AD FS

562 events across 2 channels

EventTitleChannelSample
100The Federation Service started successfully.AdminY
100The Federation Service started successfullyUnknownY
102There was an error in enabling endpoints of Federation Service.AdminY
102There was an error in enabling endpoints of Federation ServiceUnknownY
103The Federation Service stopped successfully.AdminY
103The Federation Service stopped successfullyUnknownY
104The artifact resolution service is not running.AdminN
104The artifact resolution service is not runningUnknownN
105An error occurred loading an authentication provider.AdminN
105An error occurred loading an authentication providerUnknownN
106An authentication provider was successfully loaded: Identifier: …AdminY
106An authentication provider was successfully loaded: Identifier: 'data1', …UnknownY
111The Federation Service encountered an error while processing the WS-Trust …AdminN
111The Federation Service encountered an error while processing the WS-Trust …UnknownN
131During processing of the Federation Service configuration, the element 'data1' …AdminN
131During processing of the Federation Service configuration, the element 'data1' …UnknownN
132During processing of the Federation Service configuration, the required element …AdminN
132During processing of the Federation Service configuration, the required element …UnknownN
133During processing of the Federation Service configuration, the element 'data1' …AdminN
133During processing of the Federation Service configuration, the element 'data1' …UnknownN
134During processing of the Federation Service configuration, the element 'data1' …AdminN
134During processing of the Federation Service configuration, the element 'data1' …UnknownN
135During processing of the Federation Service configuration, the element 'data1' …AdminN
135During processing of the Federation Service configuration, the element 'data1' …UnknownN
136During processing of the Federation Service configuration, the Federation …AdminN
136During processing of the Federation Service configuration, the Federation …UnknownN
143The Federation Service was unable to create the federation metadata document as …AdminN
143The Federation Service was unable to create the federation metadata document as …UnknownN
144The Federation Service Proxy blocked an illegitimate request made by a client, …AdminN
144The Federation Service Proxy blocked an illegitimate request made by a client, …UnknownN
147A token was received from a claims provider identified by the key 'data1', but …AdminN
147A token was received from a claims provider identified by the key 'data1', but …UnknownN
149During processing of the Federation Service configuration, the attribute store …AdminY
149During processing of the Federation Service configuration, the attribute store …UnknownY
155The Federation Service was unable to listen at 'data1' for metadata document …AdminN
155The Federation Service was unable to listen at 'data1' for metadata document …UnknownN
156Trust monitoring cycle initiated.AdminY
156Trust monitoring cycle initiatedUnknownY
157Trust monitoring cycle completed.AdminY
157Trust monitoring cycle completedUnknownY
159The Federation Service encountered an error while writing to the following …AdminN
159The Federation Service encountered an error while writing to the following …UnknownN
163An error occurred during initialization of trust monitoring.AdminN
163An error occurred during initialization of trust monitoringUnknownN
164An error occurred during a read operation from the configuration database.AdminN
164An error occurred during a read operation from the configuration databaseUnknownN
165An error occurred during trust monitoring.AdminN
165An error occurred during trust monitoringUnknownN
166Trust monitoring service encountered an error while parsing the metadata …AdminN
166Trust monitoring service encountered an error while parsing the metadata …UnknownN
167Trust monitoring service encountered an error while applying the data in the …AdminN
167Trust monitoring service encountered an error while applying the data in the …UnknownN
168The Federation Service encountered an error while retrieving the federation …AdminN
168The Federation Service encountered an error while retrieving the federation …UnknownN
171The trust monitoring service automatically updated the trust of 'data1' …AdminN
171The trust monitoring service automatically updated the trust of 'data1' …UnknownN
173The trust monitoring service automatically updated the trust of 'data1' …AdminN
173The trust monitoring service automatically updated the trust of 'data1' …UnknownN
174Trust monitoring service detected changes in policy of 'data1', but did not …AdminN
174Trust monitoring service detected changes in policy of 'data1', but did not …UnknownN
180An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version …AdminN
180An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version …UnknownN
181AD FS could not enable the new KDFv2 feature automatically because of missing …AdminN
181AD FS could not enable the new KDFv2 feature automatically because of missing …UnknownN
182AD FS enabled the new KDFv2 feature successfully.AdminN
182AD FS enabled the new KDFv2 feature successfullyUnknownN
183KDFv2 feature is disabled on AD FS farm.AdminN
183KDFv2 feature is disabled on AD FS farmUnknownN
184A token request was received for a relying party identified by the key 'data1', …AdminN
184A token request was received for a relying party identified by the key 'data1', …UnknownN
186The Federation Service could not fulfill the token-issuance request.AdminN
186The Federation Service could not fulfill the token-issuance requestUnknownN
187AD FS server received a JWT token without nonce in the assertion and it was …AdminN
187AD FS server received a JWT token without nonce in the assertion and it was …UnknownN
188AD FS server is not configured to reject JWT tokens that did not have nonce in …AdminY
188AD FS server is not configured to reject JWT tokens that did not have nonce in …UnknownY
189AD FS server received an OAuth authorization request in the device code flow …AdminN
189AD FS server received an OAuth authorization request in the device code flow …UnknownN
193The Federation Service could not satisfy a token request because the relying …AdminN
193The Federation Service could not satisfy a token request because the relying …UnknownN
197The Federation Service could not satisfy a token request because the …AdminN
197The Federation Service could not satisfy a token request because the …UnknownN
198The federation server proxy started successfully.AdminN
198The federation server proxy started successfullyUnknownN
199The federation server proxy could not be started.AdminN
199The federation server proxy could not be startedUnknownN
200The federation server proxy stopped successfully.AdminN
200The federation server proxy stopped successfullyUnknownN
201The Federation Service data1 encountered an Access Denied error while trying to …AdminN
201The Federation Service data1 encountered an Access Denied error while trying to …UnknownN
202The Federation Service data1 could not be opened.AdminN
202The Federation Service data1 could not be openedUnknownN
203The Federation Service data1 could not be shut down properly.AdminN
203The Federation Service data1 could not be shut down properlyUnknownN
204The Federation Service data1 could not be closed.AdminN
204The Federation Service data1 could not be closedUnknownN
206The Federation Service could not fulfill the token-issuance request because the …AdminN
206The Federation Service could not fulfill the token-issuance request because the …UnknownN
207An attempt to write to the Security event log failed.AdminN
207An attempt to write to the Security event log failedUnknownN
208An error occurred during an attempt to register the event source for the …AdminN
208An error occurred during an attempt to register the event source for the …UnknownN
209The Security log event source for the Federation Service could not be …AdminN
209The Security log event source for the Federation Service could not be registeredUnknownN
215The Federation Service at 'data1' did not return any WS-Trust endpoints to be …AdminN
215The Federation Service at 'data1' did not return any WS-Trust endpoints to be …UnknownN
217A WS-Trust endpoint that was configured could not be opened.AdminN
217A WS-Trust endpoint that was configured could not be openedUnknownN
218The federation server proxy received error code 'data2' while making a request …AdminN
218The federation server proxy received error code 'data2' while making a request …UnknownN
220The Federation Service configuration could not be loaded correctly from the AD …AdminY
220The Federation Service configuration could not be loaded correctly from the AD …UnknownY
221A change to the token service configuration was detected, but there was an error …AdminY
221A change to the token service configuration was detected, but there was an error …UnknownY
222The federation server proxy was unable to complete a request to the Federation …AdminN
222The federation server proxy was unable to complete a request to the Federation …UnknownN
223Claim description could not be loaded correctly from the database.AdminN
223Claim description could not be loaded correctly from the databaseUnknownN
224The federation server proxy configuration could not be updated with the latest …AdminN
224The federation server proxy configuration could not be updated with the latest …UnknownN
225A change to the service configuration was detected, but there was an error …AdminN
225A change to the service configuration was detected, but there was an error …UnknownN
230The federation server proxy has detected congestion, caused by high latency …AdminN
230The federation server proxy has detected congestion, caused by high latency …UnknownN
238The Federation Service failed to find a domain controller for the domain data1.AdminN
238The Federation Service failed to find a domain controller for the domainUnknownN
244The Federation Service was unable to listen at 'data1' for WS-MetadataExchange …AdminN
244The Federation Service was unable to listen at 'data1' for WS-MetadataExchange …UnknownN
245The federation server proxy successfully retrieved and updated its configuration …AdminN
245The federation server proxy successfully retrieved and updated its configuration …UnknownN
246The Federation Service encountered an error during an attempt to connect to a …AdminN
246The Federation Service encountered an error during an attempt to connect to a …UnknownN
247The Federation Service encountered an error while connecting to a global catalog …AdminN
247The Federation Service encountered an error while connecting to a global catalog …UnknownN
248The federation server proxy was not able to retrieve the list of endpoints from …AdminN
248The federation server proxy was not able to retrieve the list of endpoints from …UnknownN
249The certificate identified by thumbprint 'data1' could not be found in the …AdminN
249The certificate identified by thumbprint 'data1' could not be found in the …UnknownN
250Expiration of the artifact failed.AdminY
250Expiration of the artifact failedUnknownY
251Attribute store 'Event.EventData' is loaded successfully.AdminY
251Attribute store 'data1' is loaded successfullyUnknownY
252The AD FS proxy service made changes to the endpoints it is listening on based …AdminN
252The AD FS proxy service made changes to the endpoints it is listening on based …UnknownN
253AD FS proxy service failed to start a listener for the endpoint 'data1'.AdminN
253AD FS proxy service failed to start a listener for the endpoint 'data1'UnknownN
258The relying party 'data1' is not configured with SAML Assertion Consumer …AdminN
258The relying party 'data1' is not configured with SAML Assertion Consumer …UnknownN
259The request specified an Assertion Consumer Service index 'data1' that is not …AdminN
259The request specified an Assertion Consumer Service index 'data1' that is not …UnknownN
260The request specified an Assertion Consumer Service protocol binding 'data1' …AdminN
260The request specified an Assertion Consumer Service protocol binding 'data1' …UnknownN
261The request specified an Assertion Consumer Service URL 'data1' that is not …AdminN
261The request specified an Assertion Consumer Service URL 'data1' that is not …UnknownN
262The artifact resolution request failed.AdminN
262The artifact resolution request failedUnknownN
273The request specified an assertion consumer service that is not configured or …AdminN
273The request specified an assertion consumer service that is not configured or …UnknownN
274The federation server proxy encountered an error while trying to listen on one …AdminN
274The federation server proxy encountered an error while trying to listen on one …UnknownN
275The federation server proxy could not establish a trust relationship for the SSL …AdminN
275The federation server proxy could not establish a trust relationship for the SSL …UnknownN
276The federation server proxy was not able to authenticate to the Federation …AdminN
276The federation server proxy was not able to authenticate to the Federation …UnknownN
277The Federation Service encountered an unexpected exception and has shut down.AdminN
277The Federation Service encountered an unexpected exception and has shut downUnknownN
278The SAML artifact resolution endpoint is not configured or it is disabled.AdminY
278The SAML artifact resolution endpoint is not configured or it is disabledUnknownY
279Unable to find a claims provider trust for SAML artifact resolution in the AD FS …AdminN
279Unable to find a claims provider trust for SAML artifact resolution in the AD FS …UnknownN
280Unable to resolve the SAML artifact from the claims provider because the claims …AdminN
280Unable to resolve the SAML artifact from the claims provider because the claims …UnknownN
281Unable to resolve the SAML artifact from the claims provider because the claims …AdminN
281Unable to resolve the SAML artifact from the claims provider because the claims …UnknownN
283Unable to resolve the SAML artifact.AdminN
283Unable to resolve the SAML artifactUnknownN
284Unable to resolve the SAML artifact.AdminN
284Unable to resolve the SAML artifactUnknownN
285The SAML artifact was resolved, but the response is empty or does not contain …AdminN
285The SAML artifact was resolved, but the response is empty or does not contain …UnknownN
286Cannot connect to the artifact database.AdminN
286Cannot connect to the artifact databaseUnknownN
287Cannot add the artifact to the artifact database.AdminN
287Cannot add the artifact to the artifact databaseUnknownN
288Cannot get the artifact from storage.AdminN
288Cannot get the artifact from storageUnknownN
289Cannot remove the artifact from storage.AdminN
289Cannot remove the artifact from storageUnknownN
290Cannot set expiration for the artifacts in storage.AdminN
290Cannot set expiration for the artifacts in storageUnknownN
291The artifact resolution service could not be started.AdminN
291The artifact resolution service could not be startedUnknownN
293A SAML request for the required artifact was rejected because the artifact …AdminN
293A SAML request for the required artifact was rejected because the artifact …UnknownN
294The SAML artifact resolution request specified an issuer that is not configured …AdminN
294The SAML artifact resolution request specified an issuer that is not configured …UnknownN
297The SAML artifact resolution request required an artifact resolution service …AdminN
297The SAML artifact resolution request required an artifact resolution service …UnknownN
298The Windows Hello for Business key receipt certificate background task will not …AdminY
298The Windows Hello for Business key receipt certificate background task will not …UnknownY
302The Federation Service could not authorize token issuance for caller 'data2' as …AdminN
302The Federation Service could not authorize token issuance for caller 'data2' as …UnknownN
303The Federation Service encountered an error while processing the SAML …AdminN
303The Federation Service encountered an error while processing the SAML …UnknownN
305The Federation Service encountered an error while querying a LDAP server at …AdminN
305The Federation Service encountered an error while querying a LDAP server atUnknownN
306The Federation Service encountered an error while querying a global catalog …AdminN
306The Federation Service encountered an error while querying a global catalog …UnknownN
311An attempt to update AD FS performance counters failed.AdminN
311An attempt to update AD FS performance counters failedUnknownN
315An error occurred during an attempt to build the certificate chain for the …AdminN
315An error occurred during an attempt to build the certificate chain for the …UnknownN
316An error occurred during an attempt to build the certificate chain for the …AdminN
316An error occurred during an attempt to build the certificate chain for the …UnknownN
317An error occurred during an attempt to build the certificate chain for the …AdminY
317An error occurred during an attempt to build the certificate chain for the …UnknownY
319An error occurred while the certificate chain for the client certificate …AdminN
319An error occurred while the certificate chain for the client certificate …UnknownN
320The verification of the SAML message signature failed.AdminN
320The verification of the SAML message signature failedUnknownN
321The SAML authentication request had a NameID Policy that could not be satisfied.AdminN
321The SAML authentication request had a NameID Policy that could not be satisfiedUnknownN
323The Federation Service could not authorize token issuance for the caller 'data2' …AdminN
323The Federation Service could not authorize token issuance for the caller …UnknownN
325The Federation Service could not authorize token issuance for caller 'data1'.AdminY
325The Federation Service could not authorize token issuance for caller 'data2'UnknownY
326Failed to load the AD FS claims policy engine using policy type 'data1' User …AdminN
326Failed to load the AD FS claims policy engine using policy type 'data1'UnknownN
327An error occurred during processing of the SAML logout request.AdminN
327An error occurred during processing of the SAML logout requestUnknownN
328The SAML artifact resolution request was resolved, but the response does not …AdminN
328The SAML artifact resolution request was resolved, but the response does not …UnknownN
329The certificate that is identified by thumbprint 'data1' could not be decrypted …AdminN
329The certificate that is identified by thumbprint 'data1' could not be decrypted …UnknownN
331The certificate management service encountered an error during decryption of the …AdminN
331The certificate management service encountered an error during decryption of the …UnknownN
332The certificate management service encountered an error during encryption of the …AdminN
332The certificate management service encountered an error during encryption of the …UnknownN
333The certificate management service encountered an error during database access.AdminN
333The certificate management service encountered an error during database accessUnknownN
334Certificate rollover service needs to rollover data1 certificates urgently.AdminN
334Certificate rollover service needs to rollover data1 certificates urgentlyUnknownN
335task_0335AdminY
335Event ID 335UnknownY
336The certificate management cycle was initiated.AdminY
336The certificate management cycle was initiatedUnknownY
337The certificate management cycle was completed.AdminY
337The certificate management cycle was completedUnknownY
338An error was encountered during certificate rollover.AdminN
338An error was encountered during certificate rolloverUnknownN
339An error occurred during initialization of certificate rollover.AdminN
339An error occurred during initialization of certificate rolloverUnknownN
341The NotBefore attribute for the token has a value that is set to a future time.AdminN
341The NotBefore attribute for the token has a value that is set to a future timeUnknownN
342Token validation failed.AdminY
342Token validation failedUnknownY
343There was an error during initialization of synchronization.AdminN
343There was an error during initialization of synchronizationUnknownN
344There was an error doing synchronization.AdminN
344There was an error doing synchronizationUnknownN
345There was a communication error during AD FS configuration database …AdminN
345There was a communication error during AD FS configuration database …UnknownN
346There was an error during retrieving the configuration data for the secondary …AdminN
346There was an error during retrieving the configuration data for the secondary …UnknownN
348Synchronization of configuration data from the primary federation server 'data1' …AdminN
348Synchronization of configuration data from the primary federation server 'data1' …UnknownN
349The administration service for the Federation Service started successfully.AdminY
349The administration service for the Federation Service started successfullyUnknownY
351There was an error getting synchronization properties.AdminN
351There was an error getting synchronization propertiesUnknownN
352A SQL operation in the AD FS configuration database with connection string …AdminY
352A SQL operation in the AD FS configuration database with connection string data1 …UnknownY
353Unable to resolve the SAML artifact.AdminN
353Unable to resolve the SAML artifactUnknownN
354The artifact resolution service could not verify the request signature.AdminN
354The artifact resolution service could not verify the request signatureUnknownN
356Failed to register notification to the SQL database with the connection string …AdminN
356Failed to register notification to the SQL database with the connection string …UnknownN
357Successfully registered notification to the SQL database with the connection …AdminN
357Successfully registered notification to the SQL database with the connection …UnknownN
358Restarting Event.EventData.AdminY
358RestartingUnknownY
359An error occurred during an attempt to restart data1.AdminN
359An error occurred during an attempt to restartUnknownN
360A request was made to a certificate transport endpoint, but the request did not …AdminN
360A request was made to a certificate transport endpoint, but the request did not …UnknownN
362Encountered error during federation passive sign-out.AdminN
362Encountered error during federation passive sign-outUnknownN
363A communication error occurred during an attempt to get a token from the …AdminN
363A communication error occurred during an attempt to get a token from the …UnknownN
364Encountered error during federation passive request.AdminY
364Encountered error during federation passive requestUnknownY
365A token request was received for the relying party 'data1', but the request …AdminN
365A token request was received for the relying party 'data1', but the request …UnknownN
366A token was received from claims provider 'data1', but the token could not be …AdminN
366A token was received from claims provider 'data1', but the token could not be …UnknownN
367The audience restriction was not valid because the specified audience identifier …AdminN
367The audience restriction was not valid because the specified audience identifier …UnknownN
368The SAML Single Logout request does not correspond to the logged-in session …AdminN
368The SAML Single Logout request does not correspond to the logged-in session …UnknownN
369Processing TTP request failed with the following exception.AdminN
369Processing TTP request failed with the following exceptionUnknownN
370Incoming TTP response is not valid.AdminN
370Incoming TTP response is not validUnknownN
371Cannot find certificate to validate message/token signature obtained from claims …AdminN
371Cannot find certificate to validate message/token signature obtained from claims …UnknownN
372Authentication Failed.AdminN
372Authentication FailedUnknownN
373The artifact request from the replying party is signed with a weaker signature …AdminN
373The artifact request from the replying party is signed with a weaker signature …UnknownN
374An error occurred while building the certificate chain for the claims provider …AdminN
374An error occurred while building the certificate chain for the claims provider …UnknownN
375Policy store synchronization initiated.AdminN
375Policy store synchronization initiatedUnknownN
376An Error occurred while executing a query in SQL attribute store.AdminN
376An Error occurred while executing a query in SQL attribute storeUnknownN
377A processing error occurred in an attribute store.AdminN
377A processing error occurred in an attribute storeUnknownN
378SAML request is not signed with expected signature algorithm.AdminN
378SAML request is not signed with expected signature algorithmUnknownN
379A security token was rejected as the specified IssueInstant was before the …AdminN
379A security token was rejected as the specified IssueInstant was before the …UnknownN
380During processing of the Federation Service configuration, the element 'data1' …AdminN
380During processing of the Federation Service configuration, the element 'data1' …UnknownN
381An error occurred during an attempt to build the certificate chain for …AdminN
381An error occurred during an attempt to build the certificate chain for …UnknownN
382AD FS detected that the Federation Service has more than data1 data2 trusts …AdminN
382AD FS detected that the Federation Service has more than data1 data2 trusts …UnknownN
383The Web request failed because the web.AdminN
383The Web request failed because the webUnknownN
384The request to the Federation Service failed because the web.AdminN
384The request to the Federation Service failed because the webUnknownN
385AD FS detected that one or more certificates in AD FS configuration database …AdminN
385AD FS detected that one or more certificates in AD FS configuration database …UnknownN
386AD FS detected that none of the service certificates that are configured to be …AdminY
386AD FS detected that none of the service certificates that are configured to be …UnknownY
387AD FS detected that one or more of the certificates specified in the Federation …AdminN
387AD FS detected that one or more of the certificates specified in the Federation …UnknownN
388AD FS detected that all the service certificates have appropriate access given …AdminY
388AD FS detected that all the service certificates have appropriate access given …UnknownY
389AD FS detected that one or more of your trusts require their certificates to be …AdminN
389AD FS detected that one or more of your trusts require their certificates to be …UnknownN
390AD FS detected that none of the partner certificates that are configured to be …AdminY
390AD FS detected that none of the partner certificates that are configured to be …UnknownY
392The federation server proxy was able to successfully renew its trust with the …AdminN
392The federation server proxy was able to successfully renew its trust with the …UnknownN
393The federation server proxy could not establish a trust with the Federation …AdminN
393The federation server proxy could not establish a trust with the Federation …UnknownN
394The federation server proxy could not renew its trust with the Federation …AdminN
394The federation server proxy could not renew its trust with the Federation …UnknownN
395The trust between the federation server proxy and the Federation Service was …AdminN
395The trust between the federation server proxy and the Federation Service was …UnknownN
396The trust between the federation server proxy and the Federation Service was …AdminN
396The trust between the federation server proxy and the Federation Service was …UnknownN
397The federation server loaded the HTTP proxy configuration from WinHTTP settings.AdminY
397The federation server loaded the HTTP proxy configuration from WinHTTP settingsUnknownY
398AD FS detected that one or more certificates in the AD FS configuration database …AdminN
398AD FS detected that one or more certificates in the AD FS configuration database …UnknownN
399AD FS detected that none of the service certificates that are configured to be …AdminY
399AD FS detected that none of the service certificates that are configured to be …UnknownY
400VSS writer permissions have been granted to user data1.AdminN
400VSS writer permissions have been granted to userUnknownN
401VSS writer permissions have been revoked from user data1.AdminN
401VSS writer permissions have been revoked from userUnknownN
402Failed to add some of the certificate claims.AdminN
402Failed to add some of the certificate claimsUnknownN
407Password change failed for following user.AdminN
407Password change failed for following user:UnknownN
414An error occurred during processing of a token request.AdminN
414An error occurred during processing of a token requestUnknownN
415task_0415AdminN
415Event ID 415UnknownN
416Web configuration error: data1.AdminN
416Web configuration error:UnknownN
417Unable to add the certificate claim data1.AdminN
417Unable to add the certificate claimUnknownN
418The trust between the federation server proxy and the Federation Service was …AdminN
418The trust between the federation server proxy and the Federation Service was …UnknownN
419Unable to renew the trust between the federation server proxy and the Federation …AdminN
419Unable to renew the trust between the federation server proxy and the Federation …UnknownN
420The trust between the federation server proxy and the Federation Service was …AdminN
420The trust between the federation server proxy and the Federation Service was …UnknownN
421The trust between the federation server proxy and the Federation Service could …AdminN
421The trust between the federation server proxy and the Federation Service could …UnknownN
432Error handling request from proxy at data1.AdminN
432Error handling request from proxy atUnknownN
433Error encountered while renewing trust with the federation server proxy.AdminN
433Error encountered while renewing trust with the federation server proxyUnknownN
434The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) …AdminN
434The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) …UnknownN
435The primary AD FS token signing certificate ( thumbprint data1 ) will expire at …AdminN
435The primary AD FS token signing certificate ( thumbprint data1 ) will expire at …UnknownN
436The primary AD FS token decryption certificate ( thumbprint data1 ) will expire …AdminN
436The primary AD FS token decryption certificate ( thumbprint data1 ) will expire …UnknownN
437Error encountered while checking for pending certificate rollovers.AdminN
437Error encountered while checking for pending certificate rolloversUnknownN
438Error encountered while checking rollover status of the AD FS certificate …AdminN
438Error encountered while checking rollover status of the AD FS certificate …UnknownN
439Error encountered while attempting to read an enrollment certificate from a …AdminN
439Error encountered while attempting to read an enrollment certificate from a …UnknownN
440A Certificate Authority Enrollment Certificate was found.AdminN
440A Certificate Authority Enrollment Certificate was foundUnknownN
441A token with a bad token binding key was found.AdminN
441A token with a bad token binding key was foundUnknownN
442The CA enrollment certificate management cycle was initiated.AdminN
442The CA enrollment certificate management cycle was initiatedUnknownN
443The CA enrollment certificate management cycle was completed.AdminN
443The CA enrollment certificate management cycle was completedUnknownN
444Error encountered while checking status of the AD FS enrollment certificate.AdminN
444Error encountered while checking status of the AD FS enrollment certificateUnknownN
445A token with no binding was received on a request which is …AdminN
445A token with no binding was received on a request which is token-binding-capableUnknownN
446An SSO token with no binding was received on a request which is …AdminN
446An SSO token with no binding was received on a request which is …UnknownN
447Error encountered while attempting to update the configuration policy for the …AdminN
447Error encountered while attempting to update the configuration policy for the …UnknownN
448Error encountered while attempting to add a leased task to the database.AdminN
448Error encountered while attempting to add a leased task to the databaseUnknownN
449Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask …AdminN
449Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask …UnknownN
450Error encountered while removing the expired items from the usercode cache.AdminN
450Error encountered while removing the expired items from the usercode cacheUnknownN
451Following nodes have the reported heartbeat older than data1 UTC and will be …AdminN
451Following nodes have the reported heartbeat older than data1 UTC and will be …UnknownN
452task_0452AdminN
452Event ID 452UnknownN
500More information for the event entry with Instance ID data1.AdminN
500More information for the event entry with Instance IDUnknownN
501More information for the event entry with Instance ID Event.EventData.AdminY
501More information for the event entry with Instance IDUnknownY
502More information for the event entry with Instance ID data1.AdminN
502More information for the event entry with Instance IDUnknownN
503More information for the event entry with Instance ID data1.AdminN
503More information for the event entry with Instance IDUnknownN
504The following update was successful to the application proxy store on the …AdminN
504The following update was successful to the application proxy store on the …UnknownN
505The following update attempt to the application proxy store on the federation …AdminN
505The following update attempt to the application proxy store on the federation …UnknownN
506The following update attempt to the application proxy relying party trust on the …AdminN
506The following update attempt to the application proxy relying party trust on the …UnknownN
507The following update attempt to the application proxy relying party trust on the …AdminN
507The following update attempt to the application proxy relying party trust on the …UnknownN
508The following update attempt to the relying party trust on the federation server …AdminN
508The following update attempt to the relying party trust on the federation server …UnknownN
509The following update attempt to the relying party trust on the federation server …AdminN
509The following update attempt to the relying party trust on the federation server …UnknownN
510More information for the event entry with Instance ID data1.AdminN
510More information for the event entry with Instance IDUnknownN
511The incoming sign-in request is not allowed due to an invalid Federation Service …AdminN
511The incoming sign-in request is not allowed due to an invalid Federation Service …UnknownN
517The incoming sign-in request is not allowed due to an invalid Federation Service …AdminN
517The incoming sign-in request is not allowed due to an invalid Federation Service …UnknownN
521The request for the relying party token resulted in a failure.AdminN
521The request for the relying party token resulted in a failureUnknownN
530AD FS could not read the local claims provider trusts from the AD FS …AdminN
530AD FS could not read the local claims provider trusts from the AD FS …UnknownN
531AD FS could not read the local claims provider trusts from the AD FS …AdminN
531AD FS could not read the local claims provider trusts from the AD FS …UnknownN
540The Federation Service was was unable to return the OAuth discovery document as …AdminN
540The Federation Service was was unable to return the OAuth discovery document as …UnknownN
541An invalid value was found during processing of the proxy configuration data …AdminN
541An invalid value was found during processing of the proxy configuration data …UnknownN
542There was an error during heartbeat.AdminN
542There was an error during heartbeatUnknownN
543There was an error during heartbeat communicating to primary federation server.AdminN
543There was an error during heartbeat communicating to primary federation serverUnknownN
544Heartbeat is not performed because primary server does not support heartbeat.AdminN
544Heartbeat is not performed because primary server does not support heartbeatUnknownN
545Heartbeat is performed at primary server.AdminY
545Heartbeat is performed at primary serverUnknownY
546A current tenant certificate for Azure MFA was not found.AdminN
546A current tenant certificate for Azure MFA was not foundUnknownN
547The tenant certificate for Azure MFA has been renewed.AdminN
547The tenant certificate for Azure MFA has been renewedUnknownN
548The tenant certificate for Azure MFA will expire soon.AdminN
548The tenant certificate for Azure MFA will expire soonUnknownN
549The tenant certificate for Azure MFA has expired.AdminN
549The tenant certificate for Azure MFA has expiredUnknownN
550The data1 primary certificate cannot be used because the KeySpec must have a …AdminN
550The data1 primary certificate cannot be used because the KeySpec must have a …UnknownN
551An error occurred during processing of an OAuth logout request.AdminN
551An error occurred during processing of an OAuth logout requestUnknownN
552The session cookies were successfully deleted using the OAuth logout path.AdminY
552The session cookies were successfully deleted using the OAuth logout pathUnknownY
553The specified redirect URL was validated successfully.AdminN
553The specified redirect URL was validated successfullyUnknownN
554The specified redirect URL did not match any of the OAuth client's redirect …AdminY
554The specified redirect URL did not match any of the OAuth client's redirect URIsUnknownY
555The Windows Hello for Business key receipt could not be verified.AdminN
555The Windows Hello for Business key receipt could not be verifiedUnknownN
556Error encountered while attempting to select a master node for the account …AdminN
556Error encountered while attempting to select a master node for the account storeUnknownN
557An error occured while trying to communicate with the account store rest service …AdminN
557An error occured while trying to communicate with the account store rest service …UnknownN
558Syncronization of the Account Activity data failed.AdminN
558Syncronization of the Account Activity data failedUnknownN
559Device authentication using PKeyAuth failed.AdminN
559Device authentication using PKeyAuth failedUnknownN
560User data1 could not be found in the account database.AdminN
560User data1 could not be found in the account databaseUnknownN
561Authorization failed when connecting to the account store endpoint on server …AdminN
561Authorization failed when connecting to the account store endpoint on serverUnknownN
562An error occurred when communcating with the account store endpoint on server …AdminN
562An error occurred when communcating with the account store endpoint on serverUnknownN
563An error occurred while calculating extranet lockout status.AdminN
563An error occurred while calculating extranet lockout statusUnknownN
564The banned IP list found in Microsoft.AdminN
564The banned IP list found in MicrosoftUnknownN
565An error occurred while attemtping to update the database schema for Adfs smart …AdminN
565An error occurred while attemtping to update the database schema for Adfs smart …UnknownN
566An error occurred during processing of an OAuth device code request.AdminN
566An error occurred during processing of an OAuth device code requestUnknownN
568An error occurred during processing of an OAuth device auth request with the …AdminN
568An error occurred during processing of an OAuth device auth request with the …UnknownN
570Active Directory trust enumeration was unable to enumerate one of more domains …AdminN
570Active Directory trust enumeration was unable to enumerate one of more domains …UnknownN
571Enumeration of the Active Directory domains failed.AdminN
571Enumeration of the Active Directory domains failedUnknownN
572The Active Directory suffix from this username is not trusted by this ADFS …AdminN
572The Active Directory suffix from this username is not trusted by this ADFS …UnknownN
573The following error was generated by a threat detection module.AdminN
573The following error was generated by a threat detection moduleUnknownN
574A threat detection module failed to load.AdminN
574A threat detection module failed to loadUnknownN
575The following threat detection module was successfully loaded.AdminY
575The following threat detection module was successfully loadedUnknownY
576An unexpected error was returned from a threat detection module.AdminN
576An unexpected error was returned from a threat detection moduleUnknownN
1000An error occurred during processing of a token request.AdminY
1000An error occurred during processing of a token requestUnknownY
1020Encountered error during OAuth authorization request.AdminY
1020Encountered error during OAuth authorization requestUnknownY
1021Encountered error during OAuth token request.AdminY
1021Encountered error during OAuth token requestUnknownY
1080An error occurred while processing WebFinger request.AdminN
1080An error occurred while processing WebFinger requestUnknownN
1100The Federation Service could not authorize a request to one of the REST …AdminN
1100The Federation Service could not authorize a request to one of the REST …UnknownN
1109The Federation Service failed to connect to the LDAP account store to …AdminN
1109The Federation Service failed to connect to the LDAP account store to …UnknownN
1110The Federation Service failed to connect to the primary LDAP account store to …AdminN
1110The Federation Service failed to connect to the primary LDAP account store to …UnknownN
1111The Federation Service failed to connect to all LDAP account stores to …AdminN
1111The Federation Service failed to connect to all LDAP account stores to …UnknownN
1112The Federation Service failed to connect to the Ldap server.AdminN
1112The Federation Service failed to connect to the Ldap serverUnknownN
1113Client Json Web Key Set (JWKS) synchronization initiated.AdminY
1113Client Json Web Key Set (JWKS) synchronization initiatedUnknownY
1114Client Json Web Key Set (JWKS) synchronization completed.AdminY
1114Client Json Web Key Set (JWKS) synchronization completedUnknownY
1115The Federation Service encountered an error while retrieving the Json Web Key …AdminN
1115The Federation Service encountered an error while retrieving the Json Web Key …UnknownN
1116An error occurred during a read operation from the configuration database.AdminN
1116An error occurred during a read operation from the configuration databaseUnknownN
1117An error occurred during monitoring of the following client's Json Web Key Set …AdminN
1117An error occurred during monitoring of the following client's Json Web Key Set …UnknownN
1118An error occurred during monitoring of clients'Json Web Key Set (JWKS).AdminN
1118An error occurred during monitoring of clients'Json Web Key Set (JWKS)UnknownN
1130There was an error establishing or renewing the proxy trust.AdminN
1130There was an error establishing or renewing the proxy trustUnknownN
1131There was an error establishing or renewing the trust between the proxy and STS.AdminN
1131There was an error establishing or renewing the trust between the proxy and STSUnknownN

Event ID 100: The Federation Service started successfully.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

The Federation Service started successfully. The following service hosts have been added.

Message #

The Federation Service started successfully. The following service hosts have been added: 
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:54.297871+00:00",
    "event_record_id": 34,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Federation Server Proxy ServiceHost\r\nhttps://adfs.ludus.domain:443/adfs/services/proxytrustpolicystoretransfer\r\n\r\nMSIS0014: AD FS 1.x Trust Information Service\r\nhttps://adfs.ludus.domain/adfs/fs/federationserverservice.asmx\r\n\r\nIssuance ServiceHost\r\nhttp://localhost:80/adfs/services/trust/mexsoap\r\nhttps://adfs.ludus.domain:443/adfs/services/trust/proxymex/\r\n\r\nIssuance ServiceHost\r\nhttp://localhost/adfs/services/trust/proxymexsoap\r\nhttps://adfs.ludus.domain:443/adfs/services/trust/proxymex/\r\n\r\nIssuance ServiceHost\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/windowstransport\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/certificatemixed\r\nhttps://certauth.adfs.ludus.domain/adfs/services/trust/2005/certificatetransport\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/usernamemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/kerberosmixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/issuedtokenmixedasymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/2005/issuedtokenmixedsymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/kerberosmixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/certificatemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/usernamemixed\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/issuedtokenmixedasymmetricbasic256\r\nhttps://adfs.ludus.domain/adfs/services/trust/13/issuedtokenmixedsymmetricbasic256\r\nnet.tcp://localhost/adfs/services/trusttcp/windows\r\n\r\nSAML Metadata\r\nhttps://adfs.ludus.domain/FederationMetadata/2007-06/\r\n\r\nOther endpoints\r\n\r\nhttp://+:80/adfs/users/\r\nhttps://+:443/adfs/oauth2/authorize/\r\nhttps://+:443/adfs/ls/\r\nhttps://+:443/adfs/oauth2/logout/\r\nhttps://+:443/adfs/oauth2/token/\r\nhttps://+:443/adfs/certauth/oauth2/authorize/\r\nhttps://+:443/adfs/certauth/\r\nhttps://+:443/adfs/oauth2/\r\nhttps://+:443/adfs/oauth2/deviceauth/\r\nhttp://+:80/adfs/deviceflowresult/\r\nhttp://+:80/adfs/artifact/\r\nhttps://+:443/adfs/discovery/\r\nhttps://+:443/adfs/.well-known/\r\nhttps://+:443/.well-known/webfinger/\r\nhttps://+:443/adfs/userinfo/\r\nhttps://+:443/adfs/Proxy/EstablishTrust/\r\nhttps://+:443/adfs/backendproxytls/\r\nhttps://+:443/adfs/Proxy/\r\nhttp://+:80/adfs/Proxy/PrimaryWriter/\r\nhttps://+:443/adfs/portal/\r\nhttp://+:80/adfs/probe/\r\n"
      }
    }
  },
  "message": ""
}

Event ID 100: The Federation Service started successfully

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service started successfully. The following service hosts have been added.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 100,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:12.3574440+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 102: There was an error in enabling endpoints of Federation Service.

#
Provider
AD FS
Channel
Admin
Level
Error

Description

There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Message #

There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service. 

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 102,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:11:11.158613+00:00",
    "event_record_id": 292,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 11500
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "System.ServiceModel.FaultException`1[Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault]: ADMIN0012: OperationFault (Fault Detail is equal to Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault)."
      }
    }
  },
  "message": ""
}

Event ID 102: There was an error in enabling endpoints of Federation Service

#
Provider
AD FS
Channel
Unknown
Level
2

Description

There was an error in enabling endpoints of Federation Service. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 102,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:12:50.2286277+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "System.ServiceModel.FaultException`1[Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault]: ADMIN0012: OperationFault (Fault Detail is equal to Microsoft.IdentityServer.Protocols.PolicyStore.OperationFault)."
  }
}

Event ID 103: The Federation Service stopped successfully.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

The Federation Service stopped successfully.

Message #

The Federation Service stopped successfully.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 103,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:04:06.374579+00:00",
    "event_record_id": 36,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 103: The Federation Service stopped successfully

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service stopped successfully.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 103,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:32:28.4194277+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 104: The artifact resolution service is not running.

#
Provider
AD FS
Channel
Admin

Description

The artifact resolution service is not running. The service must be running to perform token replay detection.

Message #

The artifact resolution service is not running. The service must be running to perform token replay detection. 

User Action 
Make sure that the artifact resolution service is configured properly. Or disable token replay detection by using the Set-ADFSProperties cmdlet with the PreventTokenReplays parameter in Windows PowerShell for AD FS.

Event ID 104: The artifact resolution service is not running

#
Provider
AD FS
Channel
Unknown

Description

The artifact resolution service is not running. The service must be running to perform token replay detection.

Event ID 105: An error occurred loading an authentication provider.

#
Provider
AD FS
Channel
Admin

Description

An error occurred loading an authentication provider. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Message #

An error occurred loading an authentication provider. Fix configuration errors using PowerShell cmdlets and restart the Federation Service. 
Identifier: %1 
Context: %2 

Additional Data 
Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 105: An error occurred loading an authentication provider

#
Provider
AD FS
Channel
Unknown

Description

An error occurred loading an authentication provider. Fix configuration errors using PowerShell cmdlets and restart the Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 106: An authentication provider was successfully loaded: Identifier: 'Event.EventData', Context: 'data1'.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

An authentication provider was successfully loaded: Identifier: 'Event.EventData', Context: 'data1'.

Message #

An authentication provider was successfully loaded: Identifier: '%1', Context: '%2'

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 106,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:54.076793+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "FormsAuthentication",
          "Passive protocol pipeline"
        ]
      }
    }
  },
  "message": ""
}

Event ID 106: An authentication provider was successfully loaded: Identifier: 'data1', Context: 'data2'

#
Provider
AD FS
Channel
Unknown

Description

An authentication provider was successfully loaded: Identifier: 'data1', Context: 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 106,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:12.3403827+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 111: The Federation Service encountered an error while processing the WS-Trust request.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while processing the WS-Trust request.

Message #

The Federation Service encountered an error while processing the WS-Trust request. 
Request type: %1 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 111: The Federation Service encountered an error while processing the WS-Trust request

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while processing the WS-Trust request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 131: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

#
Provider
AD FS
Channel
Admin

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The configured value 'data2' could not be parsed as type 'data3'.

Message #

During processing of the Federation Service  configuration, the element '%1' was found to have invalid data. The configured value '%2' could not be parsed as type '%3'. 
Element: %1 
Value: %2 
Type: %3 

The Federation Service will not be able to start until this configuration element is corrected. 

User Action 
Correct the specified configuration element to conform to the given type.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 131: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data

#
Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The configured value 'data2' could not be parsed as type 'data3'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 132: During processing of the Federation Service configuration, the required element 'data1' was missing.

#
Provider
AD FS
Channel
Admin

Description

During processing of the Federation Service configuration, the required element 'data1' was missing.

Message #

During processing of the Federation Service configuration, the required element '%1' was missing. 
Element: %1 

The Federation Service will not be able to start until this configuration element is configured. 

User Action 
Configure the specified configuration element using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString

Event ID 132: During processing of the Federation Service configuration, the required element 'data1' was missing

#
Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the required element 'data1' was missing.

Fields #

NameDescription
data1 UnicodeString

Event ID 133: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

#
Provider
AD FS
Channel
Admin

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The private key for the certificate that was configured could not be accessed. The following are the values of the certificate: 
Element: %1 
Subject: %2 
Thumbprint: %3 
storeName: %4 
storeLocation: %5 
Federation Service identity: %6 

The Federation Service will not be able to start until this configuration element is corrected. 

This condition can occur when the certificate is found in the specified store but there is a problem accessing the certificate's private key. Common causes for this condition include the following: 
(1) The certificate was installed from a source that did not include the private key, such as a .cer or .p7b file. 
(2) The certificate's private key was imported (for example, from a .pfx file) into a store that is different from the store specified above. 
(3) The certificate was generated as part of a certificate request that did not specify the "Machine Key" option. 
(4) The Federation Service identity '%6' has not been granted read access to the certificate's private key. 

User Action 
If the certificate was imported from a source with no private key, choose a certificate that does have a private key, or import the certificate again from a source that includes the private key (for example, a .pfx file). 

If the certificate was imported in a user context, verify that the store specified above matches the store the certificate was imported into. 

If the certificate was generated by a certificate request that did not specify the "Machine Key" option and the key is marked as exportable, export the certificate with a private key from the user store to a .pfx file and import it again directly into the store specified in the configuration file. If the key is not marked as exportable, request a new certificate using the "Machine Key" option. 

If the Federation Service identity has not been granted read access to the certificate's private key, correct this condition using the Certificates  snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 133: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 134: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

#
Provider
AD FS
Channel
Admin

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' could not be found.

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The certificate that was identified by the findValue '%2' could not be found. 
Element: %1 
storeName: %3 
storeLocation: %4 
x509FindType: %5 
findValue: %2 

The Federation Service will not be able to start until this configuration element is corrected. 

This condition occurs when the findValue that is specified does not match any certificate in the specified store. Common causes for this condition include the following: 
(1) The certificate with the specified findValue is from a store that is different from the configured store. 
(2) The certificate was deleted from the store after configuration. 

User Action 
If the certificate exists in a different store, find the location using the certificates snap-in and correct the configuration appropriately. 

If the certificate has been deleted, configure a different certificate.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 134: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data

#
Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' could not be found.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 135: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

#
Provider
AD FS
Channel
Admin

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' was not unique.

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The certificate that was identified by the findValue '%2' was not unique. 
Element: %1 
storeName: %3 
storeLocation: %4 
x509FindType: %5 
findValue: %2 

The Federation Service will not be able to start until this configuration element is corrected. 

This condition can occur when the certificate is found in the specified store but there is more than one certificate that matches the findValue. 

User Action 
If the certificate was identified by name and there are multiple certificates of the same name, configure the certificate using the certificate thumbprint.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 135: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data

#
Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the element 'data1' was found to have invalid data. The certificate that was identified by the findValue 'data2' was not unique.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 136: During processing of the Federation Service configuration, the Federation Service encountered a configuration error.

#
Provider
AD FS
Channel
Admin

Description

During processing of the Federation Service configuration, the Federation Service encountered a configuration error.

Message #

During processing of the Federation Service configuration, the Federation Service encountered a configuration error. 

%1 

Additional Data 
%2 

The Federation Service will not be able to start until this error has been corrected. 

User Action 
Correct the specified configuration error using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 136: During processing of the Federation Service configuration, the Federation Service encountered a configuration error

#
Provider
AD FS
Channel
Unknown

Description

During processing of the Federation Service configuration, the Federation Service encountered a configuration error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 143: The Federation Service was unable to create the federation metadata document as a result of an error.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service was unable to create the federation metadata document as a result of an error.

Message #

The Federation Service was unable to create the federation metadata document as a result of an error. 
Document Path: %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 143: The Federation Service was unable to create the federation metadata document as a result of an error

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service was unable to create the federation metadata document as a result of an error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 144: The Federation Service Proxy blocked an illegitimate request made by a client, as there was no matching endpoint registered at the proxy.

#
Provider
AD FS
Channel
Admin

Message #

The Federation Service Proxy blocked an illegitimate request made by a client, as there was no matching  endpoint registered at the proxy. This could point to a DNS misconfiguration, a partially configured application  published through the proxy, or a malicious request. 
Url Path: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 144: The Federation Service Proxy blocked an illegitimate request made by a client, as there was no matching endpoint registered at the proxy

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 147: A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any ...

#
Provider
AD FS
Channel
Admin

Description

A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any known claims provider trust.

Message #

A token was received from a claims provider identified by the key '%1', but the token could not be validated because the key does not identify any known claims provider trust. 
Key: %1 

This request failed. 

User Action 
If this key represents the certificate thumbprint of a claims provider trust, verify that it  matches the signing certificate of the claims provider trust in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 147: A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any known claims provider trust

#
Provider
AD FS
Channel
Unknown

Description

A token was received from a claims provider identified by the key 'data1', but the token could not be validated because the key does not identify any known claims provider trust.

Fields #

NameDescription
data1 UnicodeString

Event ID 149: During processing of the Federation Service configuration, the attribute store 'Event.EventData' could not be loaded.

#
Provider
AD FS
Channel
Admin
Level
Error

Description

During processing of the Federation Service configuration, the attribute store 'Event.EventData' could not be loaded.

Message #

During processing of the Federation Service configuration, the attribute store '%1' could not be loaded.  
Attribute store type: %2 

User Action 
If you are using a custom attribute store, verify that the custom attribute store is configured using AD FS Management snap-in. 

Additional Data 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 149,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:31.694542+00:00",
    "event_record_id": 90,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "TestLDAPStore",
          "Microsoft.IdentityServer.ClaimsPolicy.Engine.AttributeStore.Ldap.LdapAttributeStore, Microsoft.IdentityServer.ClaimsPolicy",
          "POLICY3820: The configured connection value 'LDAP://localhost:389' for the 'TestLDAPStore' attribute store is not valid. It must be a valid LDAP:// Uri. Ex:LDAP://fabrikam.com/DC=fabrikam,DC=com"
        ]
      }
    }
  },
  "message": ""
}

Event ID 149: During processing of the Federation Service configuration, the attribute store 'data1' could not be loaded

#
Provider
AD FS
Channel
Unknown
Level
2

Description

During processing of the Federation Service configuration, the attribute store 'data1' could not be loaded.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 149,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:10:24.1548560+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "TestLDAPStoreMicrosoft.IdentityServer.ClaimsPolicy.Engine.AttributeStore.Ldap.LdapAttributeStore, Microsoft.IdentityServer.ClaimsPolicyPOLICY3820: The configured connection value 'LDAP://localhost:389' for the 'TestLDAPStore' attribute store is not valid. It must be a valid LDAP:// Uri. Ex:LDAP://fabrikam.com/DC=fabrikam,DC=com"
  }
}

Event ID 155: The Federation Service was unable to listen at 'data1' for metadata document requests due to an unexpected error.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service was unable to listen at 'data1' for metadata document requests due to an unexpected error.

Message #

The Federation Service was unable to listen at '%1' for metadata document requests due to an unexpected error. 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 155: The Federation Service was unable to listen at 'data1' for metadata document requests due to an unexpected error

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service was unable to listen at 'data1' for metadata document requests due to an unexpected error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 156: Trust monitoring cycle initiated.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

Trust monitoring cycle initiated.

Message #

Trust monitoring cycle initiated.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 156,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.122193+00:00",
    "event_record_id": 75,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 11600
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 156: Trust monitoring cycle initiated

#
Provider
AD FS
Channel
Unknown

Description

Trust monitoring cycle initiated.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 156,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.2381040+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 157: Trust monitoring cycle completed.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

Trust monitoring cycle completed.

Message #

Trust monitoring cycle completed.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 157,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.147700+00:00",
    "event_record_id": 78,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 11600
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 157: Trust monitoring cycle completed

#
Provider
AD FS
Channel
Unknown

Description

Trust monitoring cycle completed.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 157,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.2534333+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 159: The Federation Service encountered an error while writing to the following object in the configuration database.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while writing to the following object in the configuration database.

Message #

The Federation Service encountered an error while writing to the following object in the configuration database. 

Object Type: 
%1 

Name: 
%2 

Metadata document URL: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 159: The Federation Service encountered an error while writing to the following object in the configuration database

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while writing to the following object in the configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 163: An error occurred during initialization of trust monitoring.

#
Provider
AD FS
Channel
Admin

Description

An error occurred during initialization of trust monitoring. Trust monitoring against the published partner configuration will be disabled for the lifetime of this service.

Message #

An error occurred during initialization of trust monitoring. Trust monitoring against the published partner configuration will be disabled for the lifetime of this service. 

Additional Data 

Exception details: 
%1 

User Action 
If you want to try to start the trust monitoring service again, restart the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 163: An error occurred during initialization of trust monitoring

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during initialization of trust monitoring. Trust monitoring against the published partner configuration will be disabled for the lifetime of this service.

Fields #

NameDescription
data1 UnicodeString

Event ID 164: An error occurred during a read operation from the configuration database.

#
Provider
AD FS
Channel
Admin

Message #

An error occurred during a read operation from the configuration database. Trust monitoring was shut down and will be tried again after an amount of time that corresponds to the trust monitoring interval. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 164: An error occurred during a read operation from the configuration database

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 165: An error occurred during trust monitoring.

#
Provider
AD FS
Channel
Admin

Description

An error occurred during trust monitoring. The trust monitoring cycle was shut down.

Message #

An error occurred during trust monitoring. The trust monitoring cycle was shut down. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 165: An error occurred during trust monitoring

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during trust monitoring. The trust monitoring cycle was shut down.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 166: Trust monitoring service encountered an error while parsing the metadata document from 'data1'.

#
Provider
AD FS
Channel
Admin

Description

Trust monitoring service encountered an error while parsing the metadata document from 'data1'. Trust monitoring failed for.

Message #

Trust monitoring service encountered an error while parsing the metadata document from '%1'. Trust monitoring failed for: 

Object Type: 
%2 

Name: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 166: Trust monitoring service encountered an error while parsing the metadata document from 'data1'

#
Provider
AD FS
Channel
Unknown

Description

Trust monitoring service encountered an error while parsing the metadata document from 'data1'. Trust monitoring failed for.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 167: Trust monitoring service encountered an error while applying the data in the metadata document from 'data1'.

#
Provider
AD FS
Channel
Admin

Description

Trust monitoring service encountered an error while applying the data in the metadata document from 'data1'. Trust monitoring failed for.

Message #

Trust monitoring service encountered an error while applying the data in the metadata document from '%1'. Trust monitoring failed for: 

Object Type: 
%2 

Name: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 167: Trust monitoring service encountered an error while applying the data in the metadata document from 'data1'

#
Provider
AD FS
Channel
Unknown

Description

Trust monitoring service encountered an error while applying the data in the metadata document from 'data1'. Trust monitoring failed for.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 168: The Federation Service encountered an error while retrieving the federation metadata document from 'data1'.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while retrieving the federation metadata document from 'data1'. The monitoring for the following trusts failed.

Message #

The Federation Service encountered an error while retrieving the federation metadata document from '%1'. The monitoring for the following trusts failed: 

Claims providers: 
%2 

Relying parties: 
%3 

Additional Data 

Exception details: 
%4 

Additional details: 
%5 

User Action 
Make sure federation metadata URL is accessible. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 168: The Federation Service encountered an error while retrieving the federation metadata document from 'data1'

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while retrieving the federation metadata document from 'data1'. The monitoring for the following trusts failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 171: The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

#
Provider
AD FS
Channel
Admin

Description

The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

Message #

The trust monitoring service automatically updated the trust of '%1' successfully with the partner's published changes.

Fields #

NameDescription
data1 UnicodeString

Event ID 171: The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes

#
Provider
AD FS
Channel
Unknown

Description

The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

Fields #

NameDescription
data1 UnicodeString

Event ID 173: The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

#
Provider
AD FS
Channel
Admin

Description

The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

Message #

The trust monitoring service automatically updated the trust of '%1' successfully with the partner's published changes. 

Additional Data 
Warnings: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 173: The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes

#
Provider
AD FS
Channel
Unknown

Description

The trust monitoring service automatically updated the trust of 'data1' successfully with the partner's published changes.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 174: Trust monitoring service detected changes in policy of 'data1', but did not automatically apply the changes on the trust partner.

#
Provider
AD FS
Channel
Admin

Description

Trust monitoring service detected changes in policy of 'data1', but did not automatically apply the changes on the trust partner.

Message #

Trust monitoring service detected changes in policy of '%1', but did not automatically apply the changes on the trust partner. 

Additional Data 
Warnings: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 174: Trust monitoring service detected changes in policy of 'data1', but did not automatically apply the changes on the trust partner

#
Provider
AD FS
Channel
Unknown

Description

Trust monitoring service detected changes in policy of 'data1', but did not automatically apply the changes on the trust partner.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 180: An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version 'data2' to Minor Version 'data3'.

#
Provider
AD FS
Channel
Admin

Description

An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version 'data2' to Minor Version 'data3'.

Message #

An error occurred while upgrading FarmBehaviorLevel '%1' from Minor Version '%2' to Minor Version '%3'. 

Additional Data 
Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 180: An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version 'data2' to Minor Version 'data3'

#
Provider
AD FS
Channel
Unknown

Description

An error occurred while upgrading FarmBehaviorLevel 'data1' from Minor Version 'data2' to Minor Version 'data3'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 181: AD FS could not enable the new KDFv2 feature automatically because of missing Windows Updates on one or more nodes of the farm.

#
Provider
AD FS
Channel
Admin

Message #

AD FS could not enable the new KDFv2 feature automatically because of missing Windows Updates on one or more nodes of the farm. Please make sure that all the farm nodes are patched with the latest Windows Updates. AD FS checks regularly for the required updates to enable the new KDFv2 feature. An event 182 will be logged when a check is successful. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 181: AD FS could not enable the new KDFv2 feature automatically because of missing Windows Updates on one or more nodes of the farm

#
Provider
AD FS
Channel
Unknown

Event ID 182: AD FS enabled the new KDFv2 feature successfully.

#
Provider
AD FS
Channel
Admin

Description

AD FS enabled the new KDFv2 feature successfully. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Message #

AD FS enabled the new KDFv2 feature successfully. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 182: AD FS enabled the new KDFv2 feature successfully

#
Provider
AD FS
Channel
Unknown

Description

AD FS enabled the new KDFv2 feature successfully. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 183: KDFv2 feature is disabled on AD FS farm.

#
Provider
AD FS
Channel
Admin

Message #

KDFv2 feature is disabled on AD FS farm. Please make sure that all the farm nodes are patched with latest Windows Updates and the KDFv2 feature is enabled to enhance the security of the farm. For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2153807.

Event ID 183: KDFv2 feature is disabled on AD FS farm

#
Provider
AD FS
Channel
Unknown

Event ID 184: A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identi...

#
Provider
AD FS
Channel
Admin

Description

A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identify any known relying party trust.

Message #

A token request was received for a relying party identified by the key '%1', but the request could not be fulfilled because the key does not identify any known relying party trust. 
Key: %1 

This request failed. 

User Action 
If this key represents a URI for which a token should be issued, verify that its prefix matches the relying party trust that is configured in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 184: A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identify any known relying party trust

#
Provider
AD FS
Channel
Unknown

Description

A token request was received for a relying party identified by the key 'data1', but the request could not be fulfilled because the key does not identify any known relying party trust.

Fields #

NameDescription
data1 UnicodeString

Event ID 186: The Federation Service could not fulfill the token-issuance request.

#
Provider
AD FS
Channel
Admin

Message #

The Federation Service could not fulfill the token-issuance request. More than  one claim based on SamlNameIdentifierClaimResource was produced after the issuance  transform rules were applies for relying party '%2'. See event 500 with the same Instance ID for claims after application of issuance transform rules. 

Additional Data 
Instance ID: %1 

User Action 
Ensure that the issuance transform rules that are configured for the relying party do not result in multiple claims based on SamlNameIdentifierClaimResource.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 186: The Federation Service could not fulfill the token-issuance request

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 187: AD FS server received a JWT token without nonce in the assertion and it was accepted based on the current configuration setting of EnforceNonceInJWT.

#
Provider
AD FS
Channel
Admin

Message #

AD FS server received a JWT token without nonce in the assertion and it was accepted based on the current configuration setting of EnforceNonceInJWT. However, it indicates a potential replay of the JWT token by a malicious client or the possibility that the client is not patched with latest Windows Updates. Please make sure to update the EnforceNonceInJWT setting to reject all such JWT tokens after patching the clients with latest Windows Updates. 
For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2238156. 

Additional Data 
    Client IP: %1 
    User Agent: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 187: AD FS server received a JWT token without nonce in the assertion and it was accepted based on the current configuration setting of EnforceNonceInJWT

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 188: AD FS server is not configured to reject JWT tokens that did not have nonce in the assertion.

#
Provider
AD FS
Channel
Admin

Message #

AD FS server is not configured to reject JWT tokens that did not have nonce in the assertion. The corresponding setting (EnforceNonceInJWT) should be enabled for security reasons after making sure that all the clients are patched with the latest Windows Updates. 
The event 187 indicates the instances where AD FS received such tokens and accepted due to the current setting of EnforceNonceInJWT. 
For more information on this, please see https://go.microsoft.com/fwlink/?linkid=2238156.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 188,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:12.3532216+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 188: AD FS server is not configured to reject JWT tokens that did not have nonce in the assertion

#
Provider
AD FS
Channel
Unknown

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 188,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:12.3532216+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 189: AD FS server received an OAuth authorization request in the device code flow without a Cross Site Request Forgery (CSRF) protection code in the Use...

#
Provider
AD FS
Channel
Admin

Message #

AD FS server received an OAuth authorization request in the device code flow without a Cross Site Request Forgery (CSRF) protection code in the UserCode cookie. This indicates that the AD FS server that issued the UserCode cookie has not  been patched with the latest Windows security updates. It is recommended to install the latest Windows security updates  on all the AD FS servers of the farm in order to be protected from CSRF attacks. Your environment is currently vulnerable  to the CSRF attacks in OAuth device code flow due to one or more unpatched AD FS servers. 

Additional Data 
    Usercode: %1 
    Client IP: %2 
    User Agent: %3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 189: AD FS server received an OAuth authorization request in the device code flow without a Cross Site Request Forgery (CSRF) protection code in the UserCode cookie

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 193: The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type.

Message #

The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type. 
Comparison type: %1 
Desired authentication type(s): %2 
Relying party: %3 

This request failed. 

User Action 
Use the AD FS PowerShell commands to configure the authentication context order property. 
Ensure that the relying party is configured to request the correct authentication type.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 193: The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service could not satisfy a token request because the relying party requested an unknown authentication type.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 197: The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of '%...

#
Provider
AD FS
Channel
Admin

Description

The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'data2' for the relying party 'data3'.

Message #

The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of '%2' for the relying party '%3'. 
Authentication type: %1 
Desired authentication type(s): %2 
Relying party: %3 

This request failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 197: The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'data2' for the relying party 'data3'

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service could not satisfy a token request because the accompanying credentials do not meet the authentication type requirement of 'data2' for the relying party 'data3'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 198: The federation server proxy started successfully.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy started successfully.

Message #

The federation server proxy started successfully.

Event ID 198: The federation server proxy started successfully

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy started successfully.

Event ID 199: The federation server proxy could not be started.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy could not be started.

Message #

The federation server proxy could not be started. 
Reason: %1 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 199: The federation server proxy could not be started

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy could not be started.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 200: The federation server proxy stopped successfully.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy stopped successfully.

Message #

The federation server proxy stopped successfully.

Event ID 200: The federation server proxy stopped successfully

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy stopped successfully.

Event ID 201: The Federation Service data1 encountered an Access Denied error while trying to register one or more endpoint URLs.

#
Provider
AD FS
Channel
Admin

Message #

The Federation Service %1 encountered an Access Denied error while trying to register one or more endpoint URLs. This condition typically occurs when the ACL for the endpoint URL is missing or the HTTP namespace in the ACL is not a prefix match of the endpoint URL. 

 The %1 could not be opened. 

User Action 
Ensure that a valid ACL for each of the URLs has been configured on this computer. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 201: The Federation Service data1 encountered an Access Denied error while trying to register one or more endpoint URLs

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 202: The Federation Service data1 could not be opened.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service data1 could not be opened.

Message #

The Federation Service %1 could not be opened. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 202: The Federation Service data1 could not be opened

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service could not be opened.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 203: The Federation Service data1 could not be shut down properly.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service data1 could not be shut down properly.

Message #

The Federation Service %1 could not be shut down properly. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 203: The Federation Service data1 could not be shut down properly

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service could not be shut down properly.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 204: The Federation Service data1 could not be closed.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service data1 could not be closed.

Message #

The Federation Service %1 could not be closed. 

Additional Data 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 204: The Federation Service data1 could not be closed

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service could not be closed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 206: The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint addr...

#
Provider
AD FS
Channel
Admin

Description

The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint address.

Message #

The Federation Service could not fulfill the token-issuance request because the relying party '%1' is missing a WS-Federation Passive endpoint address. 
Relying party: %1 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure a WS-Federation Passive endpoint on this relying party.

Fields #

NameDescription
data1 UnicodeString

Event ID 206: The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint address

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service could not fulfill the token-issuance request because the relying party 'data1' is missing a WS-Federation Passive endpoint address.

Fields #

NameDescription
data1 UnicodeString

Event ID 207: An attempt to write to the Security event log failed.

#
Provider
AD FS
Channel
Admin

Description

An attempt to write to the Security event log failed.

Message #

An attempt to write to the Security event log failed. 

Additional Data 
Windows error code: %1 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 207: An attempt to write to the Security event log failed

#
Provider
AD FS
Channel
Unknown

Description

An attempt to write to the Security event log failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 208: An error occurred during an attempt to register the event source for the Security log.

#
Provider
AD FS
Channel
Admin

Description

An error occurred during an attempt to register the event source for the Security log.

Message #

An error occurred during an attempt to register the event source for the Security log.  

User Action 
Ensure that the Federation Service has the correct permissions to write to the Security log.

Event ID 208: An error occurred during an attempt to register the event source for the Security log

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during an attempt to register the event source for the Security log.

Event ID 209: The Security log event source for the Federation Service could not be registered.

#
Provider
AD FS
Channel
Admin

Description

The Security log event source for the Federation Service could not be registered.

Message #

The Security log event source for the Federation Service could not be registered. 

Additional Data 
Windows error code: %1 
Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 209: The Security log event source for the Federation Service could not be registered

#
Provider
AD FS
Channel
Unknown

Description

The Security log event source for the Federation Service could not be registered.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 215: The Federation Service at 'data1' did not return any WS-Trust endpoints to be published by the federation server proxy.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service at 'data1' did not return any WS-Trust endpoints to be published by the federation server proxy.

Message #

The Federation Service at '%1' did not return any WS-Trust endpoints to be published by the federation server proxy. 

User Action 
If you want to publish WS-Trust endpoints to the federation server proxy, make sure that the endpoints are enabled for proxy use on the federation server.

Fields #

NameDescription
data1 UnicodeString

Event ID 215: The Federation Service at 'data1' did not return any WS-Trust endpoints to be published by the federation server proxy

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service at 'data1' did not return any WS-Trust endpoints to be published by the federation server proxy.

Fields #

NameDescription
data1 UnicodeString

Event ID 217: A WS-Trust endpoint that was configured could not be opened.

#
Provider
AD FS
Channel
Admin

Description

A WS-Trust endpoint that was configured could not be opened.

Message #

A WS-Trust endpoint that was configured could not be opened. 

Additional Data 
Address: %1 
Mode: %2 

Error: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 217: A WS-Trust endpoint that was configured could not be opened

#
Provider
AD FS
Channel
Unknown

Description

A WS-Trust endpoint that was configured could not be opened.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 218: The federation server proxy received error code 'data2' while making a request to the Federation Service at 'data1'.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy received error code 'data2' while making a request to the Federation Service at 'data1'. This could mean that the Federation Service is not started on the remote host.

Message #

The federation server proxy received error code '%2' while making a request to the Federation Service at '%1'. This could mean that the Federation Service is not started on the remote host. 

User Action 
Verify that the Federation Service is running on the remote host.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 218: The federation server proxy received error code 'data2' while making a request to the Federation Service at 'data1'

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy received error code 'data2' while making a request to the Federation Service at 'data1'. This could mean that the Federation Service is not started on the remote host.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 220: The Federation Service configuration could not be loaded correctly from the AD FS configuration database.

#
Provider
AD FS
Channel
Admin
Level
Error

Description

The Federation Service configuration could not be loaded correctly from the AD FS configuration database.

Message #

The Federation Service configuration could not be loaded correctly from the AD FS configuration database. 

Additional Data 
Error:  
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 220,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:11:11.159207+00:00",
    "event_record_id": 297,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 11500
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "ADMIN0012: OperationFault"
      }
    }
  },
  "message": ""
}

Event ID 220: The Federation Service configuration could not be loaded correctly from the AD FS configuration database

#
Provider
AD FS
Channel
Unknown
Level
2

Description

The Federation Service configuration could not be loaded correctly from the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 220,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:12:50.2296755+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "ADMIN0012: OperationFault"
  }
}

Event ID 221: A change to the token service configuration was detected, but there was an error reloading the changes to configuration.

#
Provider
AD FS
Channel
Admin
Level
Error

Description

A change to the token service configuration was detected, but there was an error reloading the changes to configuration.

Message #

A change to the token service configuration was detected, but there was an error reloading the changes to configuration. 

Additional Data 
Error:  
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 221,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:10:50.898809+00:00",
    "event_record_id": 229,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 8536
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "ADMIN0012: OperationFault"
      }
    }
  },
  "message": ""
}

Event ID 221: A change to the token service configuration was detected, but there was an error reloading the changes to configuration

#
Provider
AD FS
Channel
Unknown
Level
2

Description

A change to the token service configuration was detected, but there was an error reloading the changes to configuration.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 221,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:12:50.2295701+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "ADMIN0012: OperationFault"
  }
}

Event ID 222: The federation server proxy was unable to complete a request to the Federation Service at address 'data1' because of a time-out.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy was unable to complete a request to the Federation Service at address 'data1' because of a time-out. This might mean that the Federation Service is currently unavailable.

Message #

The federation server proxy was unable to complete a request to the Federation Service at address '%1' because of a time-out. This might mean that the Federation Service is currently unavailable. 

User Action 
Verify that the Federation Service is running.

Fields #

NameDescription
data1 UnicodeString

Event ID 222: The federation server proxy was unable to complete a request to the Federation Service at address 'data1' because of a time-out

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy was unable to complete a request to the Federation Service at address 'data1' because of a time-out. This might mean that the Federation Service is currently unavailable.

Fields #

NameDescription
data1 UnicodeString

Event ID 223: Claim description could not be loaded correctly from the database.

#
Provider
AD FS
Channel
Admin

Description

Claim description could not be loaded correctly from the database.

Message #

Claim description could not be loaded correctly from the database. 

Additional Data 
Error:  
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 223: Claim description could not be loaded correctly from the database

#
Provider
AD FS
Channel
Unknown

Description

Claim description could not be loaded correctly from the database.

Fields #

NameDescription
data1 UnicodeString

Event ID 224: The federation server proxy configuration could not be updated with the latest configuration on the federation service.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy configuration could not be updated with the latest configuration on the federation service.

Message #

The federation server proxy configuration could not be updated with the latest configuration on the federation service. 

Additional Data 
Error:  
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 224: The federation server proxy configuration could not be updated with the latest configuration on the federation service

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy configuration could not be updated with the latest configuration on the federation service.

Fields #

NameDescription
data1 UnicodeString

Event ID 225: A change to the service configuration was detected, but there was an error reloading the changes to data1.

#
Provider
AD FS
Channel
Admin

Description

A change to the service configuration was detected, but there was an error reloading the changes to data1.

Message #

A change to the service configuration was detected, but there was an error reloading the changes to %1. 

Additional Data 
Error:  
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 225: A change to the service configuration was detected, but there was an error reloading the changes to

#
Provider
AD FS
Channel
Unknown

Description

A change to the service configuration was detected, but there was an error reloading the changes to .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 230: The federation server proxy has detected congestion, caused by high latency response times, on the Federation Service.

#
Provider
AD FS
Channel
Admin

Message #

The federation server proxy has detected congestion, caused by high latency response times, on the Federation Service. The load might be above the Federation Service operating capacity, or there might be network connectivity issues. Request throttling has been enforced to limit the number of concurrent requests to the following size: %1. 

User Action 
Verify that the Federation Service is operating within its operating capacity. 
Verify that the Federation Service is not experiencing network outages.

Fields #

NameDescription
data1 UnicodeString

Event ID 230: The federation server proxy has detected congestion, caused by high latency response times, on the Federation Service

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 238: The Federation Service failed to find a domain controller for the domain data1.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service failed to find a domain controller for the domain data1.

Message #

The Federation Service failed to find a domain controller for the domain %1. 

Additional Data 
Domain Name: %1 
Error: %2 

User Action 
Use Nltest to determine why DC locator is failing. Nltest is part of the Windows Support Tools.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 238: The Federation Service failed to find a domain controller for the domain

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service failed to find a domain controller for the domain .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 244: The Federation Service was unable to listen at 'data1' for WS-MetadataExchange requests due to an unexpected error.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service was unable to listen at 'data1' for WS-MetadataExchange requests due to an unexpected error.

Message #

The Federation Service was unable to listen at '%1' for WS-MetadataExchange requests due to an unexpected error. 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 244: The Federation Service was unable to listen at 'data1' for WS-MetadataExchange requests due to an unexpected error

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service was unable to listen at 'data1' for WS-MetadataExchange requests due to an unexpected error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 245: The federation server proxy successfully retrieved and updated its configuration from the Federation Service 'data1'.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy successfully retrieved and updated its configuration from the Federation Service 'data1'.

Message #

The federation server proxy successfully retrieved and updated its configuration from the Federation Service '%1'.

Fields #

NameDescription
data1 UnicodeString

Event ID 245: The federation server proxy successfully retrieved and updated its configuration from the Federation Service 'data1'

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy successfully retrieved and updated its configuration from the Federation Service 'data1'.

Fields #

NameDescription
data1 UnicodeString

Event ID 246: The Federation Service encountered an error during an attempt to connect to a LDAP server at data1.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error during an attempt to connect to a LDAP server at data1.

Message #

The Federation Service encountered an error during an attempt to connect to a LDAP server at %1. 

Additional Data 
Domain Name: %1 
LDAP server hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from LDAP server (if available): %7 
Exception Details: 
 %8 

User Action 
 Check the network connectivity to the LDAP server. Also, check whether the LDAP server is configured properly.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 246: The Federation Service encountered an error during an attempt to connect to a LDAP server at

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error during an attempt to connect to a LDAP server at .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 247: The Federation Service encountered an error while connecting to a global catalog server at data1.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while connecting to a global catalog server at data1.

Message #

The Federation Service encountered an error while connecting to a global catalog server at %1. 

Additional Data 
Domain Name: %1 
Global Catalog hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from server (if available): %7 
Exception Details: 
 
 %8 

User Action 
Troubleshoot the network connectivity to the global catalog server. Also, verify that the global catalog server is configured properly.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 247: The Federation Service encountered an error while connecting to a global catalog server at

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while connecting to a global catalog server at .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 248: The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1. The error message is 'data2'.

Message #

The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at %1. The error message is '%2'. 

User Action 
Make sure that the Federation Service is running. Troubleshoot network connectivity. If the trust between the federation server proxy and the Federation Service is lost, run the Federation Server Proxy Configuration Wizard again.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 248: The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy was not able to retrieve the list of endpoints from the Federation Service at data1. The error message is 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 249: The certificate identified by thumbprint 'data1' could not be found in the certificate store.

#
Provider
AD FS
Channel
Admin

Message #

The certificate identified by thumbprint '%1' could not be found in the certificate store.  In certificate rollover scenarios, this can potentially cause a failure when the Federation Service is signing or decrypting using this certificate. 

User Action 
Ensure that the certificate that is identified by thumbprint '%1' has been added to the Localmachine "My" store and that it is accessible by the service account of the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 249: The certificate identified by thumbprint 'data1' could not be found in the certificate store

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 250: Expiration of the artifact failed.

#
Provider
AD FS
Channel
Admin

Description

Expiration of the artifact failed.

Message #

Expiration of the artifact failed. 

Additional Data 
Exception message: 
%1 

User Action 
Ensure that the artifact storage server is configured properly. Troubleshoot network connectivity to the artifact storage server.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 250,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-06T11:31:03.4208627+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 250: Expiration of the artifact failed

#
Provider
AD FS
Channel
Unknown

Description

Expiration of the artifact failed.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 250,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-06T11:31:03.4208627+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 251: Attribute store 'Event.EventData' is loaded successfully.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

Attribute store 'Event.EventData' is loaded successfully.

Message #

Attribute store '%1' is loaded successfully.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 251,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:52.787344+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Active Directory"
      }
    }
  },
  "message": ""
}

Event ID 251: Attribute store 'data1' is loaded successfully

#
Provider
AD FS
Channel
Unknown

Description

Attribute store 'data1' is loaded successfully.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 251,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:10.8344846+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 252: The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service.

#
Provider
AD FS
Channel
Admin

Description

The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service.

Message #

The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service. 

Endpoints added: 
%1 

Endpoints removed: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 252: The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service

#
Provider
AD FS
Channel
Unknown

Description

The AD FS proxy service made changes to the endpoints it is listening on based on the configuration it retrieved from the Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 253: AD FS proxy service failed to start a listener for the endpoint 'data1'.

#
Provider
AD FS
Channel
Admin

Description

AD FS proxy service failed to start a listener for the endpoint 'data1'.

Message #

AD FS proxy service failed to start a listener for the endpoint '%1' 
Exceptiondetails: 
%2 

User action: Ensure that no conflicting SSL bindings are configured for the specified endpoint.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 253: AD FS proxy service failed to start a listener for the endpoint 'data1'

#
Provider
AD FS
Channel
Unknown

Description

AD FS proxy service failed to start a listener for the endpoint 'data1'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 258: The relying party 'data1' is not configured with SAML Assertion Consumer Services.

#
Provider
AD FS
Channel
Admin

Description

The relying party 'data1' is not configured with SAML Assertion Consumer Services.

Message #

The relying party '%1' is not configured with SAML Assertion Consumer Services. 
Relying party: %1 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure one or more Assertion Consumer Services for this relying party.

Fields #

NameDescription
data1 UnicodeString

Event ID 258: The relying party 'data1' is not configured with SAML Assertion Consumer Services

#
Provider
AD FS
Channel
Unknown

Description

The relying party 'data1' is not configured with SAML Assertion Consumer Services.

Fields #

NameDescription
data1 UnicodeString

Event ID 259: The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'.

#
Provider
AD FS
Channel
Admin

Description

The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'.

Message #

The request specified an Assertion Consumer Service index '%1' that is not  configured on the relying party '%2'. 
Assertion Consumer Service index: %1 
Relying party: %2 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an Assertion Consumer Service with the specified index for this relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 259: The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'

#
Provider
AD FS
Channel
Unknown

Description

The request specified an Assertion Consumer Service index 'data1' that is not configured on the relying party 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 260: The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'.

#
Provider
AD FS
Channel
Admin

Description

The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'.

Message #

The request specified an Assertion Consumer Service protocol binding '%1' that is not  configured on the relying party '%2'. 
Assertion Consumer Service protocol binding: %1 
Relying party: %2 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an Assertion Consumer Service with the specified protocol binding for this relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 260: The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'

#
Provider
AD FS
Channel
Unknown

Description

The request specified an Assertion Consumer Service protocol binding 'data1' that is not configured on the relying party 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 261: The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'.

#
Provider
AD FS
Channel
Admin

Description

The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'.

Message #

The request specified an Assertion Consumer Service URL '%1' that is not  configured on the relying party '%2'. 
Assertion Consumer Service URL: %1 
Relying party: %2 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an Assertion Consumer Service with the specified URL for this relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 261: The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'

#
Provider
AD FS
Channel
Unknown

Description

The request specified an Assertion Consumer Service URL 'data1' that is not configured on the relying party 'data2'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 262: The artifact resolution request failed.

#
Provider
AD FS
Channel
Admin

Description

The artifact resolution request failed.

Message #

The artifact resolution request failed. 

Additional Data 
Exception message: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 262: The artifact resolution request failed

#
Provider
AD FS
Channel
Unknown

Description

The artifact resolution request failed.

Fields #

NameDescription
data1 UnicodeString

Event ID 273: The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'.

#
Provider
AD FS
Channel
Admin

Description

The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'.

Message #

The request specified an assertion consumer service  that is not  configured or not supported on the relying party '%4'. 
Request parameters: '%1', '%2', '%3' 
Relying party: %4 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure an assertion consumer service with the specified parameters for this relying party. Also, check whether the artifact resolution service is enabled if the SAML artifact is requested.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 273: The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'

#
Provider
AD FS
Channel
Unknown

Description

The request specified an assertion consumer service that is not configured or not supported on the relying party 'data4'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 274: The federation server proxy encountered an error while trying to listen on one of the proxy endpoints.

#
Provider
AD FS
Channel
Admin

Message #

The federation server proxy encountered an error while trying to listen on one of the proxy endpoints.  The federation server proxy will not be able to start until it can listen on all required proxy endpoints. 
Proxy Endpoints: 
 
%1 

User Action 
Ensure that the permissions on the URLs of the proxy endpoints allow the federation server proxy security account (the default is Network Service) to listen on them.

Fields #

NameDescription
data1 UnicodeString

Event ID 274: The federation server proxy encountered an error while trying to listen on one of the proxy endpoints

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 275: The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service data1.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service data1.

Message #

The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service %1. 
Error Message: 
%2 

User Action 
Ensure that the SSL certificate for Federation Service '%1' is valid and trusted by the federation server proxy.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 275: The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy could not establish a trust relationship for the SSL secure channel with the Federation Service .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 276: The federation server proxy was not able to authenticate to the Federation Service.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy was not able to authenticate to the Federation Service.

Message #

The federation server proxy was not able to authenticate to the Federation Service. 

User Action 
Ensure that the proxy is trusted by the Federation Service. To do this, log on to the proxy computer with the host name that is identified in the certificate subject name and re-establish trust between the proxy and the Federation Service using the Install-WebApplicationProxy cmdlet. 

Additional Data 

Certificate details: 

Subject Name: 
%1 

Thumbprint: 
%2 

NotBefore Time: 
%3 

NotAfter Time: 
%4 

Client endpoint: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 276: The federation server proxy was not able to authenticate to the Federation Service

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy was not able to authenticate to the Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 277: The Federation Service encountered an unexpected exception and has shut down.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an unexpected exception and has shut down.

Message #

The Federation Service encountered an unexpected exception and has shut down. 

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 277: The Federation Service encountered an unexpected exception and has shut down

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an unexpected exception and has shut down.

Fields #

NameDescription
data1 UnicodeString

Event ID 278: The SAML artifact resolution endpoint is not configured or it is disabled.

#
Provider
AD FS
Channel
Admin
Level
Warning

Description

The SAML artifact resolution endpoint is not configured or it is disabled.

Message #

The SAML artifact resolution endpoint is not configured or it is disabled. 

User Action 
If SAML artifact resolution is required, use the AD FS Management snap-in to configure or enable the SAML artifact resolution endpoint.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 278,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:53.726364+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 278: The SAML artifact resolution endpoint is not configured or it is disabled

#
Provider
AD FS
Channel
Unknown

Description

The SAML artifact resolution endpoint is not configured or it is disabled.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 278,
    "level": "Warning",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:11.7775437+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 279: Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database.

#
Provider
AD FS
Channel
Admin

Description

Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database.

Message #

Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database.  
SAML artifact: %1 

This request failed. 

User Action 
Verify that a claims provider trust exists in the AD FS configuration database. 
Make sure that the data for the claims provider trust is up to date.

Fields #

NameDescription
data1 UnicodeString

Event ID 279: Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database

#
Provider
AD FS
Channel
Unknown

Description

Unable to find a claims provider trust for SAML artifact resolution in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 280: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service config...

#
Provider
AD FS
Channel
Admin

Description

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured.

Message #

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured.  
Claims provider trust: %1 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Add the artifact resolution service endpoint to the claims provider trust.

Fields #

NameDescription
data1 UnicodeString

Event ID 280: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured

#
Provider
AD FS
Channel
Unknown

Description

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the artifact resolution service configured.

Fields #

NameDescription
data1 UnicodeString

Event ID 281: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpo...

#
Provider
AD FS
Channel
Admin

Description

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured.

Message #

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured.  
Claims provider trust: %1 
Required endpoint index: %2 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Use the AD FS Management snap-in to configure the artifact resolution endpoint with the  specified index.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 281: Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured

#
Provider
AD FS
Channel
Unknown

Description

Unable to resolve the SAML artifact from the claims provider because the claims provider trust does not have the required artifact resolution endpoint with the specified index configured.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 283: Unable to resolve the SAML artifact.

#
Provider
AD FS
Channel
Admin

Description

Unable to resolve the SAML artifact. The artifact resolution request to the claims provider failed. See inner exception for more details.

Message #

Unable to resolve the SAML artifact. The artifact resolution request to the claims provider failed. See inner exception for more details. 
SAML Artifact: %1 
Claims provider: %2 
Inner exception: 
%3 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Verify network connectivity. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 283: Unable to resolve the SAML artifact

#
Provider
AD FS
Channel
Unknown

Description

Unable to resolve the SAML artifact. The artifact resolution request to the claims provider failed. See inner exception for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 284: Unable to resolve the SAML artifact.

#
Provider
AD FS
Channel
Admin

Description

Unable to resolve the SAML artifact. A malformed response was received from the claims provider. See inner exception for more details.

Message #

Unable to resolve the SAML artifact. A malformed response was received from the claims provider. See inner exception for more details. 
SAML artifact: %1 
Claims provider: %2 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 284: Unable to resolve the SAML artifact

#
Provider
AD FS
Channel
Unknown

Description

Unable to resolve the SAML artifact. A malformed response was received from the claims provider. See inner exception for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 285: The SAML artifact was resolved, but the response is empty or does not contain expected assertions.

#
Provider
AD FS
Channel
Admin

Description

The SAML artifact was resolved, but the response is empty or does not contain expected assertions.

Message #

The SAML artifact was resolved, but the response is empty or does not contain expected assertions. 
SAML artifact: %1 
Claims provider: %2 

This request failed. 

User Action 
For more information, contact the claims provider.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 285: The SAML artifact was resolved, but the response is empty or does not contain expected assertions

#
Provider
AD FS
Channel
Unknown

Description

The SAML artifact was resolved, but the response is empty or does not contain expected assertions.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 286: Cannot connect to the artifact database.

#
Provider
AD FS
Channel
Admin

Description

Cannot connect to the artifact database.

Message #

Cannot connect to the artifact database. 
Connection string: %1 
Error message: 

%2 

User Action 
Ensure that the artifact database is configured properly. Use the Set-ADFSProperties cmdlet with the ArtifactDbConnection parameter in the Windows PowerShell for AD FS to modify the connection string, if necessary. 
Troubleshoot the connectivity to the artifact storage .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 286: Cannot connect to the artifact database

#
Provider
AD FS
Channel
Unknown

Description

Cannot connect to the artifact database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 287: Cannot add the artifact to the artifact database.

#
Provider
AD FS
Channel
Admin

Description

Cannot add the artifact to the artifact database. See exception message for more details.

Message #

Cannot add the artifact to the artifact database. See exception message for more details. 
Artifact ID: %1 
Inner exception details: 
%2 

User Action 
Ensure that the artifact database is configured properly.  
Troubleshoot the connectivity to the artifact database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 287: Cannot add the artifact to the artifact database

#
Provider
AD FS
Channel
Unknown

Description

Cannot add the artifact to the artifact database. See exception message for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 288: Cannot get the artifact from storage.

#
Provider
AD FS
Channel
Admin

Description

Cannot get the artifact from storage. See exception message for more details.

Message #

Cannot get the artifact from storage. See exception message for more details. 
ArtifactId: %1 
Inner exception details: 
%2 

User Action 
Ensure that the artifact storage in the AD FS configuration database is configured properly.  
Troubleshoot connectivity to the artifact storage in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 288: Cannot get the artifact from storage

#
Provider
AD FS
Channel
Unknown

Description

Cannot get the artifact from storage. See exception message for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 289: Cannot remove the artifact from storage.

#
Provider
AD FS
Channel
Admin

Description

Cannot remove the artifact from storage. See inner exception message for more details.

Message #

Cannot remove the artifact from storage. See inner exception message for more details. 
ArtifactId: %1 
Inner exception details: 
%2 

User Action 
Ensure that the artifact storage in the AD FS configuration database is configured properly.  
Troubleshoot connectivity to the artifact storage in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 289: Cannot remove the artifact from storage

#
Provider
AD FS
Channel
Unknown

Description

Cannot remove the artifact from storage. See inner exception message for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 290: Cannot set expiration for the artifacts in storage.

#
Provider
AD FS
Channel
Admin

Description

Cannot set expiration for the artifacts in storage. See inner exception message for more details.

Message #

Cannot set expiration for the artifacts in storage. See inner exception message for more details. 
Inner exception details: 
%1 

User Action 
Ensure that the artifact storage in the AD FS configuration database is configured properly.  
Troubleshoot connectivity to the artifact storage in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString

Event ID 290: Cannot set expiration for the artifacts in storage

#
Provider
AD FS
Channel
Unknown

Description

Cannot set expiration for the artifacts in storage. See inner exception message for more details.

Fields #

NameDescription
data1 UnicodeString

Event ID 291: The artifact resolution service could not be started.

#
Provider
AD FS
Channel
Admin

Description

The artifact resolution service could not be started.

Message #

The artifact resolution service could not be started. 

Additional Data 
Exception details: 
%1 

User Action 
Make sure artifact resolution service is properly configured.

Fields #

NameDescription
data1 UnicodeString

Event ID 291: The artifact resolution service could not be started

#
Provider
AD FS
Channel
Unknown

Description

The artifact resolution service could not be started.

Fields #

NameDescription
data1 UnicodeString

Event ID 293: A SAML request for the required artifact was rejected because the artifact resolution service is not enabled.

#
Provider
AD FS
Channel
Admin

Description

A SAML request for the required artifact was rejected because the artifact resolution service is not enabled.

Message #

A SAML request for the required artifact was rejected because the artifact resolution service is not enabled. 
Relying party: %1 

This request failed. 

User Action 
Enable the artifact resolution service. 
Use the AD FS Management snap-in to configure or enable the SAML artifact resolution endpoint.

Fields #

NameDescription
data1 UnicodeString

Event ID 293: A SAML request for the required artifact was rejected because the artifact resolution service is not enabled

#
Provider
AD FS
Channel
Unknown

Description

A SAML request for the required artifact was rejected because the artifact resolution service is not enabled.

Fields #

NameDescription
data1 UnicodeString

Event ID 294: The SAML artifact resolution request specified an issuer that is not configured for the relying party.

#
Provider
AD FS
Channel
Admin

Description

The SAML artifact resolution request specified an issuer that is not configured for the relying party.

Message #

The SAML artifact resolution request specified an issuer that is not configured for the relying party. 
Relying party: %1 
Artifact resolution request issuer: %2 

This artifact resolution request failed. 

User Action 
Ensure that the relying party is configured properly using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 294: The SAML artifact resolution request specified an issuer that is not configured for the relying party

#
Provider
AD FS
Channel
Unknown

Description

The SAML artifact resolution request specified an issuer that is not configured for the relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 297: The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured.

#
Provider
AD FS
Channel
Admin

Description

The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured.

Message #

The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured. 
Endpoint index: %1 
Configured endpoint index: %2 

This artifact resolution request failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 297: The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured

#
Provider
AD FS
Channel
Unknown

Description

The SAML artifact resolution request required an artifact resolution service endpoint with an index that is not configured.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 298: The Windows Hello for Business key receipt certificate background task will not run.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

The Windows Hello for Business key receipt certificate background task will not run.

Message #

The Windows Hello for Business key receipt certificate background task will not run. 

Additional Information: %1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 298,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.107600+00:00",
    "event_record_id": 71,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13100
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "ServiceState.IsDrsInitialized is false."
      }
    }
  },
  "message": ""
}

Event ID 298: The Windows Hello for Business key receipt certificate background task will not run

#
Provider
AD FS
Channel
Unknown

Description

The Windows Hello for Business key receipt certificate background task will not run.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 298,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:31:52.8156192+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 302: The Federation Service could not authorize token issuance for caller 'data2' as subject 'data3' to the relying party 'data4'.

#
Provider
AD FS
Channel
Admin

Message #

The Federation Service could  not authorize token issuance for caller '%2' as subject '%3' to the relying party '%4'. See event 501 with the same Instance ID for caller identity. See event 503 with the same Instance ID for ActAs identity, if any. 

Additional Data 
Instance ID: %1 
Relying party: %4 
Exception details: 
%5 
User Action 
Use the AD FS Management snap-in to ensure that the caller is authorized to act as the subject to the relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 302: The Federation Service could not authorize token issuance for caller 'data2' as subject 'data3' to the relying party 'data4'

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 303: The Federation Service encountered an error while processing the SAML authentication request.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while processing the SAML authentication request.

Message #

The Federation Service encountered an error while processing the SAML authentication request. 

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 303: The Federation Service encountered an error while processing the SAML authentication request

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while processing the SAML authentication request.

Fields #

NameDescription
data1 UnicodeString

Event ID 305: The Federation Service encountered an error while querying a LDAP server at data1.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while querying a LDAP server at data1.

Message #

The Federation Service encountered an error while querying a LDAP server at %1. 

Additional Data 
Domain name: %1 
LDAP server hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from LDAP server (if available): %7 
Exception Details: 
 %8

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 305: The Federation Service encountered an error while querying a LDAP server at

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while querying a LDAP server at .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 306: The Federation Service encountered an error while querying a global catalog server at data1.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while querying a global catalog server at data1.

Message #

The Federation Service encountered an error while querying a global catalog server at %1. 

Additional Data 
Domain name: %1 
Global catalog server hostname (if available): %2 
Authentication type: %3 
SSL mode: %4 
Username (if available): %5 
Error code (if available): %6 
Error from server (if available): %7 
Exception Details: 
 
 %8

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 306: The Federation Service encountered an error while querying a global catalog server at

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while querying a global catalog server at .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString

Event ID 311: An attempt to update AD FS performance counters failed.

#
Provider
AD FS
Channel
Admin

Description

An attempt to update AD FS performance counters failed.

Message #

An attempt to update AD FS performance counters failed.  

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 311: An attempt to update AD FS performance counters failed

#
Provider
AD FS
Channel
Unknown

Description

An attempt to update AD FS performance counters failed.

Fields #

NameDescription
data1 UnicodeString

Event ID 315: An error occurred during an attempt to build the certificate chain for the claims provider trust 'data1' certificate identified by thumbprint 'data2'.

#
Provider
AD FS
Channel
Admin

Message #

An error occurred during an attempt to build the certificate chain for the claims provider trust '%1' certificate identified by thumbprint '%2'. Possible causes are that the certificate has been revoked, the certificate chain could not be verified as specified by the claims provider trust's signing certificate revocation settings or certificate is not within its validity period. 

You can use Windows PowerShell commands for AD FS to configure the revocation settings for the claims provider trust's signing certificate. 
Claims provider trust's signing certificate revocation settings: %3 
The following errors occurred while building the certificate chain:  
%4 

User Action: 
Ensure that the claims provider trust's signing certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 315: An error occurred during an attempt to build the certificate chain for the claims provider trust 'data1' certificate identified by thumbprint 'data2'

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 316: An error occurred during an attempt to build the certificate chain for the relying party trust 'data1' certificate identified by thumbprint 'data2'.

#
Provider
AD FS
Channel
Admin

Message #

An error occurred during an attempt to build the certificate chain for the relying party trust '%1' certificate identified by thumbprint '%2'. Possible causes are that the certificate has been revoked, the certificate chain could not be verified as specified by the relying party trust's signing certificate revocation settings or certificate is not within its validity period. 

You can use Windows PowerShell commands for AD FS to configure the revocation settings for the relying party signing certificate. 
Relying party trust's signing certificate revocation settings: %3 
The following errors occurred while building the certificate chain:  
%4 

User Action: 
Ensure that the relying party trust's signing certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 316: An error occurred during an attempt to build the certificate chain for the relying party trust 'data1' certificate identified by thumbprint 'data2'

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 317: An error occurred during an attempt to build the certificate chain for the relying party trust 'Event.EventData' certificate identified by thumbprint 'data1'.

#
Provider
AD FS
Channel
Admin
Level
Error

Message #

An error occurred during an attempt to build the certificate chain for the relying party trust '%1' certificate identified by thumbprint '%2'. Possible causes are that the certificate has been revoked, the certificate chain could not be verified as specified by the relying party trust's encryption certificate revocation settings or certificate is not within its validity period. 

You can use Windows PowerShell commands for AD FS to configure the revocation settings for the relying party encryption certificate. 
Relying party trust's encryption certificate revocation settings: %3 
The following errors occurred while building the certificate chain:  
%4 

User Action: 
Ensure that the relying party trust's encryption certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 317,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:09:23.681803+00:00",
    "event_record_id": 208,
    "correlation": {
      "ActivityID": "88CEECE0-7882-41D3-9B05-08A1D8CE3B05"
    },
    "execution": {
      "process_id": 13608,
      "thread_id": 14296
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "https://testrp3.example.com/oauth",
          "DB0FEA9B641F3814FC5168AE83EF7839AF1BB012",
          "CheckChainExcludeRoot",
          "The certificate is revoked.\r\n\r\n"
        ]
      }
    }
  },
  "message": ""
}

Event ID 317: An error occurred during an attempt to build the certificate chain for the relying party trust 'data1' certificate identified by thumbprint 'data2'

#
Provider
AD FS
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 317,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:09:23.6818033+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "https://testrp3.example.com/oauthDB0FEA9B641F3814FC5168AE83EF7839AF1BB012CheckChainExcludeRootThe certificate is revoked.\n\n"
  }
}

Event ID 319: An error occurred while the certificate chain for the client certificate identified by thumbprint 'data1' was being built.

#
Provider
AD FS
Channel
Admin

Message #

An error occurred while the certificate chain for the client certificate identified by thumbprint '%1' was being built. The certificate chain could not be built. The certificate has been revoked, the certificate chain could not be verified as specified by the encryption certificate revocation settings or certificate is not within its validity period. 

You can use the Set-ADFSProperties cmdlet with the ProxyCertRevocationCheck parameter in Windows PowerShell for AD FS to configure the client certificate revocation settings. 
Client Certificate Revocation Settings: %2 
The following errors occurred while building the certificate chain:  
%3 

User Action: 
Ensure that the client certificate is valid and has not been revoked. 
Ensure that the Federation Service can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 319: An error occurred while the certificate chain for the client certificate identified by thumbprint 'data1' was being built

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 320: The verification of the SAML message signature failed.

#
Provider
AD FS
Channel
Admin

Description

The verification of the SAML message signature failed.

Message #

The verification of the SAML message signature failed. 
Message issuer: %1 
Exception details: 
%2 

This request failed. 

User Action 
Verify that the message issuer configuration in the AD FS configuration database is up to date. 
Configure the signing certificate for the specified issuer. 
Verify that the issuer's certificate is up to date. 
Verify the issuer and server message signing requirements.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 320: The verification of the SAML message signature failed

#
Provider
AD FS
Channel
Unknown

Description

The verification of the SAML message signature failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 321: The SAML authentication request had a NameID Policy that could not be satisfied.

#
Provider
AD FS
Channel
Admin

Description

The SAML authentication request had a NameID Policy that could not be satisfied.

Message #

The SAML authentication request had a NameID Policy that could not be satisfied. 
Requestor: %1 
Name identifier format: %2 
SPNameQualifier: %3 
Exception details: 
%4 

This request failed. 

User Action 
Use the AD FS Management snap-in to configure the configuration that emits the required name identifier.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 321: The SAML authentication request had a NameID Policy that could not be satisfied

#
Provider
AD FS
Channel
Unknown

Description

The SAML authentication request had a NameID Policy that could not be satisfied.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 323: The Federation Service could not authorize token issuance for the caller 'data2' on behalf of the subject 'data3' to the relying party 'data4'.

#
Provider
AD FS
Channel
Admin

Message #

The Federation Service could  not authorize token issuance for the caller '%2' on behalf of the subject '%3' to the relying party '%4'. See event 501 with the same Instance ID for caller identity. See event 502 with the same Instance ID for OnBehalfOf identity, if any. 

Additional Data 
Instance ID: %1 
Exception details: 
%5 
User Action 
Use the Windows PowerShell Get-ADFSClaimsProviderTrust or Get-ADFSRelyingPartyTrust cmdlet to ensure the caller is authorized on behalf of the subject to the relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 323: The Federation Service could not authorize token issuance for the caller 'data2' on behalf of the subject 'data3' to the relying party 'data4'

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 325: The Federation Service could not authorize token issuance for caller 'data1'.

#
Provider
AD FS
Channel
Admin
Level
Error

Message #

The Federation Service could not authorize token issuance for caller '%2'. The caller is not authorized to request a token for the relying party '%3'. See event 501 with the same Instance ID for caller identity. 

Additional Data 
Instance ID: %1 
Relying party: %3 
Exception details: 
%4 
User Action 
Use the AD FS Management snap-in to ensure that the caller is authorized to request a token for the relying party.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 325,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:37.248466+00:00",
    "event_record_id": 96,
    "correlation": {
      "ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "a6f4ff0b-8776-43a4-9be1-6b9bf86e338f",
          "ludus\\domainadmin\r\n",
          "https://testrp1.example.com/saml",
          "Microsoft.IdentityServer.Service.IssuancePipeline.CallerAuthorizationException: MSIS5007: The caller authorization failed for caller identity ludus\\domainadmin for relying party trust https://testrp1.example.com/saml.\r\n   at Microsoft.IdentityModel.Threading.AsyncResult.End(IAsyncResult result)\r\n   at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.ProcessCoreAsyncResult.End(IAsyncResult ar)\r\n   at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.EndProcessCore(IAsyncResult ar, String requestAction, String responseAction, String trustNamespace)"
        ]
      }
    }
  },
  "message": ""
}

Event ID 325: The Federation Service could not authorize token issuance for caller 'data2'

#
Provider
AD FS
Channel
Unknown
Level
2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 325,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:09:23.9077724+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "2699b4ab-8f31-4d84-a931-f6e38783fc3bludus\\domainadmin\nhttps://testrp1.example.com/samlMicrosoft.IdentityServer.Service.IssuancePipeline.CallerAuthorizationException: MSIS5007: The caller authorization failed for caller identity ludus\\domainadmin for relying party trust https://testrp1.example.com/saml.\n   at Microsoft.IdentityModel.Threading.AsyncResult.End(IAsyncResult result)\n   at Microsoft.IdentityModel.Protocols.WSTrust.WSTrustServiceContract.ProcessCoreAsyncResult.End(IAsyncResult ar)\n   a..."
  }
}

Event ID 326: Failed to load the AD FS claims policy engine using policy type 'data1' User Action Make sure AD FS is installed correctly.

#
Provider
AD FS
Channel
Admin

Description

Failed to load the AD FS claims policy engine using policy type 'data1'.

Message #

Failed to load the AD FS claims policy engine using policy type '%1' 

User Action 
Make sure AD FS is installed correctly.

Fields #

NameDescription
data1 UnicodeString

Event ID 326: Failed to load the AD FS claims policy engine using policy type 'data1'

#
Provider
AD FS
Channel
Unknown

Description

Failed to load the AD FS claims policy engine using policy type 'data1'.

Fields #

NameDescription
data1 UnicodeString

Event ID 327: An error occurred during processing of the SAML logout request.

#
Provider
AD FS
Channel
Admin

Description

An error occurred during processing of the SAML logout request.

Message #

An error occurred during processing of the SAML logout request. 

Additional Data 
Caller identity: %1 
Logout initiator identity: %2 
Error message: %3 
Exception details: %4 
User Action 
Ensure that the single logout service is configured properly for this relying party trust or claims provider trust in the AD FS configuration database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 327: An error occurred during processing of the SAML logout request

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during processing of the SAML logout request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 328: The SAML artifact resolution request was resolved, but the response does not contain the expected assertions.

#
Provider
AD FS
Channel
Admin

Description

The SAML artifact resolution request was resolved, but the response does not contain the expected assertions.

Message #

The SAML artifact resolution request was resolved, but the response does not contain the expected assertions. 

Additional Data: 
SAML artifact: %1 
Status code: %2 
SubStatus code: %3 
Status message: %4 

This request failed. 

User Action 
Contact the claims provider for more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 328: The SAML artifact resolution request was resolved, but the response does not contain the expected assertions

#
Provider
AD FS
Channel
Unknown

Description

The SAML artifact resolution request was resolved, but the response does not contain the expected assertions.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 329: The certificate that is identified by thumbprint 'data1' could not be decrypted using the keys for X.

#
Provider
AD FS
Channel
Admin

Description

The certificate that is identified by thumbprint 'data1' could not be decrypted using the keys for X.509 certificate private key sharing.

Message #

The certificate that is identified by thumbprint '%1' could not be decrypted using the keys for X.509 certificate private key sharing. 

Additional Data: 
X.509 certificate private key sharing diagnosis: %2 

User Action 
You may have to restore all Active Directory objects underneath the specified distinguished name in the diagnostic information above for X.509 certificate private key sharing.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 329: The certificate that is identified by thumbprint 'data1' could not be decrypted using the keys for X

#
Provider
AD FS
Channel
Unknown

Description

The certificate that is identified by thumbprint 'data1' could not be decrypted using the keys for X.509 certificate private key sharing.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 331: The certificate management service encountered an error during decryption of the keys.

#
Provider
AD FS
Channel
Admin

Description

The certificate management service encountered an error during decryption of the keys.

Message #

The certificate management service encountered an error during decryption of the keys. 
storeName: %2 
storeLocation: %1 
x509FindType: %4 
findValue: %3 

Additional Data: 
X.509 certificate private key sharing diagnosis: %5  

User Action 
You may have to restore all Active Directory objects underneath the distinguished name that is specified in the diagnosis for X.509 certificate private key sharing above.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 331: The certificate management service encountered an error during decryption of the keys

#
Provider
AD FS
Channel
Unknown

Description

The certificate management service encountered an error during decryption of the keys.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 332: The certificate management service encountered an error during encryption of the keys.

#
Provider
AD FS
Channel
Admin

Description

The certificate management service encountered an error during encryption of the keys.

Message #

The certificate management service encountered an error during encryption of the keys. 
Subject: %1 
Diagnosis: %2 

User Action 
You may have to restore all Active Directory objects underneath the distinguished name that is specified in the diagnosis above for X.509 certificate private key sharing.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 332: The certificate management service encountered an error during encryption of the keys

#
Provider
AD FS
Channel
Unknown

Description

The certificate management service encountered an error during encryption of the keys.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 333: The certificate management service encountered an error during database access.

#
Provider
AD FS
Channel
Admin

Description

The certificate management service encountered an error during database access.

Message #

The certificate management service encountered an error during database access. 

Additional Data: 
Diagnosis: %1 

User Action 
Confirm that the SQL store is online.

Fields #

NameDescription
data1 UnicodeString

Event ID 333: The certificate management service encountered an error during database access

#
Provider
AD FS
Channel
Unknown

Description

The certificate management service encountered an error during database access.

Fields #

NameDescription
data1 UnicodeString

Event ID 334: Certificate rollover service needs to rollover data1 certificates urgently.

#
Provider
AD FS
Channel
Admin

Description

Certificate rollover service needs to rollover data1 certificates urgently. Partners will not be able to apply the update in time.

Message #

Certificate rollover service needs to rollover %1 certificates urgently. Partners will not be able to apply the update in time.

Fields #

NameDescription
data1 UnicodeString

Event ID 334: Certificate rollover service needs to rollover data1 certificates urgently

#
Provider
AD FS
Channel
Unknown

Description

Certificate rollover service needs to rollover certificates urgently. Partners will not be able to apply the update in time.

Fields #

NameDescription
data1 UnicodeString

Event ID 335: task_0335

#
Provider
AD FS
Channel
Admin
Level
Warning

Message #

%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 335,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:06:25.397047+00:00",
    "event_record_id": 83,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13020
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "MSIS10005: Certificate rollover service has added certificate with thumbprint '7D951E82355227B06C62677CAA93C92BCC9FD7BC' to 'Signing' certificate collection. See https://go.microsoft.com/fwlink/?linkid=861845 for more information."
      }
    }
  },
  "message": ""
}

Event ID 335

#
Provider
AD FS
Channel
Unknown
Level
3

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 335,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:06:25.3970562+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "MSIS10004: Certificate rollover service has set certificate with thumbprint '7D951E82355227B06C62677CAA93C92BCC9FD7BC' as primary 'Signing' certificate. See https://go.microsoft.com/fwlink/?linkid=861845 for more information."
  }
}

Event ID 336: The certificate management cycle was initiated.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

The certificate management cycle was initiated.

Message #

The certificate management cycle was initiated.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 336,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.117752+00:00",
    "event_record_id": 72,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13136
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 336: The certificate management cycle was initiated

#
Provider
AD FS
Channel
Unknown

Description

The certificate management cycle was initiated.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 336,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.2192666+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 337: The certificate management cycle was completed.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

The certificate management cycle was completed.

Message #

The certificate management cycle was completed.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 337,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.300723+00:00",
    "event_record_id": 81,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13136
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 337: The certificate management cycle was completed

#
Provider
AD FS
Channel
Unknown

Description

The certificate management cycle was completed.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 337,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.3938107+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 338: An error was encountered during certificate rollover.

#
Provider
AD FS
Channel
Admin

Description

An error was encountered during certificate rollover. The monitoring cycle was shut down.

Message #

An error was encountered during certificate rollover. The monitoring cycle was shut down. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 338: An error was encountered during certificate rollover

#
Provider
AD FS
Channel
Unknown

Description

An error was encountered during certificate rollover. The monitoring cycle was shut down.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 339: An error occurred during initialization of certificate rollover.

#
Provider
AD FS
Channel
Admin

Description

An error occurred during initialization of certificate rollover. Certificates will not be rolled over.

Message #

An error occurred during initialization of certificate rollover. Certificates will not be rolled over. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 339: An error occurred during initialization of certificate rollover

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during initialization of certificate rollover. Certificates will not be rolled over.

Fields #

NameDescription
data1 UnicodeString

Event ID 341: The NotBefore attribute for the token has a value that is set to a future time.

#
Provider
AD FS
Channel
Admin

Description

The NotBefore attribute for the token has a value that is set to a future time. See inner exception for more details.

Message #

The NotBefore attribute for the token has a value that is set to a future time. See inner exception for more details. 

Additional Data 

Token Type: 
%1 

Exception details: 
%2 

This request failed. 

User Action 
Verify that system clock is synchronized.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 341: The NotBefore attribute for the token has a value that is set to a future time

#
Provider
AD FS
Channel
Unknown

Description

The NotBefore attribute for the token has a value that is set to a future time. See inner exception for more details.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 342: Token validation failed.

#
Provider
AD FS
Channel
Admin
Level
Error

Description

Token validation failed.

Message #

Token validation failed.  

Additional Data 

Token Type: 
%1 
%Error message: 
%2 

Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 342,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:36.815386+00:00",
    "event_record_id": 95,
    "correlation": {
      "ActivityID": "FCDC6F25-76F3-4BC2-B0EB-7EFEBD19BD6C"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 11496
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "http://schemas.microsoft.com/ws/2006/05/identitymodel/tokens/UserName",
          "fakeuser-The user name or password is incorrect",
          "System.IdentityModel.Tokens.SecurityTokenValidationException: fakeuser ---> System.ComponentModel.Win32Exception: The user name or password is incorrect\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserInfo(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String authenticationType, String issuerName)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUser(String domain, String username, String password, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String issuerName)\r\n   at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)\r\n   --- End of inner exception stack trace ---\r\n   at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)\r\n   at Microsoft.IdentityServer.Service.Tokens.MsisLocalCpUserNameSecurityTokenHandler.ValidateTokenInternal(UsernameAuthenticationContext usernameAuthenticationContext, SecurityToken token)\r\n   at Microsoft.IdentityServer.Service.Tokens.MsisLocalCpUserNameSecurityTokenHandler.ValidateToken(SecurityToken token)\r\n\r\nSystem.ComponentModel.Win32Exception (0x80004005): The user name or password is incorrect\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserInfo(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String authenticationType, String issuerName)\r\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUser(String domain, String username, String password, DateTime& nextPasswordChange, DateTime& lastPasswordChange, String issuerName)\r\n   at Microsoft.IdentityServer.Service.LocalAccountStores.ActiveDirectory.ActiveDirectoryCpTrustStore.ValidateUser(IAuthenticationContext context)"
        ]
      }
    }
  },
  "message": ""
}

Event ID 342: Token validation failed

#
Provider
AD FS
Channel
Unknown
Level
2

Description

Token validation failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 342,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:07:36.8153864+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "http://schemas.microsoft.com/ws/2006/05/identitymodel/tokens/UserNamefakeuser-The user name or password is incorrectSystem.IdentityModel.Tokens.SecurityTokenValidationException: fakeuser ---> System.ComponentModel.Win32Exception: The user name or password is incorrect\n   at Microsoft.IdentityServer.Tokens.LsaLogonUserHelper.GetLsaLogonUserHandle(SafeHGlobalHandle pLogonInfo, Int32 logonInfoSize, SafeCloseHandle& tokenHandle, SafeLsaReturnBufferHandle& profileHandle)\n   at Microsoft.IdentityServe..."
  }
}

Event ID 343: There was an error during initialization of synchronization.

#
Provider
AD FS
Channel
Admin

Description

There was an error during initialization of synchronization. Synchronization of data from the primary federation server to the secondary federation server will not occur.

Message #

There was an error during initialization of synchronization. Synchronization of data from the primary federation server to the secondary federation server will not occur. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 343: There was an error during initialization of synchronization

#
Provider
AD FS
Channel
Unknown

Description

There was an error during initialization of synchronization. Synchronization of data from the primary federation server to the secondary federation server will not occur.

Fields #

NameDescription
data1 UnicodeString

Event ID 344: There was an error doing synchronization.

#
Provider
AD FS
Channel
Admin

Description

There was an error doing synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.

Message #

There was an error doing synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur. 

Additional data 

Exception details: 
%1 

User Action 
 Make sure the primary federation server is available or the service account identity of this machine matches the service account identity of the primary federation server.

Fields #

NameDescription
data1 UnicodeString

Event ID 344: There was an error doing synchronization

#
Provider
AD FS
Channel
Unknown

Description

There was an error doing synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.

Fields #

NameDescription
data1 UnicodeString

Event ID 345: There was a communication error during AD FS configuration database synchronization.

#
Provider
AD FS
Channel
Admin

Description

There was a communication error during AD FS configuration database synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.

Message #

There was a communication error during AD FS configuration database synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur. 

Additional Data 

Master Name : %1 
Endpoint Uri : %2 
Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 345: There was a communication error during AD FS configuration database synchronization

#
Provider
AD FS
Channel
Unknown

Description

There was a communication error during AD FS configuration database synchronization. Synchronization of data from the primary federation server to a secondary federation server did not occur.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 346: There was an error during retrieving the configuration data for the secondary federation server.

#
Provider
AD FS
Channel
Admin

Description

There was an error during retrieving the configuration data for the secondary federation server.

Message #

There was an error during retrieving the configuration data for the secondary federation server. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 346: There was an error during retrieving the configuration data for the secondary federation server

#
Provider
AD FS
Channel
Unknown

Description

There was an error during retrieving the configuration data for the secondary federation server.

Fields #

NameDescription
data1 UnicodeString

Event ID 348: Synchronization of configuration data from the primary federation server 'data1' is completed.

#
Provider
AD FS
Channel
Admin

Description

Synchronization of configuration data from the primary federation server 'data1' is completed. data2 objects were added. data3 objects were deleted.

Message #

Synchronization of configuration data from the primary federation server '%1' is completed. %2 objects were added. %3 objects were deleted.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 348: Synchronization of configuration data from the primary federation server 'data1' is completed

#
Provider
AD FS
Channel
Unknown

Description

Synchronization of configuration data from the primary federation server 'data1' is completed. data2 objects were added. data3 objects were deleted.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 349: The administration service for the Federation Service started successfully.

#
Provider
AD FS
Channel
Admin
Level
Informational

Message #

The administration service for the Federation Service started successfully. You can now use the Windows Powershell commands for AD FS to modify the Federation Service configuration. The following service hosts have been added: 
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 349,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:51.927998+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Policy Administration ServiceHost\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nnet.tcp://localhost:1500/policy\r\nhttp://adfs.ludus.domain:80/adfs/services/policystoretransfer\r\nnet.tcp://localhost:1501/adfs/services/policystoretransfer\r\n\r\n"
      }
    }
  },
  "message": ""
}

Event ID 349: The administration service for the Federation Service started successfully

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 349,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:10.3652052+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 351: There was an error getting synchronization properties.

#
Provider
AD FS
Channel
Admin

Description

There was an error getting synchronization properties.

Message #

There was an error getting synchronization properties. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 351: There was an error getting synchronization properties

#
Provider
AD FS
Channel
Unknown

Description

There was an error getting synchronization properties.

Fields #

NameDescription
data1 UnicodeString

Event ID 352: A SQL operation in the AD FS configuration database with connection string Event.EventData failed.

#
Provider
AD FS
Channel
Admin
Level
Error

Description

A SQL operation in the AD FS configuration database with connection string Event.EventData failed.

Message #

A SQL operation in the AD FS configuration database with connection string %1 failed.  

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 352,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:10:50.887915+00:00",
    "event_record_id": 228,
    "correlation": {},
    "execution": {
      "process_id": 12444,
      "thread_id": 8536
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1309"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "Data Source=np:\\\\.\\pipe\\microsoft##wid\\tsql\\query;Initial Catalog=AdfsConfigurationV4;Integrated Security=True",
          "Login failed for user 'ludus\\svc_adfs'."
        ]
      }
    }
  },
  "message": ""
}

Event ID 352: A SQL operation in the AD FS configuration database with connection string data1 failed

#
Provider
AD FS
Channel
Unknown
Level
2

Description

A SQL operation in the AD FS configuration database with connection string failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 352,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:12:50.2294719+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "Data Source=np:\\\\.\\pipe\\microsoft##wid\\tsql\\query;Initial Catalog=AdfsConfigurationV4;Integrated Security=TrueLogin failed for user 'ludus\\svc_adfs'."
  }
}

Event ID 353: Unable to resolve the SAML artifact.

#
Provider
AD FS
Channel
Admin

Description

Unable to resolve the SAML artifact. Verification of the artifact response signature failed.

Message #

Unable to resolve the SAML artifact. Verification of the artifact response signature failed. 
Claims provider: %1 
Exception details: 
%2 

This request failed. 

User Action 
Verify that the claims provider trust in the AD FS configuration database is up to date. 
Verify that the claims provider trust's signing certificate is up to date.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 353: Unable to resolve the SAML artifact

#
Provider
AD FS
Channel
Unknown

Description

Unable to resolve the SAML artifact. Verification of the artifact response signature failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 354: The artifact resolution service could not verify the request signature.

#
Provider
AD FS
Channel
Admin

Description

The artifact resolution service could not verify the request signature.

Message #

The artifact resolution service could not verify the request signature. 

Additional Data 
Exception details: 
%1 

User action: 
Verify that the relying party trust in the AD FS configuration database is up to date. 
Configure the relying party certificate for request signing. 
Verify that relying party certificate is up to date.

Fields #

NameDescription
data1 UnicodeString

Event ID 354: The artifact resolution service could not verify the request signature

#
Provider
AD FS
Channel
Unknown

Description

The artifact resolution service could not verify the request signature.

Fields #

NameDescription
data1 UnicodeString

Event ID 356: Failed to register notification to the SQL database with the connection string data1 for cache type 'data2'.

#
Provider
AD FS
Channel
Admin

Description

Failed to register notification to the SQL database with the connection string data1 for cache type 'data2'. Changes to settings may not take effect until the Federation Service restarts.

Message #

Failed to register notification to the SQL database with the connection string %1 for cache type '%2'. Changes to settings may not take effect until the Federation Service restarts. 

Additional Data 

Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 356: Failed to register notification to the SQL database with the connection string data1 for cache type 'data2'

#
Provider
AD FS
Channel
Unknown

Description

Failed to register notification to the SQL database with the connection string data1 for cache type 'data2'. Changes to settings may not take effect until the Federation Service restarts.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 357: Successfully registered notification to the SQL database with the connection string data1.

#
Provider
AD FS
Channel
Admin

Description

Successfully registered notification to the SQL database with the connection string data1.

Message #

Successfully registered notification to the SQL database with the connection string %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 357: Successfully registered notification to the SQL database with the connection string

#
Provider
AD FS
Channel
Unknown

Description

Successfully registered notification to the SQL database with the connection string .

Fields #

NameDescription
data1 UnicodeString

Event ID 358: Restarting Event.EventData.

#
Provider
AD FS
Channel
Admin
Level
Warning

Message #

Restarting %1. This restart is necessary because a change was detected in the certificates that this service host uses. Requests that are served by endpoints of this service host may fail during restart.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 358,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:06:25.236927+00:00",
    "event_record_id": 82,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 13020
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Issuance ServiceHost"
      }
    }
  },
  "message": ""
}

Event ID 358: Restarting

#
Provider
AD FS
Channel
Unknown
Level
3

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 358,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:06:25.5672417+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "Issuance ServiceHost"
  }
}

Event ID 359: An error occurred during an attempt to restart data1.

#
Provider
AD FS
Channel
Admin

Description

An error occurred during an attempt to restart data1.

Message #

An error occurred during an attempt to restart %1. 

Additional Data 

Exception details: 
%2 

User Action 
 Restart the Federation Service to recover from the error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 359: An error occurred during an attempt to restart

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during an attempt to restart .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 360: A request was made to a certificate transport endpoint, but the request did not include a client certificate.

#
Provider
AD FS
Channel
Admin

Message #

A request was made to a certificate transport endpoint, but the request did not include a client certificate. This could be because the root CA certificate that issued the client certificate is not in the Trust CA certificate store or because the client certificate is expired. 

User Action: 
Ensure that the CA that issued the client certificate in this request has its certificate in the Trusted Root Certificate Authority store on the Local Computer. 
Ensure that the client certificate is not expired.

Event ID 360: A request was made to a certificate transport endpoint, but the request did not include a client certificate

#
Provider
AD FS
Channel
Unknown

Event ID 362: Encountered error during federation passive sign-out.

#
Provider
AD FS
Channel
Admin

Description

Encountered error during federation passive sign-out.

Message #

Encountered error during federation passive sign-out. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 362: Encountered error during federation passive sign-out

#
Provider
AD FS
Channel
Unknown

Description

Encountered error during federation passive sign-out.

Fields #

NameDescription
data1 UnicodeString

Event ID 363: A communication error occurred during an attempt to get a token from the Federation Service.

#
Provider
AD FS
Channel
Admin

Description

A communication error occurred during an attempt to get a token from the Federation Service. Make sure that the Federation Service is running.

Message #

A communication error occurred during an attempt to get a token from the Federation Service. Make sure that the Federation Service is running. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 363: A communication error occurred during an attempt to get a token from the Federation Service

#
Provider
AD FS
Channel
Unknown

Description

A communication error occurred during an attempt to get a token from the Federation Service. Make sure that the Federation Service is running.

Fields #

NameDescription
data1 UnicodeString

Event ID 364: Encountered error during federation passive request.

#
Provider
AD FS
Channel
Admin
Level
Error

Description

Encountered error during federation passive request.

Message #

Encountered error during federation passive request. 

Additional Data 

Protocol Name: 
%1 

Relying Party: 
%2 

Exception details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 364,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:52.936421+00:00",
    "event_record_id": 109,
    "correlation": {
      "ActivityID": "E915B92E-2E46-4CB5-0900-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "OAuthAuthorizationProtocol",
          "",
          "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\r\n   at Microsoft.IdentityServer.Web.Protocols.ProtocolContext.Validate()\r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationProtocolHandler.GetRequiredPipelineBehaviors(ProtocolContext pContext)\r\n   at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context)\r\n\r\n"
        ]
      }
    }
  },
  "message": ""
}

Event ID 364: Encountered error during federation passive request

#
Provider
AD FS
Channel
Unknown
Level
2

Description

Encountered error during federation passive request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 364,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:08:53.1123197+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "OAuthAuthorizationProtocolMicrosoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\n   at Microsoft.IdentityServer.Web.Protocols.P..."
  }
}

Event ID 365: A token request was received for the relying party 'data1', but the request could not be fulfilled because the relying party trust is not enabled.

#
Provider
AD FS
Channel
Admin

Description

A token request was received for the relying party 'data1', but the request could not be fulfilled because the relying party trust is not enabled.

Message #

A token request was received for the relying party '%1', but the request could not be fulfilled because the relying party trust is not enabled. 
Relying party: %1 

This request failed. 

User Action 
If this relying party trust should be enabled, enable it by using the AD FS Management snap-in or Windows PowerShell for AD FS.

Fields #

NameDescription
data1 UnicodeString

Event ID 365: A token request was received for the relying party 'data1', but the request could not be fulfilled because the relying party trust is not enabled

#
Provider
AD FS
Channel
Unknown

Description

A token request was received for the relying party 'data1', but the request could not be fulfilled because the relying party trust is not enabled.

Fields #

NameDescription
data1 UnicodeString

Event ID 366: A token was received from claims provider 'data1', but the token could not be validated because the claims provider trust is not enabled.

#
Provider
AD FS
Channel
Admin

Description

A token was received from claims provider 'data1', but the token could not be validated because the claims provider trust is not enabled.

Message #

A token was received from claims provider '%1', but the token could not be validated because the claims provider trust is not enabled. 
Claims provider: %1 

This request failed. 

User Action 
If this claims provider trust should be enabled, enable it by using the AD FS Management snap-in or Windows PowerShell for AD FS.

Fields #

NameDescription
data1 UnicodeString

Event ID 366: A token was received from claims provider 'data1', but the token could not be validated because the claims provider trust is not enabled

#
Provider
AD FS
Channel
Unknown

Description

A token was received from claims provider 'data1', but the token could not be validated because the claims provider trust is not enabled.

Fields #

NameDescription
data1 UnicodeString

Event ID 367: The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federati...

#
Provider
AD FS
Channel
Admin

Description

The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federation Service.

Message #

The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federation Service. 

User Action 
See the exception details for the audience identifier that failed validation. If the audience identifier identifies this Federation Service, add the audience identifier to the acceptable identifiers list by using Windows PowerShell for AD FS.  Note that the audience identifier is used to verify whether the token was sent to this Federation Service. If you think that the audience identifier does not identify your Federation Service, adding it to the acceptable identifiers list may open a security vulnerability in your system. 

Additional Data 

Token Type: 
%1 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 367: The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federation Service

#
Provider
AD FS
Channel
Unknown

Description

The audience restriction was not valid because the specified audience identifier is not present in the acceptable identifiers list of this Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 368: The SAML Single Logout request does not correspond to the logged-in session participant.

#
Provider
AD FS
Channel
Admin

Description

The SAML Single Logout request does not correspond to the logged-in session participant.

Message #

The SAML Single Logout request does not correspond to the logged-in session participant. 
Requestor: %1 
Request name identifier: %2 
Logged-in session participants: 
%3  

This request failed. 

User Action 
Verify that the claim provider trust or the relying party trust configuration is up to date. If the name identifier in the request is different from the name identifier in the session only by NameQualifier or SPNameQualifier, check and correct the name identifier policy issuance rule using the AD FS Management snap-in.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 368: The SAML Single Logout request does not correspond to the logged-in session participant

#
Provider
AD FS
Channel
Unknown

Description

The SAML Single Logout request does not correspond to the logged-in session participant.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 369: Processing TTP request failed with the following exception.

#
Provider
AD FS
Channel
Admin

Description

Processing TTP request failed with the following exception.

Message #

Processing TTP request failed with the following exception. 

Additional Data 

Exception details: 
%1 

User Action 
Ensure that user has enabled cookies in browser settings.

Fields #

NameDescription
data1 UnicodeString

Event ID 369: Processing TTP request failed with the following exception

#
Provider
AD FS
Channel
Unknown

Description

Processing TTP request failed with the following exception.

Fields #

NameDescription
data1 UnicodeString

Event ID 370: Incoming TTP response is not valid.

#
Provider
AD FS
Channel
Admin

Description

Incoming TTP response is not valid. Processing response failed with following exception.

Message #

Incoming TTP response is not valid. Processing response failed with following exception. 

Additional Data 

Exception details: 
%1 

User Action 
Ensure that partner federation provider is configured properly to send valid TTP response.

Fields #

NameDescription
data1 UnicodeString

Event ID 370: Incoming TTP response is not valid

#
Provider
AD FS
Channel
Unknown

Description

Incoming TTP response is not valid. Processing response failed with following exception.

Fields #

NameDescription
data1 UnicodeString

Event ID 371: Cannot find certificate to validate message/token signature obtained from claims provider.

#
Provider
AD FS
Channel
Admin

Description

Cannot find certificate to validate message/token signature obtained from claims provider.

Message #

Cannot find certificate to validate message/token signature obtained from claims provider. 
Claims provider: %1 

This request failed. 

User Action 
Check that Claim Provider Trust configuration is up to date.

Fields #

NameDescription
data1 UnicodeString

Event ID 371: Cannot find certificate to validate message/token signature obtained from claims provider

#
Provider
AD FS
Channel
Unknown

Description

Cannot find certificate to validate message/token signature obtained from claims provider.

Fields #

NameDescription
data1 UnicodeString

Event ID 372: Authentication Failed.

#
Provider
AD FS
Channel
Admin

Description

Authentication Failed. The token used to authenticate the user is signed using a weaker signature algorithm than expected.

Message #

Authentication Failed. The token used to authenticate the user is signed using a weaker signature algorithm than expected. 

Additional Data 
 Token Type: %1 
 Issuer: %2 
 Actual token signature algorithm: %3 
 Expected token signature algorithm: %4  

User Action 
Check that Claim Provider is configured to accept tokens with expected signature algorithm.  
Use the AD FS PowerShell commands to configure the signature algorithm property.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 372: Authentication Failed

#
Provider
AD FS
Channel
Unknown

Description

Authentication Failed. The token used to authenticate the user is signed using a weaker signature algorithm than expected.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 373: The artifact request from the replying party is signed with a weaker signature algorithm.

#
Provider
AD FS
Channel
Admin

Description

The artifact request from the replying party is signed with a weaker signature algorithm.

Message #

The artifact request from the replying party is signed with a weaker signature algorithm. 

Additional Data 
Relying party identity: %1 
Actual message signature algorithm: %2 
Expected message signature algorithm: %3 

User action: 
Check that relying party is configured to accept artifact resolution request with expected signature algorithm. 
Use the AD FS PowerShell commands to configure the signature algorithm property.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 373: The artifact request from the replying party is signed with a weaker signature algorithm

#
Provider
AD FS
Channel
Unknown

Description

The artifact request from the replying party is signed with a weaker signature algorithm.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 374: An error occurred while building the certificate chain for the claims provider trust 'data1' certificate identified by thumbprint 'data2'.

#
Provider
AD FS
Channel
Admin

Message #

An error occurred while building the certificate chain for the claims provider trust '%1' certificate identified by thumbprint '%2'.  The certificate chain could not be built, the certificate has been revoked, or the certificate chain could not be verified as specified by the claims provider trust's encryption certificate revocation settings. 

AD FS powershell commands can be used to configure the claims provider trust encryption certificate revocation settings. 
Claims Provider Trust Encryption Certificate Revocation Settings: %3 
The following errors occurred while building the certificate chain:  
%4 
User Action: 
Ensure that the claims provider trust's encryption certificate is valid and has not been revoked. 
Ensure that AD FS can access the certificate revocation list if the revocation setting does not specify "none" or a "cache only" setting. 
Verify your proxy server setting. For more information about how to verify your proxy server setting, see the AD FS Troubleshooting Guide (http://go.microsoft.com/fwlink/?LinkId=182180).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 374: An error occurred while building the certificate chain for the claims provider trust 'data1' certificate identified by thumbprint 'data2'

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 375: Policy store synchronization initiated.

#
Provider
AD FS
Channel
Admin

Description

Policy store synchronization initiated.

Message #

Policy store synchronization initiated.

Event ID 375: Policy store synchronization initiated

#
Provider
AD FS
Channel
Unknown

Description

Policy store synchronization initiated.

Event ID 376: An Error occurred while executing a query in SQL attribute store.

#
Provider
AD FS
Channel
Admin

Description

An Error occurred while executing a query in SQL attribute store.

Message #

An Error occurred while executing a query in SQL attribute store. 

Additional Data 
 Connection information: %1 
 Query: %2 
 Parameters: %3 

User Action 
Examine the exception details to take one or more of the following actions if applicable. 
  Verify that the connection string to the SQL attribute store is valid. 
  Make sure that the SQL attribute store can be reached by the connection string and the SQL attribute store exists. 
  Verify that the SQL query and parameters are valid. 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 376: An Error occurred while executing a query in SQL attribute store

#
Provider
AD FS
Channel
Unknown

Description

An Error occurred while executing a query in SQL attribute store.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 377: A processing error occurred in an attribute store.

#
Provider
AD FS
Channel
Admin

Description

A processing error occurred in an attribute store.

Message #

A processing error occurred in an attribute store. 

User Action 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 377: A processing error occurred in an attribute store

#
Provider
AD FS
Channel
Unknown

Description

A processing error occurred in an attribute store.

Fields #

NameDescription
data1 UnicodeString

Event ID 378: SAML request is not signed with expected signature algorithm.

#
Provider
AD FS
Channel
Admin

Description

SAML request is not signed with expected signature algorithm. SAML request is signed with signature algorithm data1 . Expected signature algorithm is data2.

Message #

SAML request is not signed with expected signature algorithm. SAML request is signed with signature algorithm %1 . Expected signature algorithm is %2 

User Action: 
Verify that signature algorithm for the partner is configured as expected.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 378: SAML request is not signed with expected signature algorithm

#
Provider
AD FS
Channel
Unknown

Description

SAML request is not signed with expected signature algorithm. SAML request is signed with signature algorithm . Expected signature algorithm is.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 379: A security token was rejected as the specified IssueInstant was before the allowed time frame.

#
Provider
AD FS
Channel
Admin

Description

A security token was rejected as the specified IssueInstant was before the allowed time frame.

Message #

A security token was rejected as the specified IssueInstant was before the allowed time frame. 

Token Type: 
%1 

User Action: 
 To allow tokens for a larger timeframe, use the AD FS PowerShell commands to adjust the value of the ReplayCacheExpirationInterval.

Fields #

NameDescription
data1 UnicodeString

Event ID 379: A security token was rejected as the specified IssueInstant was before the allowed time frame

#
Provider
AD FS
Channel
Unknown

Description

A security token was rejected as the specified IssueInstant was before the allowed time frame.

Fields #

NameDescription
data1 UnicodeString

Event ID 380: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data.

#
Provider
AD FS
Channel
Admin

Message #

During processing of the Federation Service configuration, the element '%1' was found to have invalid data. The certificate that was configured could not be used. The certificate has been revoked, the certificate chain could not be verified or certificate is not within its validity period. The following are the values of the certificate: 
Element: %1 
Subject: %2 
Thumbprint: %3 

The Federation Service will not be able to start until this configuration element is corrected. 

User Action 
Verify whether the certificate chain for the certificate configured has been revoked by its certificate authority. 
If the certificate has been revoked or expired, the AD FS service must be issued a new certificate.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 380: During processing of the Federation Service configuration, the element 'data1' was found to have invalid data

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 381: An error occurred during an attempt to build the certificate chain for configuration certificate identified by thumbprint 'data1'.

#
Provider
AD FS
Channel
Admin

Message #

An error occurred during an attempt to build the certificate chain for configuration certificate identified by thumbprint '%1'. Possible causes are that the certificate has been revoked or certificate is not within its validity period. 
The following errors occurred while building the certificate chain:  
%2 

User Action: 
Ensure that the certificate is valid and has not been revoked or expired.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 381: An error occurred during an attempt to build the certificate chain for configuration certificate identified by thumbprint 'data1'

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 382: AD FS detected that the Federation Service has more than data1 data2 trusts configured and that the data in the AD FS configuration database for this Fed...

#
Provider
AD FS
Channel
Admin

Message #

AD FS detected that the Federation Service has more than %1 %2 trusts configured and that the data in the AD FS configuration database for this Federation Service is stored and synchronized using Windows Internal Database technology. The overall performance of data synchronization between configuration databases that are stored locally on federation servers across the farm will degrade as you add more than %1 trusts when you use the Windows Internal Database to store the AD FS configuration database. 

User Action: 
To improve synchronization performance across your federation server farm, we recommend that you migrate the data in the AD FS configuration database to SQL server. For more information about how to do this, see AD FS Operations Guide (http://go.microsoft.com/fwlink/?LinkId=181189).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 382: AD FS detected that the Federation Service has more than data1 data2 trusts configured and that the data in the AD FS configuration database for this Federation Service is stored and synchronized u...

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 383: The Web request failed because the web.

#
Provider
AD FS
Channel
Admin

Description

The Web request failed because the web.config file is malformed.

Message #

The Web request failed because the web.config file is malformed. 

User Action: 
Fix the malformed data in the web.config file. 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 383: The Web request failed because the web

#
Provider
AD FS
Channel
Unknown

Description

The Web request failed because the web.config file is malformed.

Fields #

NameDescription
data1 UnicodeString

Event ID 384: The request to the Federation Service failed because the web.

#
Provider
AD FS
Channel
Admin

Description

The request to the Federation Service failed because the web.config file has an invalid configuration for 'data1' that the Federation Service does not support.

Message #

The request to the Federation Service failed because the web.config file has an invalid  configuration for '%1' that the Federation Service does not support. 

User Action: Ensure that the configuration of the property '%1' is supported by the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 384: The request to the Federation Service failed because the web

#
Provider
AD FS
Channel
Unknown

Description

The request to the Federation Service failed because the web.config file has an invalid configuration for 'data1' that the Federation Service does not support.

Fields #

NameDescription
data1 UnicodeString

Event ID 385: AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire s...

#
Provider
AD FS
Channel
Admin

Description

AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon. See additional details for more information.

Message #

AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon. See additional details for more information 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 385: AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon

#
Provider
AD FS
Channel
Unknown

Description

AD FS detected that one or more certificates in AD FS configuration database need to be updated manually because they are expired, or will expire soon. See additional details for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 386: AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire.

Message #

AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 386,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.125743+00:00",
    "event_record_id": 76,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 9156
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 386: AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire

#
Provider
AD FS
Channel
Unknown

Description

AD FS detected that none of the service certificates that are configured to be managed by the administrator are due to expire.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 386,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T20:13:14.5591807+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 387: AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD F...

#
Provider
AD FS
Channel
Admin

Description

AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service.

Message #

AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service. 

User Action: Ensure that the AD FS service account has read permissions on the certificate private keys. 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 387: AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service

#
Provider
AD FS
Channel
Unknown

Description

AD FS detected that one or more of the certificates specified in the Federation Service were not accessible to the service account used by the AD FS Windows Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 388: AD FS detected that all the service certificates have appropriate access given to the AD FS service account.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

AD FS detected that all the service certificates have appropriate access given to the AD FS service account.

Message #

AD FS detected that all the service certificates have appropriate access given to the AD FS service account.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 388,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.126174+00:00",
    "event_record_id": 77,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 11756
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 388: AD FS detected that all the service certificates have appropriate access given to the AD FS service account

#
Provider
AD FS
Channel
Unknown

Description

AD FS detected that all the service certificates have appropriate access given to the AD FS service account.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 388,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:44:12.3999854+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 389: AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon.

#
Provider
AD FS
Channel
Admin

Description

AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon. See additional details for more information.

Message #

AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon. See additional details for more information 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 389: AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon

#
Provider
AD FS
Channel
Unknown

Description

AD FS detected that one or more of your trusts require their certificates to be updated manually because they are expired, or will expire soon. See additional details for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 390: AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire.

Message #

AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 390,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.154591+00:00",
    "event_record_id": 79,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 9156
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 390: AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire

#
Provider
AD FS
Channel
Unknown

Description

AD FS detected that none of the partner certificates that are configured to be managed by the administrator are due to expire.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 390,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T20:13:14.5760402+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 392: The federation server proxy was able to successfully renew its trust with the Federation Service.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy was able to successfully renew its trust with the Federation Service.

Message #

The federation server proxy was able to successfully renew its trust with the Federation Service.  

Proxy trust certificate subject: %1. 
Proxy trust certificate old thumbprint: %2. 
Proxy trust certificate new thumbprint: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 392: The federation server proxy was able to successfully renew its trust with the Federation Service

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy was able to successfully renew its trust with the Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 393: The federation server proxy could not establish a trust with the Federation Service.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy could not establish a trust with the Federation Service.

Message #

The federation server proxy could not establish a trust with the Federation Service. 

Additional Data 
Exception details: 
%1 

User Action 
Ensure that the credentials being used to establish a trust between the federation server proxy and the Federation Service are valid and that the Federation Service can be reached.

Fields #

NameDescription
data1 UnicodeString

Event ID 393: The federation server proxy could not establish a trust with the Federation Service

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy could not establish a trust with the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 394: The federation server proxy could not renew its trust with the Federation Service.

#
Provider
AD FS
Channel
Admin

Description

The federation server proxy could not renew its trust with the Federation Service.

Message #

The federation server proxy could not renew its trust with the Federation Service.  

Additional Data 
Exception details: 
%1 

User Action 
Ensure that the federation server proxy is trusted by the Federation Service. If the trust does not exist or has been revoked, establish a trust between the proxy and the Federation Service using the Federation Service Proxy Configuration Wizard by logging on to the proxy computer.

Fields #

NameDescription
data1 UnicodeString

Event ID 394: The federation server proxy could not renew its trust with the Federation Service

#
Provider
AD FS
Channel
Unknown

Description

The federation server proxy could not renew its trust with the Federation Service.

Fields #

NameDescription
data1 UnicodeString

Event ID 395: The trust between the federation server proxy and the Federation Service was established successfully using the account 'data1'.

#
Provider
AD FS
Channel
Admin

Description

The trust between the federation server proxy and the Federation Service was established successfully using the account 'data1'.

Message #

The trust between the federation server proxy and the Federation Service was established successfully using the account '%1'. 

Proxy trust certificate subject: %2. 
Proxy trust certificate thumbprint: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 395: The trust between the federation server proxy and the Federation Service was established successfully using the account 'data1'

#
Provider
AD FS
Channel
Unknown

Description

The trust between the federation server proxy and the Federation Service was established successfully using the account 'data1'.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 396: The trust between the federation server proxy and the Federation Service was renewed successfully.

#
Provider
AD FS
Channel
Admin

Description

The trust between the federation server proxy and the Federation Service was renewed successfully.

Message #

The trust between the federation server proxy and the Federation Service was renewed successfully. 

Proxy trust certificate subject: %1. 
Proxy trust certificate old thumbprint: %2. 
Proxy trust certificate new thumbprint: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 396: The trust between the federation server proxy and the Federation Service was renewed successfully

#
Provider
AD FS
Channel
Unknown

Description

The trust between the federation server proxy and the Federation Service was renewed successfully.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 397: The federation server loaded the HTTP proxy configuration from WinHTTP settings.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

The federation server loaded the HTTP proxy configuration from WinHTTP settings.

Message #

The federation server loaded the HTTP proxy configuration from WinHTTP settings. 

HTTP Proxy: %1 
HTTPS Proxy: %2 
Bypass proxy for local addresses: %3 
Bypass proxy for addresses: %4 

To learn more about how to set the HTTP proxy settings for the federation server, see http://go.microsoft.com/fwlink/?LinkId=182180.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 397,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:50.877782+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 12484
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "",
          "",
          "",
          "\r\n"
        ]
      }
    }
  },
  "message": ""
}

Event ID 397: The federation server loaded the HTTP proxy configuration from WinHTTP settings

#
Provider
AD FS
Channel
Unknown

Description

The federation server loaded the HTTP proxy configuration from WinHTTP settings.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 397,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:43:09.5969961+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 398: AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived.

#
Provider
AD FS
Channel
Admin

Description

AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived.

Message #

AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived. 

Additional Details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 398: AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived

#
Provider
AD FS
Channel
Unknown

Description

AD FS detected that one or more certificates in the AD FS configuration database need to be updated manually because they are archived.

Fields #

NameDescription
data1 UnicodeString

Event ID 399: AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived.

Message #

AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 399,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.121989+00:00",
    "event_record_id": 74,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 9156
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 399: AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived

#
Provider
AD FS
Channel
Unknown

Description

AD FS detected that none of the service certificates that are configured to be managed by the administrator are archived.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 399,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T20:13:14.5561015+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 400: VSS writer permissions have been granted to user data1.

#
Provider
AD FS
Channel
Admin

Description

VSS writer permissions have been granted to user data1.

Message #

VSS writer permissions have been granted to user %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 400: VSS writer permissions have been granted to user

#
Provider
AD FS
Channel
Unknown

Description

VSS writer permissions have been granted to user .

Fields #

NameDescription
data1 UnicodeString

Event ID 401: VSS writer permissions have been revoked from user data1.

#
Provider
AD FS
Channel
Admin

Description

VSS writer permissions have been revoked from user data1.

Message #

VSS writer permissions have been revoked from user %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 401: VSS writer permissions have been revoked from user

#
Provider
AD FS
Channel
Unknown

Description

VSS writer permissions have been revoked from user .

Fields #

NameDescription
data1 UnicodeString

Event ID 402: Failed to add some of the certificate claims.

#
Provider
AD FS
Channel
Admin

Description

Failed to add some of the certificate claims.

Message #

Failed to add some of the certificate claims.

Event ID 402: Failed to add some of the certificate claims

#
Provider
AD FS
Channel
Unknown

Description

Failed to add some of the certificate claims.

Event ID 407: Password change failed for following user.

#
Provider
AD FS
Channel
Admin

Description

Password change failed for following user.

Message #

Password change failed for following user: 

Additional Data 

User: 
%1 

Server on which password change was attempted: 
%2 
Error details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 407: Password change failed for following user:

#
Provider
AD FS
Channel
Unknown

Description

Password change failed for following user.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 414: An error occurred during processing of a token request.

#
Provider
AD FS
Channel
Admin

Description

An error occurred during processing of a token request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.

Message #

An error occurred during processing of a token request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.  

Additional Data 

Activity ID:
 %1 

Target Relying Party:
 %2 

Is Application Proxy Configured:
 %3 

Is Request From the Extranet:
 %4 

User action: 
Use the Activity ID data in this message to search and correlate the data to events in the Event log using Event Viewer. This Activity ID will also be shown as additional information in the error page when an error occurs in the federation passive Web application.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 414: An error occurred during processing of a token request

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during processing of a token request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 415: task_0415

#
Provider
AD FS
Channel
Admin

Message #

%1

Fields #

NameDescription
data1 UnicodeString

Event ID 415

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 416: Web configuration error: data1.

#
Provider
AD FS
Channel
Admin

Description

Web configuration error: data1.

Message #

Web configuration error: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 416: Web configuration error:

#
Provider
AD FS
Channel
Unknown

Description

Web configuration error.

Fields #

NameDescription
data1 UnicodeString

Event ID 417: Unable to add the certificate claim data1.

#
Provider
AD FS
Channel
Admin

Description

Unable to add the certificate claim data1.

Message #

Unable to add the certificate claim %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 417: Unable to add the certificate claim

#
Provider
AD FS
Channel
Unknown

Description

Unable to add the certificate claim .

Fields #

NameDescription
data1 UnicodeString

Event ID 418: The trust between the federation server proxy and the Federation Service was successfully renewed.

#
Provider
AD FS
Channel
Admin

Description

The trust between the federation server proxy and the Federation Service was successfully renewed.

Message #

The trust between the federation server proxy and the Federation Service was successfully renewed. 

Additional Data 

Server from which request was made: 
%1 
Certificate Subject: 
%2 
Old Certificate Thumbprint: 
%3 
New Certificate Thumbprint: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 418: The trust between the federation server proxy and the Federation Service was successfully renewed

#
Provider
AD FS
Channel
Unknown

Description

The trust between the federation server proxy and the Federation Service was successfully renewed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 419: Unable to renew the trust between the federation server proxy and the Federation Service.

#
Provider
AD FS
Channel
Admin

Description

Unable to renew the trust between the federation server proxy and the Federation Service.

Message #

Unable to renew the trust between the federation server proxy and the Federation Service. 

Additional Data 

Server from which request was made: 
%1 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 419: Unable to renew the trust between the federation server proxy and the Federation Service

#
Provider
AD FS
Channel
Unknown

Description

Unable to renew the trust between the federation server proxy and the Federation Service.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 420: The trust between the federation server proxy and the Federation Service was successfully established.

#
Provider
AD FS
Channel
Admin

Description

The trust between the federation server proxy and the Federation Service was successfully established.

Message #

The trust between the federation server proxy and the Federation Service was successfully established. 

Additional Data 

User: 
%1 

Server from which request was made: 
%2 
Certificate Subject: 
%3 
Certificate Thumbprint: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 420: The trust between the federation server proxy and the Federation Service was successfully established

#
Provider
AD FS
Channel
Unknown

Description

The trust between the federation server proxy and the Federation Service was successfully established.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 421: The trust between the federation server proxy and the Federation Service could not be established.

#
Provider
AD FS
Channel
Admin

Description

The trust between the federation server proxy and the Federation Service could not be established.

Message #

The trust between the federation server proxy and the Federation Service could not be established. 

Additional Data 

User: 
%1 

Server from which request was made: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 421: The trust between the federation server proxy and the Federation Service could not be established

#
Provider
AD FS
Channel
Unknown

Description

The trust between the federation server proxy and the Federation Service could not be established.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 432: Error handling request from proxy at data1.

#
Provider
AD FS
Channel
Admin

Description

Error handling request from proxy at data1.

Message #

Error handling request from proxy at %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 432: Error handling request from proxy at

#
Provider
AD FS
Channel
Unknown

Description

Error handling request from proxy at.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 433: Error encountered while renewing trust with the federation server proxy.

#
Provider
AD FS
Channel
Admin

Description

Error encountered while renewing trust with the federation server proxy.

Message #

Error encountered while renewing trust with the federation server proxy.  

Additional Data 
Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 433: Error encountered while renewing trust with the federation server proxy

#
Provider
AD FS
Channel
Unknown

Description

Error encountered while renewing trust with the federation server proxy.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 434: The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) will expire at data2 UTC.

#
Provider
AD FS
Channel
Admin

Description

The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) will expire at data2 UTC.

Message #

The primary AD FS certificate authority issuer certificate ( thumbprint %1 ) will expire at %2 UTC. 
The certificate rollover service will roll over to the current secondary ( thumbprint %3 ) at %4 UTC. 
To avoid certificate issuance service interruption, ensure that the current secondary certificate ( thumbprint %3 ) is installed in Active Directory before the rollover occurs at %4 UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 434: The primary AD FS certificate authority issuer certificate ( thumbprint data1 ) will expire at data2 UTC

#
Provider
AD FS
Channel
Unknown

Description

The primary AD FS certificate authority issuer certificate ( thumbprint ) will expire at UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 435: The primary AD FS token signing certificate ( thumbprint data1 ) will expire at data2 UTC.

#
Provider
AD FS
Channel
Admin

Description

The primary AD FS token signing certificate ( thumbprint data1 ) will expire at data2 UTC.

Message #

The primary AD FS token signing certificate ( thumbprint %1 ) will expire at %2 UTC. 
The certificate rollover service will roll over to the current secondary ( thumbprint %3 ) at %4 UTC. 
Relying parties that rely on federation metadata will be notified automatically; any relying parties that do not rely on federation metadata must be informed of the new certificate before the rollover at %4 UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 435: The primary AD FS token signing certificate ( thumbprint data1 ) will expire at data2 UTC

#
Provider
AD FS
Channel
Unknown

Description

The primary AD FS token signing certificate ( thumbprint ) will expire at UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 436: The primary AD FS token decryption certificate ( thumbprint data1 ) will expire at data2 UTC.

#
Provider
AD FS
Channel
Admin

Description

The primary AD FS token decryption certificate ( thumbprint data1 ) will expire at data2 UTC.

Message #

The primary AD FS token decryption certificate ( thumbprint %1 ) will expire at %2 UTC. 
The certificate rollover service will roll over to the current secondary ( thumbprint %3 ) at %4 UTC. 
Identity providers that rely on federation metadata will be notified automatically; any identity providers that send encrypted tokens to AD FS and do not rely on federation metadata must be informed of the new certificate before the expiration at %2 UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 436: The primary AD FS token decryption certificate ( thumbprint data1 ) will expire at data2 UTC

#
Provider
AD FS
Channel
Unknown

Description

The primary AD FS token decryption certificate ( thumbprint ) will expire at UTC.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 437: Error encountered while checking for pending certificate rollovers.

#
Provider
AD FS
Channel
Admin

Description

Error encountered while checking for pending certificate rollovers.

Message #

Error encountered while checking for pending certificate rollovers. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC. 
If this issue persists, AD FS will not be able to advise of pending certificate rollover events. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 437: Error encountered while checking for pending certificate rollovers

#
Provider
AD FS
Channel
Unknown

Description

Error encountered while checking for pending certificate rollovers.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 438: Error encountered while checking rollover status of the AD FS certificate authority issuer certificate.

#
Provider
AD FS
Channel
Admin

Description

Error encountered while checking rollover status of the AD FS certificate authority issuer certificate.

Message #

Error encountered while checking rollover status of the AD FS certificate authority issuer certificate. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC.  Future runs may occur on other farm nodes if AD FS is running in a farm configuration. 
If this issue persists, the AD FS certificate authority issuer certificate cannot be rolled over successfully when it nears expiry. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 438: Error encountered while checking rollover status of the AD FS certificate authority issuer certificate

#
Provider
AD FS
Channel
Unknown

Description

Error encountered while checking rollover status of the AD FS certificate authority issuer certificate.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 439: Error encountered while attempting to read an enrollment certificate from a template.

#
Provider
AD FS
Channel
Admin

Description

Error encountered while attempting to read an enrollment certificate from a template.

Message #

Error encountered while attempting to read an enrollment certificate from a template. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 439: Error encountered while attempting to read an enrollment certificate from a template

#
Provider
AD FS
Channel
Unknown

Description

Error encountered while attempting to read an enrollment certificate from a template.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 440: A Certificate Authority Enrollment Certificate was found.

#
Provider
AD FS
Channel
Admin

Description

A Certificate Authority Enrollment Certificate was found.

Message #

A Certificate Authority Enrollment Certificate was found. 

Additional Data 

Certificate Thumbprint: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 440: A Certificate Authority Enrollment Certificate was found

#
Provider
AD FS
Channel
Unknown

Description

A Certificate Authority Enrollment Certificate was found.

Fields #

NameDescription
data1 UnicodeString

Event ID 441: A token with a bad token binding key was found.

#
Provider
AD FS
Channel
Admin

Description

A token with a bad token binding key was found.

Message #

A token with a bad token binding key was found. 

Additional Data 

User: %1 
Target RP: %2 
Client IP: %3 
Token Binding ID: %4 
Request Provided ID: %5 
Request Referred ID: %6

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 441: A token with a bad token binding key was found

#
Provider
AD FS
Channel
Unknown

Description

A token with a bad token binding key was found.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 442: The CA enrollment certificate management cycle was initiated.

#
Provider
AD FS
Channel
Admin

Description

The CA enrollment certificate management cycle was initiated.

Message #

The CA enrollment certificate management cycle was initiated.

Event ID 442: The CA enrollment certificate management cycle was initiated

#
Provider
AD FS
Channel
Unknown

Description

The CA enrollment certificate management cycle was initiated.

Event ID 443: The CA enrollment certificate management cycle was completed.

#
Provider
AD FS
Channel
Admin

Description

The CA enrollment certificate management cycle was completed.

Message #

The CA enrollment certificate management cycle was completed.

Event ID 443: The CA enrollment certificate management cycle was completed

#
Provider
AD FS
Channel
Unknown

Description

The CA enrollment certificate management cycle was completed.

Event ID 444: Error encountered while checking status of the AD FS enrollment certificate.

#
Provider
AD FS
Channel
Admin

Description

Error encountered while checking status of the AD FS enrollment certificate.

Message #

Error encountered while checking status of the AD FS enrollment certificate. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC. 
If this issue persists, the AD FS will not be able to enroll certificate. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 444: Error encountered while checking status of the AD FS enrollment certificate

#
Provider
AD FS
Channel
Unknown

Description

Error encountered while checking status of the AD FS enrollment certificate.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 445: A token with no binding was received on a request which is token-binding-capable.

#
Provider
AD FS
Channel
Admin

Description

A token with no binding was received on a request which is token-binding-capable.

Message #

A token with no binding was received on a request which is token-binding-capable.  
This could be evidence of a possible downgrade attack, or it could mean the token originally came from a server that doesn't support token binding. 

Additional Data 

User: %1 
Target RP: %2 
Client IP: %3 
Request Provided ID: %4 
Request Referred ID: %5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 445: A token with no binding was received on a request which is token-binding-capable

#
Provider
AD FS
Channel
Unknown

Description

A token with no binding was received on a request which is token-binding-capable.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 446: An SSO token with no binding was received on a request which is token-binding-capable.

#
Provider
AD FS
Channel
Admin

Description

An SSO token with no binding was received on a request which is token-binding-capable. This is evidence of a possible downgrade attack.

Message #

An SSO token with no binding was received on a request which is token-binding-capable. This is evidence of a possible downgrade attack.  

Additional Data 

User: %1 
Target RP: %2 
Client IP: %3 
Request Provided ID: %4 
Request Referred ID: %5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 446: An SSO token with no binding was received on a request which is token-binding-capable

#
Provider
AD FS
Channel
Unknown

Description

An SSO token with no binding was received on a request which is token-binding-capable. This is evidence of a possible downgrade attack.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 447: Error encountered while attempting to update the configuration policy for the template data1.

#
Provider
AD FS
Channel
Admin

Description

Error encountered while attempting to update the configuration policy for the template data1. If the template is published under machine policy, service might not be able to read it.

Message #

Error encountered while attempting to update the configuration policy for the template %1. If the template is published under machine policy, service might not be able to read it. 
See https://go.microsoft.com/fwlink/?linkid=852318 for more information. 

Exception details: UpdateMachinePolicyConfigurationForTemplate returned error: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 447: Error encountered while attempting to update the configuration policy for the template

#
Provider
AD FS
Channel
Unknown

Description

Error encountered while attempting to update the configuration policy for the template . If the template is published under machine policy, service might not be able to read it.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 448: Error encountered while attempting to add a leased task to the database.

#
Provider
AD FS
Channel
Admin

Description

Error encountered while attempting to add a leased task to the database.

Message #

Error encountered while attempting to add a leased task to the database. 

Additional Data: 

Task name: %1 
Error: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 448: Error encountered while attempting to add a leased task to the database

#
Provider
AD FS
Channel
Unknown

Description

Error encountered while attempting to add a leased task to the database.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 449: Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task.

#
Provider
AD FS
Channel
Admin

Description

Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task.

Message #

Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task. 

Additional Data: 

Error: %1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 449: Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task

#
Provider
AD FS
Channel
Unknown

Description

Error encountered while executing the The AddFarmNodesIdentifierBackgroundTask task.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 450: Error encountered while removing the expired items from the usercode cache.

#
Provider
AD FS
Channel
Admin

Description

Error encountered while removing the expired items from the usercode cache.

Message #

Error encountered while removing the expired items from the usercode cache. 

Additional Data: 

Error: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 450: Error encountered while removing the expired items from the usercode cache

#
Provider
AD FS
Channel
Unknown

Description

Error encountered while removing the expired items from the usercode cache.

Fields #

NameDescription
data1 UnicodeString

Event ID 451: Following nodes have the reported heartbeat older than data1 UTC and will be deleted.

#
Provider
AD FS
Channel
Admin

Description

Following nodes have the reported heartbeat older than data1 UTC and will be deleted.

Message #

Following nodes have the reported heartbeat older than %1 UTC and will be deleted. 

%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 451: Following nodes have the reported heartbeat older than data1 UTC and will be deleted

#
Provider
AD FS
Channel
Unknown

Description

Following nodes have the reported heartbeat older than UTC and will be deleted.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 452: task_0452

#
Provider
AD FS
Channel
Admin

Message #

%1

Fields #

NameDescription
data1 UnicodeString

Event ID 452

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Event ID 500: More information for the event entry with Instance ID data1.

#
Provider
AD FS
Channel
Admin

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID:  
%1 
 

Issued identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 500: More information for the event entry with Instance ID

#
Provider
AD FS
Channel
Unknown

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 501: More information for the event entry with Instance ID Event.EventData.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

More information for the event entry with Instance ID Event.EventData. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID: 
%1 
 
Caller identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 501,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:37.250884+00:00",
    "event_record_id": 97,
    "correlation": {
      "ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "a6f4ff0b-8776-43a4-9be1-6b9bf86e338f",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname",
          "ludus\\domainadmin",
          "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name",
          "ludus\\domainadmin",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysid",
          "S-1-5-21-1006758700-2167138679-1475694448-1105",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-572",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-1149",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-18-1",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-519",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-518",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-512",
          "http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsid",
          "S-1-5-21-1006758700-2167138679-1475694448-520"
        ]
      }
    }
  },
  "message": ""
}

Event ID 501: More information for the event entry with Instance ID

#
Provider
AD FS
Channel
Unknown
Level
4

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 501,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:09:23.9078077+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "2699b4ab-8f31-4d84-a931-f6e38783fc3bhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/implicitupndomainadmin@ludus.domainhttp://schemas.microsoft.com/ws/2014/01/identity/claims/accountstoreAD AUTHORITYhttp://schemas.microsoft.com/ws/2014/01/identity/claims/anchorclaimtypehttp://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"
  }
}

Event ID 502: More information for the event entry with Instance ID data1.

#
Provider
AD FS
Channel
Admin

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID: 
%1 
 
OnBehalfOf identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 502: More information for the event entry with Instance ID

#
Provider
AD FS
Channel
Unknown

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 503: More information for the event entry with Instance ID data1.

#
Provider
AD FS
Channel
Admin

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 

Instance ID: 
%1 
 
ActAs identity: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 503: More information for the event entry with Instance ID

#
Provider
AD FS
Channel
Unknown

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 504: The following update was successful to the application proxy store on the federation server.

#
Provider
AD FS
Channel
Admin

Description

The following update was successful to the application proxy store on the federation server.

Message #

The following update was successful to the application proxy store on the federation server. 

Authentication information:  
%1 

HTTP method:  
%2 

Key: 
%3 

Value: 
%4 

Version: 
%5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 504: The following update was successful to the application proxy store on the federation server

#
Provider
AD FS
Channel
Unknown

Description

The following update was successful to the application proxy store on the federation server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 505: The following update attempt to the application proxy store on the federation server failed.

#
Provider
AD FS
Channel
Admin

Description

The following update attempt to the application proxy store on the federation server failed.

Message #

The following update attempt to the application proxy store on the federation server failed. 

Authentication information:  
%1 

HTTP method:  
%2 

Key: 
%3 

Value: 
%4 

Version: 
%5 

Error information: 
%6

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 505: The following update attempt to the application proxy store on the federation server failed

#
Provider
AD FS
Channel
Unknown

Description

The following update attempt to the application proxy store on the federation server failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 506: The following update attempt to the application proxy relying party trust on the federation server succeeded.

#
Provider
AD FS
Channel
Admin

Description

The following update attempt to the application proxy relying party trust on the federation server succeeded.

Message #

The following update attempt to the application proxy relying party trust on the federation server succeeded. 

Authentication information:  
%1 

HTTP method:  
%2 

Identifier: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 506: The following update attempt to the application proxy relying party trust on the federation server succeeded

#
Provider
AD FS
Channel
Unknown

Description

The following update attempt to the application proxy relying party trust on the federation server succeeded.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 507: The following update attempt to the application proxy relying party trust on the federation server failed.

#
Provider
AD FS
Channel
Admin

Description

The following update attempt to the application proxy relying party trust on the federation server failed.

Message #

The following update attempt to the application proxy relying party trust on the federation server failed. 

Authentication information:  
%1 

HTTP method:  
%2 

Identifier: 
%3 

Error information: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 507: The following update attempt to the application proxy relying party trust on the federation server failed

#
Provider
AD FS
Channel
Unknown

Description

The following update attempt to the application proxy relying party trust on the federation server failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 508: The following update attempt to the relying party trust on the federation server succeeded.

#
Provider
AD FS
Channel
Admin

Description

The following update attempt to the relying party trust on the federation server succeeded.

Message #

The following update attempt to the relying party trust on the federation server succeeded. 

Authentication information:  
%1 

HTTP method:  
%2 

Relying party trust identifier: 
%3 

Internal Url: 
%4 

External Url: 
%5 

Published identifier: 
%6

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 508: The following update attempt to the relying party trust on the federation server succeeded

#
Provider
AD FS
Channel
Unknown

Description

The following update attempt to the relying party trust on the federation server succeeded.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString

Event ID 509: The following update attempt to the relying party trust on the federation server failed.

#
Provider
AD FS
Channel
Admin

Description

The following update attempt to the relying party trust on the federation server failed.

Message #

The following update attempt to the relying party trust on the federation server failed. 

Authentication information:  
%1 

HTTP method:  
%2 

Relying party trust identifier: 
%3 

Internal url: 
%4 

External url: 
%5 

Published identifier: 
%6 

Error information: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 509: The following update attempt to the relying party trust on the federation server failed

#
Provider
AD FS
Channel
Unknown

Description

The following update attempt to the relying party trust on the federation server failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 510: More information for the event entry with Instance ID data1.

#
Provider
AD FS
Channel
Admin
Collection Priority
Recommended (ASD)

Description

More information for the event entry with Instance ID data1. There may be more events with the same Instance ID with more information.

Message #

More information for the event entry with Instance ID %1. There may be more events with the same Instance ID with more information. 
 
Instance ID:  
%1 
 
Details: 
%2 
%3 
%4 
%5 
%6 
%7 
%8 
%9 
%10 
%11 
%12 
%13 
%14 
%15 
%16 
%17 
%18 
%19 
%20 
%21

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 510: More information for the event entry with Instance ID

#
Provider
AD FS
Channel
Unknown
Collection Priority
Recommended (ASD)

Description

More information for the event entry with Instance ID . There may be more events with the same Instance ID with more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString
data10 UnicodeString
data11 UnicodeString
data12 UnicodeString
data13 UnicodeString
data14 UnicodeString
data15 UnicodeString
data16 UnicodeString
data17 UnicodeString
data18 UnicodeString
data19 UnicodeString
data20 UnicodeString
data21 UnicodeString

Event ID 511: The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

#
Provider
AD FS
Channel
Admin

Description

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

Message #

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.  

Request url: 
 %1 

User Action:
 Examine the Federation Service configuration and take the following actions: 
  Verify that the sign-in request has all the required parameters and is formatted correctly. 
  Verify that a web application proxy relying party trust exists, is enabled, and has identifiers which match the sign-in request parameters. 
  Verify that the target relying party trust object exists, is published through the web application proxy, and has identifiers which match the sign-in request parameters.

Fields #

NameDescription
data1 UnicodeString

Event ID 511: The incoming sign-in request is not allowed due to an invalid Federation Service configuration

#
Provider
AD FS
Channel
Unknown

Description

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

Fields #

NameDescription
data1 UnicodeString

Event ID 517: The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

#
Provider
AD FS
Channel
Admin

Description

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

Message #

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.  

Request url: 
 %1 

User Action:
 Verify that either an enabled web application proxy relying party trust exists in your Federation Service configuration or that the target relying party trust object is not published through a web application proxy.

Fields #

NameDescription
data1 UnicodeString

Event ID 517: The incoming sign-in request is not allowed due to an invalid Federation Service configuration

#
Provider
AD FS
Channel
Unknown

Description

The incoming sign-in request is not allowed due to an invalid Federation Service configuration.

Fields #

NameDescription
data1 UnicodeString

Event ID 521: The request for the relying party token resulted in a failure.

#
Provider
AD FS
Channel
Admin

Description

The request for the relying party token resulted in a failure.

Message #

The request for the relying party token resulted in a failure. 

Authentication information:  
%1 

HTTP method: 
%2 

Username:  
%3 

Password presented:  
%4 

Realm: 
%5 

Application realm:  
%6 

Device registration certificate thumbprint:  
%7 

User certificate thumbprint:  
%8 

Error information: 
%9 

User action: 
Examine the request and verify that at least one of the following parameter sets are present. 
  Username and password 
  Username, password, and device registration certificate 
  User certificate

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString

Event ID 521: The request for the relying party token resulted in a failure

#
Provider
AD FS
Channel
Unknown

Description

The request for the relying party token resulted in a failure.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString
data8 UnicodeString
data9 UnicodeString

Event ID 530: AD FS could not read the local claims provider trusts from the AD FS configuration.

#
Provider
AD FS
Channel
Admin

Description

AD FS could not read the local claims provider trusts from the AD FS configuration. AD FS will continue to operating from cached configuration.

Message #

AD FS could not read the local claims provider trusts from the AD FS configuration.  AD FS will continue to operating from cached configuration. 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 530: AD FS could not read the local claims provider trusts from the AD FS configuration

#
Provider
AD FS
Channel
Unknown

Description

AD FS could not read the local claims provider trusts from the AD FS configuration. AD FS will continue to operating from cached configuration.

Fields #

NameDescription
data1 UnicodeString

Event ID 531: AD FS could not read the local claims provider trusts from the AD FS configuration.

#
Provider
AD FS
Channel
Admin

Description

AD FS could not read the local claims provider trusts from the AD FS configuration. AD FS will not function until this configuration can be read for the first time.

Message #

AD FS could not read the local claims provider trusts from the AD FS configuration.  AD FS will not function until this configuration can be read for the first time. 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 531: AD FS could not read the local claims provider trusts from the AD FS configuration

#
Provider
AD FS
Channel
Unknown

Description

AD FS could not read the local claims provider trusts from the AD FS configuration. AD FS will not function until this configuration can be read for the first time.

Fields #

NameDescription
data1 UnicodeString

Event ID 540: The Federation Service was was unable to return the OAuth discovery document as a result of an error.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service was was unable to return the OAuth discovery document as a result of an error.

Message #

The Federation Service was was unable to return the OAuth discovery document as a result of an error. 
Document Path: %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 540: The Federation Service was was unable to return the OAuth discovery document as a result of an error

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service was was unable to return the OAuth discovery document as a result of an error.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 541: An invalid value was found during processing of the proxy configuration data from the AD FS server.

#
Provider
AD FS
Channel
Admin

Description

An invalid value was found during processing of the proxy configuration data from the AD FS server. The value will be ignored, and the rest of the proxy configuration data will be processed.

Message #

An invalid value was found during processing of the proxy configuration data from the AD FS server. The value will be ignored, and the rest of the proxy configuration data will be processed.  

Additional Data 

FarmBehavior: '%1' 

User action: 
This may point to an interoperability issue between the proxy and the AD FS server. Contact the vendor for your AD FS server.

Fields #

NameDescription
data1 UnicodeString

Event ID 541: An invalid value was found during processing of the proxy configuration data from the AD FS server

#
Provider
AD FS
Channel
Unknown

Description

An invalid value was found during processing of the proxy configuration data from the AD FS server. The value will be ignored, and the rest of the proxy configuration data will be processed.

Fields #

NameDescription
data1 UnicodeString

Event ID 542: There was an error during heartbeat.

#
Provider
AD FS
Channel
Admin

Description

There was an error during heartbeat.

Message #

There was an error during heartbeat. 

Additional data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 542: There was an error during heartbeat

#
Provider
AD FS
Channel
Unknown

Description

There was an error during heartbeat.

Fields #

NameDescription
data1 UnicodeString

Event ID 543: There was an error during heartbeat communicating to primary federation server.

#
Provider
AD FS
Channel
Admin

Description

There was an error during heartbeat communicating to primary federation server.

Message #

There was an error during heartbeat communicating to primary federation server. 

Primary server: '%1' 

Endpoint: '%2' 

Additional data 

Exception details: 
%3 

User Action 
 Make sure the primary federation server is available or the service account identity of this machine matches the service account identity of the primary federation server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 543: There was an error during heartbeat communicating to primary federation server

#
Provider
AD FS
Channel
Unknown

Description

There was an error during heartbeat communicating to primary federation server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 544: Heartbeat is not performed because primary server does not support heartbeat.

#
Provider
AD FS
Channel
Admin

Description

Heartbeat is not performed because primary server does not support heartbeat.

Message #

Heartbeat is not performed because primary server does not support heartbeat. 

Primary server: '%1'

Fields #

NameDescription
data1 UnicodeString

Event ID 544: Heartbeat is not performed because primary server does not support heartbeat

#
Provider
AD FS
Channel
Unknown

Description

Heartbeat is not performed because primary server does not support heartbeat.

Fields #

NameDescription
data1 UnicodeString

Event ID 545: Heartbeat is performed at primary server.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

Heartbeat is performed at primary server.

Message #

Heartbeat is performed at primary server. 

Primary server: '%1'

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 545,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:56.798717+00:00",
    "event_record_id": 35,
    "correlation": {
      "ActivityID": "0D26E79C-B333-000D-9A2E-270D33B3DC01"
    },
    "execution": {
      "process_id": 8080,
      "thread_id": 11896
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "localhost"
      }
    }
  },
  "message": ""
}

Event ID 545: Heartbeat is performed at primary server

#
Provider
AD FS
Channel
Unknown
Level
4

Description

Heartbeat is performed at primary server.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 545,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:13:59.8735895+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "localhost"
  }
}

Event ID 546: A current tenant certificate for Azure MFA was not found.

#
Provider
AD FS
Channel
Admin

Description

A current tenant certificate for Azure MFA was not found.

Message #

A current tenant certificate for Azure MFA was not found.  

TenantId: %1.

Fields #

NameDescription
data1 UnicodeString

Event ID 546: A current tenant certificate for Azure MFA was not found

#
Provider
AD FS
Channel
Unknown

Description

A current tenant certificate for Azure MFA was not found.

Fields #

NameDescription
data1 UnicodeString

Event ID 547: The tenant certificate for Azure MFA has been renewed.

#
Provider
AD FS
Channel
Admin

Description

The tenant certificate for Azure MFA has been renewed.

Message #

The tenant certificate for Azure MFA has been renewed.  

TenantId: %1. 
Old thumbprint: %2. 
Old expiration date: %3. 
New thumbprint: %4. 
New expiration date: %5.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 547: The tenant certificate for Azure MFA has been renewed

#
Provider
AD FS
Channel
Unknown

Description

The tenant certificate for Azure MFA has been renewed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 548: The tenant certificate for Azure MFA will expire soon.

#
Provider
AD FS
Channel
Admin

Description

The tenant certificate for Azure MFA will expire soon.

Message #

The tenant certificate for Azure MFA will expire soon.  

TenantId: %1. 
Thumbprint: %2. 
Expiration date: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 548: The tenant certificate for Azure MFA will expire soon

#
Provider
AD FS
Channel
Unknown

Description

The tenant certificate for Azure MFA will expire soon.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 549: The tenant certificate for Azure MFA has expired.

#
Provider
AD FS
Channel
Admin

Description

The tenant certificate for Azure MFA has expired.

Message #

The tenant certificate for Azure MFA has expired.  

TenantId: %1. 
Thumbprint: %2. 
Expiration date: %3.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 549: The tenant certificate for Azure MFA has expired

#
Provider
AD FS
Channel
Unknown

Description

The tenant certificate for Azure MFA has expired.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 550: The data1 primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1).

#
Provider
AD FS
Channel
Admin

Description

The data1 primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1).

Message #

The %1 primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1). 

User Action: This value can be changed by reimporting the certificate from a pfx file.  From an elevated command prompt, use the command "certutil -importpfx filename.pfx AT_KEYEXCHANGE". For more information, see http://go.microsoft.com/fwlink/?LinkId=798501

Fields #

NameDescription
data1 UnicodeString

Event ID 550: The data1 primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1)

#
Provider
AD FS
Channel
Unknown

Description

The primary certificate cannot be used because the KeySpec must have a value of AT_KEYEXCHANGE (1).

Fields #

NameDescription
data1 UnicodeString

Event ID 551: An error occurred during processing of an OAuth logout request.

#
Provider
AD FS
Channel
Admin

Description

An error occurred during processing of an OAuth logout request.

Message #

An error occurred during processing of an OAuth logout request. 
Path: %1 

Additional Data 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 551: An error occurred during processing of an OAuth logout request

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during processing of an OAuth logout request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 552: The session cookies were successfully deleted using the OAuth logout path.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

The session cookies were successfully deleted using the OAuth logout path.

Message #

The session cookies were successfully deleted using the OAuth logout path.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 552,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:53.219831+00:00",
    "event_record_id": 114,
    "correlation": {
      "ActivityID": "26B7203E-F387-4B80-0E00-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 552: The session cookies were successfully deleted using the OAuth logout path

#
Provider
AD FS
Channel
Unknown
Level
4

Description

The session cookies were successfully deleted using the OAuth logout path.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 552,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:08:53.2198315+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": ""
  }
}

Event ID 553: The specified redirect URL was validated successfully.

#
Provider
AD FS
Channel
Admin

Description

The specified redirect URL was validated successfully.

Message #

The specified redirect URL was validated successfully. 

URL: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 553: The specified redirect URL was validated successfully

#
Provider
AD FS
Channel
Unknown

Description

The specified redirect URL was validated successfully.

Fields #

NameDescription
data1 UnicodeString

Event ID 554: The specified redirect URL did not match any of the OAuth client's redirect URIs.

#
Provider
AD FS
Channel
Admin
Level
Error

Description

The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected.

Message #

The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected. 

URL: %1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 554,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:53.228256+00:00",
    "event_record_id": 115,
    "correlation": {
      "ActivityID": "26B7203E-F387-4B80-0E00-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "https://localhost"
      }
    }
  },
  "message": ""
}

Event ID 554: The specified redirect URL did not match any of the OAuth client's redirect URIs

#
Provider
AD FS
Channel
Unknown
Level
2

Description

The specified redirect URL did not match any of the OAuth client's redirect URIs. The logout was successful but the client will not be redirected.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 554,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:08:53.2282562+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "https://localhost"
  }
}

Event ID 555: The Windows Hello for Business key receipt could not be verified.

#
Provider
AD FS
Channel
Admin

Description

The Windows Hello for Business key receipt could not be verified.

Message #

The Windows Hello for Business key receipt could not be verified. 

Additional Information: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 555: The Windows Hello for Business key receipt could not be verified

#
Provider
AD FS
Channel
Unknown

Description

The Windows Hello for Business key receipt could not be verified.

Fields #

NameDescription
data1 UnicodeString

Event ID 556: Error encountered while attempting to select a master node for the account store.

#
Provider
AD FS
Channel
Admin

Description

Error encountered while attempting to select a master node for the account store.

Message #

Error encountered while attempting to select a master node for the account store. 
This check will be attempted again every %1 minutes; the next run is expected at %2 UTC.  Future runs may occur on other farm nodes if AD FS is running in a farm configuration. 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information. 

Additional Data 

Exception details: 
%3 

Additional details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 556: Error encountered while attempting to select a master node for the account store

#
Provider
AD FS
Channel
Unknown

Description

Error encountered while attempting to select a master node for the account store.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 557: An error occured while trying to communicate with the account store rest service on node data1.

#
Provider
AD FS
Channel
Admin

Description

An error occured while trying to communicate with the account store rest service on node data1.

Message #

An error occured while trying to communicate with the account store rest service on node %1.   
If this is a WID farm the primary node may be offline. 
If this is a SQL farm ADFS will automatically select a new node to host the User store master role. 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 557: An error occured while trying to communicate with the account store rest service on node

#
Provider
AD FS
Channel
Unknown

Description

An error occured while trying to communicate with the account store rest service on node .

Fields #

NameDescription
data1 UnicodeString

Event ID 558: Syncronization of the Account Activity data failed.

#
Provider
AD FS
Channel
Admin

Description

Syncronization of the Account Activity data failed.

Message #

Syncronization of the Account Activity data failed. 

Additional Data 
Exception message: 
%1 

User Action 
Ensure that the artifact storage server is configured properly. Troubleshoot network connectivity to the artifact storage server.  
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 558: Syncronization of the Account Activity data failed

#
Provider
AD FS
Channel
Unknown

Description

Syncronization of the Account Activity data failed.

Fields #

NameDescription
data1 UnicodeString

Event ID 559: Device authentication using PKeyAuth failed.

#
Provider
AD FS
Channel
Admin

Description

Device authentication using PKeyAuth failed. Request might continue without device authentication.

Message #

Device authentication using PKeyAuth failed. Request might continue without device authentication. 

Additional Information: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 559: Device authentication using PKeyAuth failed

#
Provider
AD FS
Channel
Unknown

Description

Device authentication using PKeyAuth failed. Request might continue without device authentication.

Fields #

NameDescription
data1 UnicodeString

Event ID 560: User data1 could not be found in the account database.

#
Provider
AD FS
Channel
Admin

Description

User data1 could not be found in the account database.

Message #

User %1 could not be found in the account database.

Fields #

NameDescription
data1 UnicodeString

Event ID 560: User data1 could not be found in the account database

#
Provider
AD FS
Channel
Unknown

Description

User could not be found in the account database.

Fields #

NameDescription
data1 UnicodeString

Event ID 561: Authorization failed when connecting to the account store endpoint on server data1.

#
Provider
AD FS
Channel
Admin

Description

Authorization failed when connecting to the account store endpoint on server data1.

Message #

Authorization failed when connecting to the account store endpoint on server %1 

Additional Data 

Exception Message: 
%2 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 561: Authorization failed when connecting to the account store endpoint on server

#
Provider
AD FS
Channel
Unknown

Description

Authorization failed when connecting to the account store endpoint on server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 562: An error occurred when communcating with the account store endpoint on server data1.

#
Provider
AD FS
Channel
Admin

Description

An error occurred when communcating with the account store endpoint on server data1.

Message #

An error occurred when communcating with the account store endpoint on server %1. 

Additional Data 

Exception Message: 
%2 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 562: An error occurred when communcating with the account store endpoint on server

#
Provider
AD FS
Channel
Unknown

Description

An error occurred when communcating with the account store endpoint on server .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 563: An error occurred while calculating extranet lockout status.

#
Provider
AD FS
Channel
Admin

Description

An error occurred while calculating extranet lockout status. Due to the value of the data1 setting authentication will be allowed for this user and token issuance will continue.

Message #

An error occurred while calculating extranet lockout status. Due to the value of the %1 setting authentication will be allowed for this user and token issuance will continue. 
If this is a WID farm the primary node may be offline. 
If this is a SQL farm ADFS will automatically select a new node to host the User store master role. 
See https://go.microsoft.com/fwlink/?linkid=849965 for more information. 

Additional Data 
Account store server name: 
%2 
User Id: 
%3 

Exception Message: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 563: An error occurred while calculating extranet lockout status

#
Provider
AD FS
Channel
Unknown

Description

An error occurred while calculating extranet lockout status. Due to the value of the setting authentication will be allowed for this user and token issuance will continue.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 564: The banned IP list found in Microsoft.

#
Provider
AD FS
Channel
Admin

Message #

The banned IP list found in Microsoft.IdentityServer.Servicehost.exe.config is being used instead of the banned IP list found in the ADFS configuration database.  Verify that the configuration file contains the correct list.  Clearing the banned IPs from the database using Set-ADFSProperties -RemoveBannedIPs will silence this warning.

Event ID 564: The banned IP list found in Microsoft

#
Provider
AD FS
Channel
Unknown

Event ID 565: An error occurred while attemtping to update the database schema for Adfs smart lockout.

#
Provider
AD FS
Channel
Admin

Description

An error occurred while attemtping to update the database schema for Adfs smart lockout. See https://go.microsoft.com/fwlink/?linkid=864556 for more information.

Message #

An error occurred while attemtping to update the database schema for Adfs smart lockout. See https://go.microsoft.com/fwlink/?linkid=864556 for more information. 

Additional Data 

Exception Message: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 565: An error occurred while attemtping to update the database schema for Adfs smart lockout

#
Provider
AD FS
Channel
Unknown

Description

An error occurred while attemtping to update the database schema for Adfs smart lockout. See https://go.microsoft.com/fwlink/?linkid=864556 for more information.

Fields #

NameDescription
data1 UnicodeString

Event ID 566: An error occurred during processing of an OAuth device code request.

#
Provider
AD FS
Channel
Admin

Description

An error occurred during processing of an OAuth device code request.

Message #

An error occurred during processing of an OAuth device code request. 
Error: %1 

Additional Data 

Client identifier: %2 

Full request: %3 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 566: An error occurred during processing of an OAuth device code request

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during processing of an OAuth device code request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 568: An error occurred during processing of an OAuth device auth request with the provided usercode: data1.

#
Provider
AD FS
Channel
Admin

Description

An error occurred during processing of an OAuth device auth request with the provided usercode: data1.

Message #

An error occurred during processing of an OAuth device auth request with the provided usercode: %1. 
Error: %2 

Additional Data 

User Code Data (if available): %3 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 568: An error occurred during processing of an OAuth device auth request with the provided usercode:

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during processing of an OAuth device auth request with the provided usercode: .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 570: Active Directory trust enumeration was unable to enumerate one of more domains due to the following error.

#
Provider
AD FS
Channel
Admin

Message #

Active Directory trust enumeration was unable to enumerate one of more domains due to the following error.  Enumeration will continue but the Active Directory identifier list may not be correct. Validate that all expected Active Directory identifiers are present by running Get-ADFSDirectoryProperties: 

Error string: %1 

Exception Details: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 570: Active Directory trust enumeration was unable to enumerate one of more domains due to the following error

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 571: Enumeration of the Active Directory domains failed.

#
Provider
AD FS
Channel
Admin

Description

Enumeration of the Active Directory domains failed.

Message #

Enumeration of the Active Directory domains failed. 

Exception Details: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 571: Enumeration of the Active Directory domains failed

#
Provider
AD FS
Channel
Unknown

Description

Enumeration of the Active Directory domains failed.

Fields #

NameDescription
data1 UnicodeString

Event ID 572: The Active Directory suffix from this username is not trusted by this ADFS server.

#
Provider
AD FS
Channel
Admin

Description

The Active Directory suffix from this username is not trusted by this ADFS server. If this identifier is expected it can be added to the trusted identier list by using Set-ADFSDirectoryProperties.

Message #

The Active Directory suffix from this username is not trusted by this ADFS server.  If this identifier is expected it can be added to the trusted identier list by using Set-ADFSDirectoryProperties. 

Username: %1 

Suffix: %2 

Client IP: %3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 572: The Active Directory suffix from this username is not trusted by this ADFS server

#
Provider
AD FS
Channel
Unknown

Description

The Active Directory suffix from this username is not trusted by this ADFS server. If this identifier is expected it can be added to the trusted identier list by using Set-ADFSDirectoryProperties.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 573: The following error was generated by a threat detection module.

#
Provider
AD FS
Channel
Admin

Description

The following error was generated by a threat detection module.

Message #

The following error was generated by a threat detection module. 

Module Identifier: %1 

Message: %2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 573: The following error was generated by a threat detection module

#
Provider
AD FS
Channel
Unknown

Description

The following error was generated by a threat detection module.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 574: A threat detection module failed to load.

#
Provider
AD FS
Channel
Admin

Description

A threat detection module failed to load. Verify the module binary is correctly installed on this node.

Message #

A threat detection module failed to load.  Verify the module binary is correctly installed on this node. 

Module Name: %1 

Module Identifier: %2 

Type: %3 

Failure Message: %4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 574: A threat detection module failed to load

#
Provider
AD FS
Channel
Unknown

Description

A threat detection module failed to load. Verify the module binary is correctly installed on this node.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 575: The following threat detection module was successfully loaded.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

The following threat detection module was successfully loaded.

Message #

The following threat detection module was successfully loaded 

Module Name: %1 

Module Identifier: %2 

Type: %3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 575,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:03:53.739665+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 11528,
      "thread_id": 11808
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "BannedIpProvider",
          "",
          "Microsoft.IdentityServer.Service.AccountPolicy.BannedIpProvider, Microsoft.IdentityServer.Service, Version=10.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"
        ]
      }
    }
  },
  "message": ""
}

Event ID 575: The following threat detection module was successfully loaded

#
Provider
AD FS
Channel
Unknown

Description

The following threat detection module was successfully loaded.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 575,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-24T22:33:03.4173770+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 576: An unexpected error was returned from a threat detection module.

#
Provider
AD FS
Channel
Admin

Description

An unexpected error was returned from a threat detection module.

Message #

An unexpected error was returned from a threat detection module. 

Module Name: %1 

Module Identifier: %2 

Type: %3 

Exception Type: %4 

Error Message: %5

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 576: An unexpected error was returned from a threat detection module

#
Provider
AD FS
Channel
Unknown

Description

An unexpected error was returned from a threat detection module.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Event ID 1000: An error occurred during processing of a token request.

#
Provider
AD FS
Channel
Admin
Level
Warning

Message #

An error occurred during processing of a token request. The data in this event may have the identity of the caller (application) that made this request. The data includes an Activity ID that you can cross-reference to error or warning events to help diagnose the problem that caused this error.  

Additional Data 

Caller:
 %1 

OnBehalfOf user:
 %2 

ActAs user:
 %3 

Target Relying Party:
 %4 

Device identity:
 %5 

User action: 
Use the Activity ID data in this message to search and correlate the data to events in the Event log using Event Viewer. This Activity ID will also be shown as additional information in the error page when an error occurs in the federation passive Web application.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1000,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:37.253680+00:00",
    "event_record_id": 101,
    "correlation": {
      "ActivityID": "9AE06E63-2F0D-47E6-820D-3F3EAADF8F67"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": [
          "ludus\\domainadmin\r\n",
          "",
          "",
          "https://testrp1.example.com/saml",
          ""
        ]
      }
    }
  },
  "message": ""
}

Event ID 1000: An error occurred during processing of a token request

#
Provider
AD FS
Channel
Unknown
Level
3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 1000,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:09:23.9078230+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "ludus\\domainadmin\nhttps://testrp1.example.com/saml"
  }
}

Event ID 1020: Encountered error during OAuth authorization request.

#
Provider
AD FS
Channel
Admin
Level
Error

Description

Encountered error during OAuth authorization request.

Message #

Encountered error during OAuth authorization request. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1020,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:08:52.935997+00:00",
    "event_record_id": 108,
    "correlation": {
      "ActivityID": "E915B92E-2E46-4CB5-0900-0040080000F4"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 12680
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\r\n\r\n"
      }
    }
  },
  "message": ""
}

Event ID 1020: Encountered error during OAuth authorization request

#
Provider
AD FS
Channel
Unknown
Level
2

Description

Encountered error during OAuth authorization request.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 1020,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:08:53.1122569+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9223: Received invalid OAuth authorization request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'fake'. \n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationRequestContext.ValidateCore()\n\n"
  }
}

Event ID 1021: Encountered error during OAuth token request.

#
Provider
AD FS
Channel
Admin
Level
Error

Description

Encountered error during OAuth token request.

Message #

Encountered error during OAuth token request. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1021,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:07:36.668080+00:00",
    "event_record_id": 94,
    "correlation": {
      "ActivityID": "43EBE48F-E201-482C-1500-00400A0000FF"
    },
    "execution": {
      "process_id": 9844,
      "thread_id": 8576
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": {
        "Data": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9241: Received invalid OAuth access token request. The received 'client_id' is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client_id: 'nonexistent'. \r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthTokenRequestContext.ValidateCore()\r\n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthClientCredentialsContext.ValidateCore()\r\n\r\n"
      }
    }
  },
  "message": ""
}

Event ID 1021: Encountered error during OAuth token request

#
Provider
AD FS
Channel
Unknown
Level
2

Description

Encountered error during OAuth token request.

Fields #

NameDescription
data1 UnicodeString

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 1021,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T23:08:52.9024091+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS"
  },
  "event_data": {
    "EventData": "Microsoft.IdentityServer.Web.Protocols.OAuth.Exceptions.OAuthInvalidClientException: MSIS9300: Received invalid OAuth client credentials request. The received client is invalid as no registered client was found with this client identifier. Make sure that the client is registered. Received client: 'fake'. \n   at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthToken.OAuthUsernamePasswordContext.ValidateCore()\n\n"
  }
}

Event ID 1080: An error occurred while processing WebFinger request.

#
Provider
AD FS
Channel
Admin

Description

An error occurred while processing WebFinger request.

Message #

An error occurred while processing WebFinger request. 

Additional Data 
Request url: %1 

User Action 
Examine the exception details to take one or more of the following actions if applicable. 
  Verify that the resource query parameter exists and is valid representing an authorization server's URL. 
  Verify that all federation partners (RP-STSs) that this ADFS issues tokens to (including any chains) have been configured using powershell cmdlet Add-ADFSTrustedFederationPartner. 

Exception details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1080: An error occurred while processing WebFinger request

#
Provider
AD FS
Channel
Unknown

Description

An error occurred while processing WebFinger request.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1100: The Federation Service could not authorize a request to one of the REST endpoints.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service could not authorize a request to one of the REST endpoints.

Message #

The Federation Service could not authorize a request to one of the REST endpoints. 

Additional Data 

Exception details: 
%1

Fields #

NameDescription
data1 UnicodeString

Event ID 1100: The Federation Service could not authorize a request to one of the REST endpoints

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service could not authorize a request to one of the REST endpoints.

Fields #

NameDescription
data1 UnicodeString

Event ID 1109: The Federation Service failed to connect to the LDAP account store to authenticate user data2.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service failed to connect to the LDAP account store to authenticate user data2.

Message #

The Federation Service failed to connect to the LDAP account store to authenticate user %2. 

Activity ID: %1 

Request Details: 
    User DN: %2 
    Local CP trust identifier: %3 
    LDAP server: %4 
    SSL: %5 
    Authentication method: %6 

Exception details: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1109: The Federation Service failed to connect to the LDAP account store to authenticate user

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service failed to connect to the LDAP account store to authenticate user .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1110: The Federation Service failed to connect to the primary LDAP account store to authenticate user data2.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service failed to connect to the primary LDAP account store to authenticate user data2.

Message #

The Federation Service failed to connect to the primary LDAP account store to authenticate user %2. 

Activity ID: %1 

Request Details: 
    User DN: %2 
    Local CP trust identifier: %3 
    Ldap server: %4 
    SSL: %5 
    Authentication method: %6 

Exception details: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1110: The Federation Service failed to connect to the primary LDAP account store to authenticate user

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service failed to connect to the primary LDAP account store to authenticate user .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1111: The Federation Service failed to connect to all LDAP account stores to authenticate user data2.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service failed to connect to all LDAP account stores to authenticate user data2.

Message #

The Federation Service failed to connect to all LDAP account stores to authenticate user %2. 

Activity ID: %1 

Request Details: 
    User DN: %2 
    Local CP trust identifier: %3 
    Ldap server: %4 
    SSL: %5 
    Authentication method: %6 

Exception details: 
%7

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1111: The Federation Service failed to connect to all LDAP account stores to authenticate user

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service failed to connect to all LDAP account stores to authenticate user .

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString
data5 UnicodeString
data6 UnicodeString
data7 UnicodeString

Event ID 1112: The Federation Service failed to connect to the Ldap server.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service failed to connect to the Ldap server.

Message #

The Federation Service failed to connect to the Ldap server. 

Activity ID: %1 

Request Details: 
    Local CP trust identifier: %2 
    Ldap ErrorCode: %3 

Exception details: 
%4

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 1112: The Federation Service failed to connect to the Ldap server

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service failed to connect to the Ldap server.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 1113: Client Json Web Key Set (JWKS) synchronization initiated.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

Client Json Web Key Set (JWKS) synchronization initiated.

Message #

Client Json Web Key Set (JWKS) synchronization initiated.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1113,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.121414+00:00",
    "event_record_id": 73,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 10760
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 1113: Client Json Web Key Set (JWKS) synchronization initiated

#
Provider
AD FS
Channel
Unknown

Description

Client Json Web Key Set (JWKS) synchronization initiated.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 1113,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.2438903+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 1114: Client Json Web Key Set (JWKS) synchronization completed.

#
Provider
AD FS
Channel
Admin
Level
Informational

Description

Client Json Web Key Set (JWKS) synchronization completed.

Message #

Client Json Web Key Set (JWKS) synchronization completed.

Fields #

NameDescription
Event.EventData

Example Event #

{
  "system": {
    "provider": "AD FS",
    "guid": "2FFB687A-1571-4ACE-8550-47AB5CCAE2BC",
    "event_source_name": "",
    "event_id": 1114,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T23:05:10.154935+00:00",
    "event_record_id": 80,
    "correlation": {},
    "execution": {
      "process_id": 9844,
      "thread_id": 10760
    },
    "channel": "AD FS/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
    }
  },
  "user_data": {
    "Event": {
      "EventData": null
    }
  },
  "message": ""
}

Event ID 1114: Client Json Web Key Set (JWKS) synchronization completed

#
Provider
AD FS
Channel
Unknown

Description

Client Json Web Key Set (JWKS) synchronization completed.

Example Event #

{
  "system": {
    "provider": "AD FS",
    "event_id": 1114,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-27T16:14:39.2578083+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "AD FS/Admin"
  },
  "event_data": {
    "EventData": null
  }
}

Event ID 1115: The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from 'data1'.

#
Provider
AD FS
Channel
Admin

Description

The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from 'data1'. The key synchronization for the following client failed.

Message #

The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from '%1'. The key synchronization for the following client failed: 

Client: 
%2 

Additional Data 

Exception details: 
%3 

Additional details: 
%4 

User Action 
Make sure the JWKS URI '%1' is accessible.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 1115: The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from 'data1'

#
Provider
AD FS
Channel
Unknown

Description

The Federation Service encountered an error while retrieving the Json Web Key Set (JWKS) document from 'data1'. The key synchronization for the following client failed.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString
data4 UnicodeString

Event ID 1116: An error occurred during a read operation from the configuration database.

#
Provider
AD FS
Channel
Admin

Message #

An error occurred during a read operation from the configuration database. Monitoring of clients' Json Web Key Set (JWKS) was shut down and will be tried again after an amount of time that corresponds to the monitoring interval. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1116: An error occurred during a read operation from the configuration database

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1117: An error occurred during monitoring of the following client's Json Web Key Set (JWKS).

#
Provider
AD FS
Channel
Admin

Description

An error occurred during monitoring of the following client's Json Web Key Set (JWKS).

Message #

An error occurred during monitoring of the following client's Json Web Key Set (JWKS). 

Client: 
%1 

Additional Data 

Exception details: 
%2 

Additional details: 
%3

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 1117: An error occurred during monitoring of the following client's Json Web Key Set (JWKS)

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during monitoring of the following client's Json Web Key Set (JWKS).

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString
data3 UnicodeString

Event ID 1118: An error occurred during monitoring of clients'Json Web Key Set (JWKS).

#
Provider
AD FS
Channel
Admin

Description

An error occurred during monitoring of clients'Json Web Key Set (JWKS). The monitoring cycle was shut down.

Message #

An error occurred during monitoring of clients'Json Web Key Set (JWKS). The monitoring cycle was shut down. 

Additional Data 

Exception details: 
%1 

Additional details: 
%2

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1118: An error occurred during monitoring of clients'Json Web Key Set (JWKS)

#
Provider
AD FS
Channel
Unknown

Description

An error occurred during monitoring of clients'Json Web Key Set (JWKS). The monitoring cycle was shut down.

Fields #

NameDescription
data1 UnicodeString
data2 UnicodeString

Event ID 1130: There was an error establishing or renewing the proxy trust.

#
Provider
AD FS
Channel
Admin

Description

There was an error establishing or renewing the proxy trust. Ensure the STS and proxy servers have the same TLS version enabled.

Message #

There was an error establishing or renewing the proxy trust. Ensure the STS and proxy servers have the same TLS version enabled. 
Consult the following links for additional details: 
https://go.microsoft.com/fwlink/?linkid=875038  
https://go.microsoft.com/fwlink/?linkid=875039  

Additional Data 

Exception Details: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 1130: There was an error establishing or renewing the proxy trust

#
Provider
AD FS
Channel
Unknown

Description

There was an error establishing or renewing the proxy trust. Ensure the STS and proxy servers have the same TLS version enabled.

Fields #

NameDescription
data1 UnicodeString

Event ID 1131: There was an error establishing or renewing the trust between the proxy and STS.

#
Provider
AD FS
Channel
Admin

Message #

There was an error establishing or renewing the trust between the proxy and STS. Ensure the Network Service Account has Read/Write permissions on C:\Program Data\Microsoft\Crypto\RSA\Machine Keys on the proxy server. 
Consult the following link for additional details: 
https://go.microsoft.com/fwlink/?linkid=875037  

Additional Data 

Exception Details: %1

Fields #

NameDescription
data1 UnicodeString

Event ID 1131: There was an error establishing or renewing the trust between the proxy and STS

#
Provider
AD FS
Channel
Unknown

Fields #

NameDescription
data1 UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 2ffb687a-1571-4ace-8550-47ab5ccae2bc

Defined in Microsoft.IdentityServer.NativeResources.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 5.00, captured 2026-06-02