 
  User certificate

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString

Event ID 530: AD FS could not read the local claims provider trusts from the AD FS configuration

#
Channel
Admin, Unknown

Description

AD FS could not read the local claims provider trusts from the AD FS configuration. AD FS will continue to operating from cached configuration.

Message #

AD FS could not read the local claims provider trusts from the AD FS configuration.  AD FS will continue to operating from cached configuration. 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 531: AD FS could not read the local claims provider trusts from the AD FS configuration

#
Channel
Admin, Unknown

Description

AD FS could not read the local claims provider trusts from the AD FS configuration. AD FS will not function until this configuration can be read for the first time.

Message #

AD FS could not read the local claims provider trusts from the AD FS configuration.  AD FS will not function until this configuration can be read for the first time. 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 540: The Federation Service was was unable to return the OAuth discovery document as a result of an error

#
Channel
Admin, Unknown

Message #

The Federation Service was was unable to return the OAuth discovery document as a result of an error. 
Document Path: %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 541: An invalid value was found during processing of the proxy configuration data from the AD FS server

#
Channel
Admin, Unknown

Description

An invalid value was found during processing of the proxy configuration data from the AD FS server. The value will be ignored, and the rest of the proxy configuration data will be processed.

Message #

An invalid value was found during processing of the proxy configuration data from the AD FS server. The value will be ignored, and the rest of the proxy configuration data will be processed.  

Additional Data 

FarmBehavior: '%1' 

User action: 
This may point to an interoperability issue between the proxy and the AD FS server. Contact the vendor for your AD FS server.

Fields #

NameDescription
data1 UnicodeString

Event ID 542: There was an error during heartbeat

#
Channel
Admin, Unknown

Message #

There was an error during heartbeat. 

Additional data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 543: There was an error during heartbeat communicating to primary federation server

#
Channel
Admin, Unknown

Message #

There was an error during heartbeat communicating to primary federation server. 

Primary server: '%1' 

Endpoint: '%2' 

Additional data 

Exception details: 
%3 

User Action 
 Make sure the primary federation server is available or the service account identity of this machine matches the service account identity of the primary federation server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 544: Heartbeat is not performed because primary server does not support heartbeat

#
Channel
Admin, Unknown

Message #

Heartbeat is not performed because primary server does not support heartbeat. 

Primary server: '%1'

Fields #

NameDescription
data1 UnicodeString

Event ID 545: Heartbeat is performed at primary server.

#
Channel
Admin
Level
Informational

Message #

Heartbeat is performed at primary server. 

Primary server: '%1'

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 545,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:56.798717+00:00",
    "event_record_id": 35,
    "correlation": {
      "ActivityID": "0D26E79C-B333-000D-9A2E-270D33B3DC01"
    },
    "execution": {
      "process_id": 8080,
      "thread_id": 11896
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "localhost"
      }
    }
  },
  "message": ""
}

Event ID 545: Heartbeat is performed at primary server

#
Channel
Unknown
Level
4

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 545,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:13:59.8735895+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "localhost"
  }
}

Example keys not documented in the fields table: EventData

Event ID 546: A current tenant certificate for Azure MFA was not found

#
Channel
Admin, Unknown

Message #

A current tenant certificate for Azure MFA was not found.  

TenantId: %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 547: The tenant certificate for Azure MFA has been renewed

#
Channel
Admin, Unknown

Message #

The tenant certificate for Azure MFA has been renewed.  

TenantId: %1. 
Old thumbprint: %2. 
Old expiration date: %3. 
New thumbprint: %4. 
New expiration date: %5.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 548: The tenant certificate for Azure MFA will expire soon

#
Channel
Admin, Unknown

Message #

The tenant certificate for Azure MFA will expire soon.  

TenantId: %1. 
Thumbprint: %2. 
Expiration date: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 549: The tenant certificate for Azure MFA has expired

#
Channel
Admin, Unknown

Message #

The tenant certificate for Azure MFA has expired.  

TenantId: %1. 
Thumbprint: %2. 
Expiration date: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 550: The data1 primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1)

#
Channel
Admin, Unknown

Message #

The %1 primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1). 

User Action: This value can be changed by reimporting the certificate from a pfx file.  From an elevated command prompt, use the command "certutil -importpfx filename.pfx AT_KEYEXCHANGE". For more information, see http://go.microsoft.com/fwlink/?LinkId=798501

Fields #

NameDescription
data1 UnicodeString

Event ID 551: An error occurred during processing of an OAuth logout request

#
Channel
Admin, Unknown

Message #

An error occurred during processing of an OAuth logout request. 
Path: %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 552: The session cookies were successfully deleted using the OAuth logout path.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 552,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:53.219831+00:00",
    "event_record_id": 114,
    "correlation": {
      "ActivityID": "26B7203E-F387-4B80-0E00-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 552: The session cookies were successfully deleted using the OAuth logout path

#
Channel
Unknown
Level
4

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 552,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:08:53.2198315+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": ""
  }
}

Example keys not documented in the fields table: EventData

Event ID 553: The specified redirect URL was validated successfully

#
Channel
Admin, Unknown

Message #

The specified redirect URL was validated successfully. 

URL: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 554: The specified redirect URL did not match any of the OAuth client's redirect URIs.

#
Channel
Admin
Level
Error

Description

The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected.

Message #

The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected. 

URL: %1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 554,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:53.228256+00:00",
    "event_record_id": 115,
    "correlation": {
      "ActivityID": "26B7203E-F387-4B80-0E00-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "https://localhost"
      }
    }
  },
  "message": ""
}

Event ID 554: The specified redirect URL did not match any of the OAuth client's redirect URIs

#
Channel
Unknown
Level
2

Description

The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 554,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:08:53.2282562+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "https://localhost"
  }
}

Example keys not documented in the fields table: EventData

Event ID 555: The Windows Hello for Business key receipt could not be verified

#
Channel
Admin, Unknown

Message #

The Windows Hello for Business key receipt could not be verified. 

Additional Information: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 556: Error encountered while attempting to select a master node for the account store

#
Channel
Admin, Unknown

Message #

Error encountered while attempting to select a master node for the account store. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC.  Future runs may occur on other farm nodes if AD FS is running in a farm configuration. 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 557: An error occured while trying to communicate with the account store rest service on node data1.

#
Channel
Admin

Message #

An error occured while trying to communicate with the account store rest service on node %1.   
If this is a WID farm the primary node may be offline. 
If this is a SQL farm ADFS will automatically select a new node to host the User store master role. 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 557: An error occured while trying to communicate with the account store rest service on node

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 558: Syncronization of the Account Activity data failed

#
Channel
Admin, Unknown

Message #

Syncronization of the Account Activity data failed. 

Additional Data 
Exception message: 
%1 

User Action 
Ensure that the artifact storage server is configured properly. Troubleshoot network connectivity to the artifact storage server.  
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 559: Device authentication using PKeyAuth failed

#
Channel
Admin, Unknown

Description

Device authentication using PKeyAuth failed. Request might continue without device authentication.

Message #

Device authentication using PKeyAuth failed. Request might continue without device authentication. 

Additional Information: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 560: User data1 could not be found in the account database

#
Channel
Admin, Unknown

Message #

User %1 could not be found in the account database.

Fields #

NameDescription
data1 UnicodeString

Event ID 561: Authorization failed when connecting to the account store endpoint on server data1.

#
Channel
Admin

Message #

Authorization failed when connecting to the account store endpoint on server %1 

Additional Data 

Exception Message: 
%2 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 561: Authorization failed when connecting to the account store endpoint on server

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 562: An error occurred when communcating with the account store endpoint on server data1.

#
Channel
Admin

Message #

An error occurred when communcating with the account store endpoint on server %1. 

Additional Data 

Exception Message: 
%2 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 562: An error occurred when communcating with the account store endpoint on server

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 563: An error occurred while calculating extranet lockout status

#
Channel
Admin, Unknown

Description

An error occurred while calculating extranet lockout status. Due to the value of the data1 setting authentication will be allowed for this user and token issuance will continue.

Message #

An error occurred while calculating extranet lockout status. Due to the value of the %1 setting authentication will be allowed for this user and token issuance will continue. 
If this is a WID farm the primary node may be offline. 
If this is a SQL farm ADFS will automatically select a new node to host the User store master role. 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information. 

Additional Data 
Account store server name: 
%2 
User Id: 
%3 

Exception Message: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 564: The banned IP list found in Microsoft

#
Channel
Admin, Unknown

Message #

The banned IP list found in Microsoft.IdentityServer.Servicehost.exe.config is being used instead of the banned IP list found in the ADFS configuration database.  Verify that the configuration file contains the correct list.  Clearing the banned IPs from the database using Set-ADFSProperties -RemoveBannedIPs will silence this warning.

Event ID 565: An error occurred while attemtping to update the database schema for Adfs smart lockout

#
Channel
Admin, Unknown

Description

An error occurred while attemtping to update the database schema for Adfs smart lockout. See https://go.microsoft.com/fwlink/?linkid=864556 for more information.

Message #

An error occurred while attemtping to update the database schema for Adfs smart lockout. See https://go.microsoft.com/fwlink/?linkid=864556 for more information. 

Additional Data 

Exception Message: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 566: An error occurred during processing of an OAuth device code request

#
Channel
Admin, Unknown

Message #

An error occurred during processing of an OAuth device code request. 
Error: %1 

Additional Data 

Client identifier: %2 

Full request: %3 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 568: An error occurred during processing of an OAuth device auth request with the provided usercode: data1.

#
Channel
Admin

Message #

An error occurred during processing of an OAuth device auth request with the provided usercode: %1. 
Error: %2 

Additional Data 

User Code Data (if available): %3 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 568: An error occurred during processing of an OAuth device auth request with the provided usercode:

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 570: Active Directory trust enumeration was unable to enumerate one of more domains due to the following error

#
Channel
Admin, Unknown

Message #

Active Directory trust enumeration was unable to enumerate one of more domains due to the following error.  Enumeration will continue but the Active Directory identifier list may not be correct. Validate that all expected Active Directory identifiers are present by running Get-ADFSDirectoryProperties: 

Error string: %1 

Exception Details: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 571: Enumeration of the Active Directory domains failed

#
Channel
Admin, Unknown

Message #

Enumeration of the Active Directory domains failed. 

Exception Details: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 572: The Active Directory suffix from this username is not trusted by this ADFS server

#
Channel
Admin, Unknown

Description

The Active Directory suffix from this username is not trusted by this ADFS server. If this identifier is expected it can be added to the trusted identier list by using Set-ADFSDirectoryProperties.

Message #

The Active Directory suffix from this username is not trusted by this ADFS server.  If this identifier is expected it can be added to the trusted identier list by using Set-ADFSDirectoryProperties. 

Username: %1 

Suffix: %2 

Client IP: %3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 573: The following error was generated by a threat detection module

#
Channel
Admin, Unknown

Message #

The following error was generated by a threat detection module. 

Module Identifier: %1 

Message: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 574: A threat detection module failed to load

#
Channel
Admin, Unknown

Description

A threat detection module failed to load. Verify the module binary is correctly installed on this node.

Message #

A threat detection module failed to load.  Verify the module binary is correctly installed on this node. 

Module Name: %1 

Module Identifier: %2 

Type: %3 

Failure Message: %4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 575: The following threat detection module was successfully loaded.

#
Channel
Admin
Level
Informational

Message #

The following threat detection module was successfully loaded 

Module Name: %1 

Module Identifier: %2 

Type: %3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 575,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:53.739665+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "BannedIpProvider",
          "",
          "Microsoft.IdentityServer.Service.AccountPolicy.BannedIpProvider, Microsoft.IdentityServer.Service, Version=10.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"
        ]
      }
    }
  },
  "message": ""
}

Event ID 575: The following threat detection module was successfully loaded

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 575,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-24T22:33:03.4173770+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 576: An unexpected error was returned from a threat detection module

#
Channel
Admin, Unknown

Message #

An unexpected error was returned from a threat detection module. 

Module Name: %1 

Module Identifier: %2 

Type: %3 

Exception Type: %4 

Error Message: %5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 1000: An error occurred during processing of a token request.

#
Channel
Admin
Level
Warning

Message #

An error occurred during processing of a token request. The data in this event may have the identity of the caller (application) that made this request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.  

Additional Data 

Caller:
 %1 

OnBehalfOf user:
 %2 

ActAs user:
 %3 

Target Relying Party:
 %4 

Device identity:
 %5 

User action: 
Use the Activity ID data in this message to search and correlate the data to events in the Event log using Event Viewer. This Activity ID will also be shown as additional information in the error page when an error occurs in the federation passive Web application.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1000,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:37.253680+00:00",
    "event_record_id": 101,
    "correlation": {
      "ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "ludus\\domainadmin\r\n",
          "",
          "",
          "https://testrp1.example.com/saml",
          ""
        ]
      }
    }
  },
  "message": ""
}

Event ID 1000: An error occurred during processing of a token request

#
Channel
Unknown
Level
3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 1000,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:09:23.9078230+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "ludus\\domainadmin\nhttps://testrp1.example.com/saml"
  }
}

Example keys not documented in the fields table: EventData

Event ID 1020: Encountered error during OAuth authorization request.

#
Channel
Admin
Level
Error

Message #

Encountered error during OAuth authorization request. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1020,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:52.935997+00:00",
    "event_record_id": 108,
    "correlation": {
      "ActivityID": "E915B92E-2E46-4CB5-0900-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\r\n\r\n"
      }
    }
  },
  "message": ""
}

Event ID 1020: Encountered error during OAuth authorization request

#
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 1020,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:08:53.1122569+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\n\n"
  }
}

Example keys not documented in the fields table: EventData

Event ID 1021: Encountered error during OAuth token request.

#
Channel
Admin
Level
Error

Message #

Encountered error during OAuth token request. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1021,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:36.668080+00:00",
    "event_record_id": 94,
    "correlation": {
      "ActivityID": "43EBE48F-E201-482C-1500-00400A0000FF"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9241: Received invalid OAuth access token request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'nonexistent'. \r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthTokenRequestContext.ValidateCore()\r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthClientCredentialsContext.ValidateCore()\r\n\r\n"
      }
    }
  },
  "message": ""
}

Event ID 1021: Encountered error during OAuth token request

#
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 1021,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:08:52.9024091+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9300: Received invalid OAuth client credentials request. The received client is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client: 'fake'. \n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthUsernamePasswordContext.ValidateCore()\n\n"
  }
}

Example keys not documented in the fields table: EventData

Event ID 1080: An error occurred while processing WebFinger request

#
Channel
Admin, Unknown

Message #

An error occurred while processing WebFinger request. 

Additional Data 
Request url: %1 

User Action 
Examine the exception details to take one or more of the following actions if applicable. 
  Verify that the resource query parameter exists and is valid representing an authorization server's URL. 
  Verify that all federation partners (RP-STSs) that this ADFS issues tokens to (including any chains) have been configured using powershell cmdlet Add-ADFSTrustedFederationPartner. 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1100: The Federation Service could not authorize a request to one of the REST endpoints

#
Channel
Admin, Unknown

Message #

The Federation Service could not authorize a request to one of the REST endpoints. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 1109: The Federation Service failed to connect to the LDAP account store to authenticate user data2.

#
Channel
Admin

Message #

The Federation Service failed to connect to the LDAP account store to authenticate user %2. 

Activity ID: %1 

Request Details: 
    User DN: %2 
    Local CP trust identifier: %3 
    LDAP server: %4 
    SSL: %5 
    Authentication method: %6 

Exception details: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1109: The Federation Service failed to connect to the LDAP account store to authenticate user

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1110: The Federation Service failed to connect to the primary LDAP account store to authenticate user data2.

#
Channel
Admin

Message #

The Federation Service failed to connect to the primary LDAP account store to authenticate user %2. 

Activity ID: %1 

Request Details: 
    User DN: %2 
    Local CP trust identifier: %3 
    Ldap server: %4 
    SSL: %5 
    Authentication method: %6 

Exception details: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1110: The Federation Service failed to connect to the primary LDAP account store to authenticate user

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1111: The Federation Service failed to connect to all LDAP account stores to authenticate user data2.

#
Channel
Admin

Message #

The Federation Service failed to connect to all LDAP account stores to authenticate user %2. 

Activity ID: %1 

Request Details: 
    User DN: %2 
    Local CP trust identifier: %3 
    Ldap server: %4 
    SSL: %5 
    Authentication method: %6 

Exception details: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1111: The Federation Service failed to connect to all LDAP account stores to authenticate user

#
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1112: The Federation Service failed to connect to the Ldap server

#
Channel
Admin, Unknown

Message #

The Federation Service failed to connect to the Ldap server. 

Activity ID: %1 

Request Details: 
    Local CP trust identifier: %2 
    Ldap ErrorCode: %3 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 1113: Client Json Web Key Set (JWKS) synchronization initiated.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1113,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.121414+00:00",
    "event_record_id": 73,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 10760
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 1113: Client Json Web Key Set (JWKS) synchronization initiated

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 1113,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.2438903+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 1114: Client Json Web Key Set (JWKS) synchronization completed.

#
Channel
Admin
Level
Informational

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1114,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.154935+00:00",
    "event_record_id": 80,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 10760
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 1114: Client Json Web Key Set (JWKS) synchronization completed

#
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 1114,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.2578083+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Example keys not documented in the fields table: EventData

Event ID 1115: The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from 'data1'

#
Channel
Admin, Unknown

Description

The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from 'data1'. The key synchronization for the following client failed.

Message #

The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from '%1'. The key synchronization for the following client failed: 

Client: 
%2 

Additional Data 

Exception details: 
%3 

Additional details: 
%4 

User Action 
Make sure the JWKS URI '%1' is accessible.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 1116: An error occurred during a read operation from the configuration database

#
Channel
Admin, Unknown

Message #

An error occurred during a read operation from the configuration database. Monitoring of clients' Json Web Key Set (JWKS) was shut down and will be tried again after an amount of time that corresponds to the monitoring interval. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1117: An error occurred during monitoring of the following client's Json Web Key Set (JWKS)

#
Channel
Admin, Unknown

Message #

An error occurred during monitoring of the following client's Json Web Key Set (JWKS). 

Client: 
%1 

Additional Data 

Exception details: 
%2 

Additional details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 1118: An error occurred during monitoring of clients'Json Web Key Set (JWKS)

#
Channel
Admin, Unknown

Description

An error occurred during monitoring of clients'Json Web Key Set (JWKS). The monitoring cycle was shut down.

Message #

An error occurred during monitoring of clients'Json Web Key Set (JWKS). The monitoring cycle was shut down. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1130: There was an error establishing or renewing the proxy trust

#
Channel
Admin, Unknown

Description

There was an error establishing or renewing the proxy trust. Ensure the STS and proxy servers have the same TLS version enabled.

Message #

There was an error establishing or renewing the proxy trust. Ensure the STS and proxy servers have the same TLS version enabled. 
Consult the following links for additional details: 
https://go.microsoft.com/fwlink/?linkid=875038  
https://go.microsoft.com/fwlink/?linkid=875039  

Additional Data 

Exception Details: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 1131: There was an error establishing or renewing the trust between the proxy and STS

#
Channel
Admin, Unknown

Message #

There was an error establishing or renewing the trust between the proxy and STS. Ensure the Network Service Account has Read/Write permissions on C:\Program Data\Microsoft\Crypto\RSA\Machine Keys on the proxy server. 
Consult the following link for additional details: 
https://go.microsoft.com/fwlink/?linkid=875037  

Additional Data 

Exception Details: %1

Fields #

NameDescription
data1 UnicodeString

Provenance

ETW provider GUID 2ffb687a-1571-4ace-8550-47ab5ccae2bc

Defined in Microsoft.IdentityServer.NativeResources.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 5.00, captured 2026-06-02