LsaSrv

88 events across 6 channels

EventTitleChannelSample
100The security package does not cache the credentials needed to authenticate to …OperationalN
200A security package received a network logon request after the logoff completed.OperationalN
300Groups assigned to a new logon.OperationalY
301Claims assigned to a new logon.OperationalN
302User UserSid logged off notification is received.OperationalY
303The security package does not cache the user's sign on credentials.OperationalY
320Automatic restart sign on successfully configured the autologon credentials for: …OperationalN
321Automatic restart sign on failed to configure the autologon credentials with …OperationalY
322Automatic restart sign on successfully deleted autologon credentials from LSA …OperationalN
5000The security package Package generated an exception.SystemN
6025Could not upgrade the Trusted domain object for domain {Domain}.SystemN
6027Could not upgrade the global secret Secret.SystemN
6029LSA could not update domain information in the registry to match the DS.SystemN
6031The database contains invalid information for trusted domain {Domain}.SystemN
6033An anonymous session connected from Client has attempted to open an LSA policy …SystemN
6034The new top level name; {TopLevelName}; has been added to the forest …SystemN
6035During a logon attempt, the user's security context accumulated too many …SystemN
6036The program Program, with the assigned Process ID PID, supplied a NULL or empty …SystemN
6037The program Data_1, with the assigned process ID Data_0, could not authenticate …SystemY
6038Microsoft Windows Server has detected that NTLM authentication is presently …SystemY
6039Microsoft Windows Server has detected that NTLM authentication is being used …SystemN
6040An authentication request for package Package was rejected because the target …SystemN
6041A CredSSP authentication to TargetName failed to negotiate a common protocol …SystemN
6144A secret object private to LSA was queried by a client.SystemY
6145An error occurred while retrieving new Central Access Policies for this machine.SystemN
6146An error occurred while processing new Central Access Policies for this machine.SystemN
6147Credential Guard is configured to run, but is not licensed.SystemN
6148The PDC completed an automatic trust scan operation for all trusts with no …SystemY
6149The PDC completed an automatic trust scan operation for all trusts and …SystemN
6150The PDC completed an administrator-requested trust scan operation for the trust …SystemN
6151The PDC was unable to find the specified trust 'TrustName' to scan.SystemN
6152The PDC completed an administrator-requested trust scan operation for the trust …SystemN
6153The PDC encountered an error trying to scan the named trust.SystemN
6154Possible use of roaming Credential Manager credentials with Credential Guard …SystemN
6155LSA package is not signed as expected.SystemY
6156Credential Guard auto enablement status.SystemY
6157The PDC completed a background trust scan operation of the named trust.SystemN
6158Error reading Credential Guard.SystemN
6160LsaIso.SystemN
6161Credential Guard configuration: Config, IsTestConfig, AutoEnabled.SystemN
6162Key Guard was started and will protect VSM-isolated keys.SystemN
6163Credential Guard was started and will protect LSA credentials.SystemN
6164Credential Guard is configured but the secure kernel is not running; continuing …SystemN
6165VBS bound machine secret is present but falling back to LSA bound secret.SystemN
6166Machine Identity Isolation status.SystemN
6167There is a partial mismatch in the machine ID.SystemN
6167There is a partial mismatch in the machine IDUnknownN
6182LogonSession alive after interactive user logoff.DiagnosticN
6225CATEGORY_LSA_LOGONPerformanceY
6226CATEGORY_LSA_LOGONPerformanceY
6227LSASID_NameLookupStartPerformanceN
6228LSASID_NameLookupStopPerformanceN
6229LSASID_NameLookupStart6229PerformanceN
6230LSASID_NameLookupStop6230PerformanceN
6231SecurityPackageManagerStartPerformanceN
6232SecurityPackageManagerStopPerformanceN
29186Moving the existing logon scripts from {OldScripts} to {NewScripts} failed.SystemN
29187Running the Security Configuration Editor over the Domain Controller encountered …SystemN
29188An existing; incompatible trust object was found on the parent server for domain …SystemN
29216Failed to disable auto logon following the successful upgrade of a domain …SystemN
29217Failed to set the default logon domain to {DomainName}.SystemN
29221During the demotion operation; the trust object on {ParentName} could not be …SystemN
29241Dcpromo failed to configure the new starttype of {Flags} for the service …SystemN
29242Dcpromo failed to remove the dependency of {ServiceName} on {Dependency} during …SystemN
32768The interdomain trust account for the domain {Domain} could not be deleted.SystemN
32772The interdomain trust account for the domain {Domain} could not be created.SystemN
32773A lookup request was made that required connectivity to a domain controller in …SystemN
32774A lookup request was made that required connectivity to the domain controller …SystemN
32775A lookup request was made that required the lookup services on the remote domain …SystemN
32777The LSA was unable to register its RPC interface over the TCP/IP interface.SystemN
32778The name {Name} was translated to SID {SID} from the trusted forest {Forest}.SystemN
32779task_032779ApplicationN
32779task_032779UnknownN
32780The LSA was unable to notify UBPM during startup with status Status.SystemN
40960The Security System detected an authentication error for the server Target.SystemN
40961The Security System could not establish a secured connection with the server …SystemN
40962The Security System was unable to authenticate to the server Target because the …SystemN
40964The Security System received an authentication attempt with an unknown …SystemN
40965The Security System has selected Protocol for the authentication protocol to …SystemN
40966The Security System has received an authentication attempt, and determined that …SystemN
40967The Security System has received an authentication request directly for …SystemN
40968The Security System has received an authentication request that could not be …SystemN
40969The Security System has received an authentication attempt, and determined that …SystemN
40970The Security System has detected a downgrade attempt when contacting the 3-part …SystemY
40971The Security System is auditing a downgrade attempt when contacting the 3-part …ApplicationN
45056Logon cache was disabled.SystemN
45057A failed logon attempt has caused a logon cache entry for user Username to be …SystemY
45058A logon cache entry for user UserName was the oldest entry and was removed.SystemN

Event ID 100: The security package does not cache the credentials needed to authenticate to the server.

#
Provider
LsaSrv
Channel
Operational

Description

The security package does not cache the credentials needed to authenticate to the server.

Message #

The security package does not cache the credentials needed to authenticate to the server.

Package Name: %1
User Name: %2
Domain Name: %3
Server Name: %4
Protected User: %5
Error Code: %6

Fields #

NameDescription
PackageName UnicodeString
UserName UnicodeString
DomainName UnicodeString
ServerName UnicodeString
ProtectedUser UInt32
ErrorCode HexInt32

Event ID 200: A security package received a network logon request after the logoff completed.

#
Provider
LsaSrv
Channel
Operational

Description

A security package received a network logon request after the logoff completed.

Message #

A security package received a network logon request after the logoff completed.

User Name: %1
Domain Name: %2
Logon ID: %3
Logoff Time: %4
PID: %5
Program: %6
Principal Name: %7
Server Name: %8
Package Name: %9
Call Type: %10
Error Code: %11

Fields #

NameDescription
UserName UnicodeString
DomainName UnicodeString
LogonId HexInt64
LogoffTime SYSTEMTIME
PID UInt32
Program UnicodeString
PrincipalName UnicodeString
ServerName UnicodeString
PackageName UnicodeString
CallType UnicodeString
ErrorCode HexInt32

Event ID 300: Groups assigned to a new logon.

#
Provider
LsaSrv
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Microsoft-WEF, others)

Description

Groups assigned to a new logon.

Message #

Groups assigned to a new logon.

New Logon:
	Security ID: %1
	Account Name: %2
	Account Domain: %3
	Logon ID: %4
	Logon GUID: %5

Event in sequence: %6 of %7

Group Membership: %8

Fields #

NameDescriptionRules
TargetUserSid SID[New Logon] Security ID.4 detection rules
TargetUserName UnicodeString[New Logon] Account Name.
TargetDomainName UnicodeString[New Logon] Account Domain.
TargetLogonId HexInt64[New Logon] Logon ID.
TargetLogonGuid GUID[New Logon] Logon GUID.
EventOrginal UInt32[New Logon] Event in sequence.
EventCountTotal UInt32
SidList UnicodeString[New Logon] Group Membership.4 detection rules

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "{199FE037-2B82-40A9-82AC-E1D46C792B99}",
    "event_source_name": "",
    "event_id": 300,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-06-13T14:10:44.2128156+00:00",
    "event_record_id": 7244,
    "correlation": {},
    "execution": {
      "process_id": 896,
      "thread_id": 3036
    },
    "channel": "Microsoft-Windows-LSA/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TargetUserSid": "S-1-5-18",
    "TargetUserName": "TELEMETRY-DC-C$",
    "TargetDomainName": "cell-c",
    "TargetLogonId": "0x2993ea9",
    "TargetLogonGuid": "{00000000-0000-0000-0000-000000000000}",
    "EventOrginal": "1",
    "EventCountTotal": "1",
    "SidList": "\n\t\t%{S-1-5-32-544}\n\t\t%{S-1-1-0}\n\t\t%{S-1-5-32-554}\n\t\t%{S-1-5-32-545}\n\t\t%{S-1-5-32-560}\n\t\t%{S-1-5-2}\n\t\t%{S-1-5-11}\n\t\t%{S-1-5-15}\n\t\t%{S-1-5-21-1006758700-2167138679-1475694448-1001}\n\t\t%{S-1-5-21-1006758700-2167138679-1475694448-516}\n\t\t%{S-1-5-9}\n\t\t%{S-1-18-1}\n\t\t%{S-1-5-21-1006758700-2167138679-1475694448-572}"
  },
  "message": "Groups assigned to a new logon.\r\n\r\nNew Logon:\r\n\tSecurity ID:\t\tS-1-5-18\r\n\tAccount Name:\t\tTELEMETRY-DC-C$\r\n\tAccount Domain:\t\tcell-c\r\n\tLogon ID:\t\t0x2993EA9\r\n\tLogon GUID:\t\t{00000000-0000-0000-0000-000000000000}\r\n\r\nEvent in sequence:\t\t1 of 1\r\n\r\nGroup Membership:\t\t\r\n\t\t%{S-1-5-32-544}\r\n\t\t%{S-1-1-0}\r\n\t\t%{S-1-5-32-554}\r\n\t\t%{S-1-5-32-545}\r\n\t\t%{S-1-5-32-560}\r\n\t\t%{S-1-5-2}\r\n\t\t%{S-1-5-11}\r\n\t\t%{S-1-5-15}\r\n\t\t%{S-1-5-21-1006758700-2167138679-1475694448-1001}\r\n\t\t%{S-1-5-21-1006758700-2167138679-1475694448-516}\r\n\t\t%{S-1-5-9}\r\n\t\t%{S-1-18-1}\r\n\t\t%{S-1-5-21-1006758700-2167138679-1475694448-572}"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
TargetUserSidstarts_withS-1-5-21-1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

Event ID 301: Claims assigned to a new logon.

#
Provider
LsaSrv
Channel
Operational

Description

Claims assigned to a new logon.

Message #

Claims assigned to a new logon.

New Logon:
	Security ID: %1
	Account Name: %2
	Account Domain: %3
	Logon ID: %4
	Logon GUID: %5


	Logon Type: %6



Event in sequence: %7 of %8

User Claims: %9

Device Claims: %10

This event is generated when a new logon session is created and the user token associated with it contains user and/or device claims. The New Logon fields indicate the account that was logged on. If all the user and device claims in the user token cannot be accommodated in a single event, multiple such events are generated. The Event in sequence field indicates how many more events are generated for this logon session. Each user or device claim is represented in the following format:

	ClaimID ClaimTypeID : Value1, Value2 ? 

The common claim types are: 0 (Invalid Type), 1 (64-bit Integer, 2 (Unsigned 64-bit Integer), 3 (String), 4 (FQBN), 5 (SID), 6 (Boolean) and 16 (Blob). If the claim value exceeds the max allowed length then the string is terminated by ...

Fields #

NameDescription
TargetUserSid SIDSID of the target account.
TargetUserName UnicodeStringAccount name of the target.
TargetDomainName UnicodeStringDomain or machine name of the target account.
TargetLogonId HexInt64Logon session identifier (LUID) for the target.
TargetLogonGuid GUID
LogonType UInt32Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). Logon type reference
EventIdx UInt32
EventCountTotal UInt32
UserClaims UnicodeString
DeviceClaims UnicodeString

Event ID 302: User UserSid logged off notification is received.

#
Provider
LsaSrv
Channel
Operational
Level
Informational

Description

User UserSid logged off notification is received.

Message #

User %1 logged off notification is received.

LogonId: %2
AuthorityName: %3
AccountName: %4
Timeout: %5 seconds

Fields #

NameDescription
UserSid SID
LogonId HexInt64
AuthorityName UnicodeString
AccountName UnicodeString
Elapse UInt32

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "199FE037-2B82-40A9-82AC-E1D46C792B99",
    "event_source_name": "",
    "event_id": 302,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-14T21:58:13.455090+00:00",
    "event_record_id": 4682,
    "correlation": {},
    "execution": {
      "process_id": 940,
      "thread_id": 3528
    },
    "channel": "Microsoft-Windows-LSA/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "UserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
    "LogonId": "0xc979b",
    "AuthorityName": "ludus",
    "AccountName": "domainadmin",
    "Elapse": 30
  },
  "message": ""
}

Event ID 303: The security package does not cache the user's sign on credentials.

#
Provider
LsaSrv
Channel
Operational
Level
Informational

Description

The security package does not cache the user's sign on credentials.

Message #

The security package does not cache the user's sign on credentials.

Package Name: %1
User Name: %2
Domain Name: %3
Protected User: %4

Fields #

NameDescription
PackageName UnicodeString
UserName UnicodeString
DomainName UnicodeString
ProtectedUser UInt32

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "199FE037-2B82-40A9-82AC-E1D46C792B99",
    "event_source_name": "",
    "event_id": 303,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:06:34.507918+00:00",
    "event_record_id": 51,
    "correlation": {
      "ActivityID": "8B83AF9E-B321-0001-1AB0-838B21B3DC01"
    },
    "execution": {
      "process_id": 968,
      "thread_id": 7780
    },
    "channel": "Microsoft-Windows-LSA/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PackageName": "CREDSSP",
    "UserName": "LAB-DC01$",
    "DomainName": "ludus",
    "ProtectedUser": 0
  },
  "message": ""
}

Event ID 320: Automatic restart sign on successfully configured the autologon credentials for: Account Name: Account_Name Account Domain: Account_Domain.

#
Provider
LsaSrv
Channel
Operational

Description

Automatic restart sign on successfully configured the autologon credentials for.

Message #

Automatic restart sign on successfully configured the autologon credentials for:

	Account Name: %1
	Account Domain: %2

Fields #

NameDescription
UserName UnicodeString
DomainName UnicodeString

Event ID 321: Automatic restart sign on failed to configure the autologon credentials with error.

#
Provider
LsaSrv
Channel
Operational
Level
Informational

Description

Automatic restart sign on failed to configure the autologon credentials with error.

Message #

Automatic restart sign on failed to configure the autologon credentials with error:

%1

Fields #

NameDescription
Error UnicodeString

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "199FE037-2B82-40A9-82AC-E1D46C792B99",
    "event_source_name": "",
    "event_id": 321,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-14T01:38:46.851959+00:00",
    "event_record_id": 7296,
    "correlation": {
      "ActivityID": "C5FDF330-93D8-4242-8AA4-AC8874FCA611"
    },
    "execution": {
      "process_id": 984,
      "thread_id": 6436
    },
    "channel": "Microsoft-Windows-LSA/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Error": "\"{Access Denied}\r\nA process has requested access to an object, but has not been granted those access rights.\r\n (0xc0000022)\""
  },
  "message": ""
}

Event ID 322: Automatic restart sign on successfully deleted autologon credentials from LSA memory

#
Provider
LsaSrv
Channel
Operational

Description

Automatic restart sign on successfully deleted autologon credentials from LSA memory.

Message #

Automatic restart sign on successfully deleted autologon credentials from LSA memory

Event ID 5000: The security package Package generated an exception.

#
Provider
LsaSrv
Channel
System

Description

The security package Package generated an exception. The exception information is the data.

Message #

The security package %1 generated an exception. The exception information is the data.

Fields #

NameDescription
Package UnicodeString
__binLength UInt32
Exception Binary

Event ID 6025: Could not upgrade the Trusted domain object for domain {Domain}.

#
Provider
LsaSrv
Channel
System

Description

Could not upgrade the Trusted domain object for domain {Domain}. Please recreate the trust manually.

Message #

Could not upgrade the Trusted domain object for domain {Domain}. Please recreate the trust manually.

Fields #

NameDescription
Domain

Event ID 6027: Could not upgrade the global secret Secret.

#
Provider
LsaSrv
Channel
System

Description

Could not upgrade the global secret Secret. Please check the status of all services in the system.

Message #

Could not upgrade the global secret %1. Please check the status of all services in the system.

Fields #

NameDescription
Secret UnicodeString
__binLength UInt32
status BinaryNTSTATUS reference

Event ID 6029: LSA could not update domain information in the registry to match the DS.

#
Provider
LsaSrv
Channel
System

Description

LSA could not update domain information in the registry to match the DS. Error={Error}.

Message #

LSA could not update domain information in the registry to match the DS. Error={Error}.

Fields #

NameDescription
Error

Event ID 6031: The database contains invalid information for trusted domain {Domain}.

#
Provider
LsaSrv
Channel
System

Description

The database contains invalid information for trusted domain {Domain}.

Message #

The database contains invalid information for trusted domain {Domain}.

Fields #

NameDescription
Domain

Event ID 6033: An anonymous session connected from Client has attempted to open an LSA policy handle on this machine.

#
Provider
LsaSrv
Channel
System

Description

An anonymous session connected from Client has attempted to open an LSA policy handle on this machine. The attempt was rejected with STATUS_ACCESS_DENIED to prevent leaking security sensitive information to the anonymous caller. The application that made this attempt needs to be fixed. Please contact the application vendor. As a temporary workaround, this security measure can be disabled by setting the \HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\TurnOffAnonymousBlock DWORD value to 1. This message will be logged at most once a day.

Message #

An anonymous session connected from %1 has attempted to open an LSA policy handle on this machine. The attempt was rejected with STATUS_ACCESS_DENIED to prevent leaking security sensitive information to the anonymous caller.
 The application that made this attempt needs to be fixed. Please contact the application vendor. As a temporary workaround, this security measure can be disabled by setting the \HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\TurnOffAnonymousBlock DWORD value to 1.
 This message will be logged at most once a day.

Fields #

NameDescription
Client UnicodeString

Event ID 6034: The new top level name; {TopLevelName}; has been added to the forest {Forestname}.

#
Provider
LsaSrv
Channel
System

Message #

The new top level name; {TopLevelName}; has been added to the forest {Forestname}. Name suffix routing for this new name is disabled because it is not within any currently routed namespace. Objects can not be resolved from this new namespace until name suffix routing is enabled for the namespace. To enable name suffix routing; open Domains and Trusts and see help under Name Suffix Routing and Forest Trusts.

Fields #

NameDescription
TopLevelName
Forestname

Event ID 6035: During a logon attempt, the user's security context accumulated too many security IDs.

#
Provider
LsaSrv
Channel
System

Description

During a logon attempt, the user's security context accumulated too many security IDs. This is a very unusual situation. Remove the user from some global or local groups to reduce the number of security IDs to incorporate into the security context. User's SID is SID If this is the Administrator account, logging on in safe mode will enable Administrator to log on by automatically restricting group memberships.

Message #

During a logon attempt, the user's security context accumulated too many security IDs. This is a very unusual situation. Remove the user from some global or local groups to reduce the number of security IDs to incorporate into the security context.
User's SID is %1
If this is the Administrator account, logging on in safe mode will enable Administrator to log on by automatically restricting group memberships.

Fields #

NameDescription
SID SID

Event ID 6036: The program Program, with the assigned Process ID PID, supplied a NULL or empty target name for the pszTargetName parameter when calling the InitializeSe...

#
Provider
LsaSrv
Channel
System

Description

The program Program, with the assigned Process ID PID, supplied a NULL or empty target name for the pszTargetName parameter when calling the InitializeSecurityContext API to initiate an outbound NTLM security context. This is a security risk when mutual authentication is required. To help protect against a malicious attack, make your code more secure. To do this, change the program so that it specifies a target name in the pszTargetName parameter field, and then recompile the code.

Message #

The program %2, with the assigned Process ID %1, supplied a NULL or empty target name for the pszTargetName parameter when calling the InitializeSecurityContext API to initiate an outbound NTLM security context. This is a security risk when mutual authentication is required.
 
 To help protect against a malicious attack, make your code more secure. To do this, change the program so that it specifies a target name in the pszTargetName parameter field, and then recompile the code.

Fields #

NameDescription
PID UnicodeString
Program UnicodeString

Event ID 6037: The program Data_1, with the assigned process ID Data_0, could not authenticate locally by using the target name Data_2.

#
Provider
LsaSrv
Channel
System
Level
Warning

Description

The program Program, with the assigned process ID PID, could not authenticate locally by using the target name TargetName. The target name used is not valid. A target name should refer to one of the local computer names, for example, the DNS host name. Try a different target name.

Message #

The program %2, with the assigned process ID %1, could not authenticate locally by using the target name %3. The target name used is not valid. A target name should refer to one of the local computer names, for example, the DNS host name.
 
 Try a different target name.

Fields #

NameDescription
PID UnicodeString
Program UnicodeString
TargetName UnicodeString

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "{199fe037-2b82-40a9-82ac-e1d46c792b99}",
    "event_source_name": "LsaSrv",
    "event_id": 6037,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-15T05:52:15.004853+00:00",
    "event_record_id": 13485,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "12832",
    "Data_1": "svchost.exe",
    "Data_2": "HOST/.",
    "Binary": ""
  },
  "message": ""
}

Event ID 6038: Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server.

#
Provider
LsaSrv
Channel
System
Level
Warning

Description

Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server. NTLM is a weaker authentication mechanism. Please check: Which applications are using NTLM authentication? Are there configuration issues preventing the use of stronger authentication such as Kerberos authentication? If NTLM must be supported, is Extended Protection configured? Details on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699.

Message #

Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.
 
NTLM is a weaker authentication mechanism. Please check:
 
      Which applications are using NTLM authentication?
      Are there configuration issues preventing the use of stronger authentication such as Kerberos authentication?
      If NTLM must be supported, is Extended Protection configured?
 
Details on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699.

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "{199FE037-2B82-40A9-82AC-E1D46C792B99}",
    "event_source_name": "",
    "event_id": 6038,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:38:34.5584199+00:00",
    "event_record_id": 6842,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.\r\n \r\nNTLM is a weaker authentication mechanism. Please check:\r\n \r\n      Which applications are using NTLM authentication?\r\n      Are there configuration issues preventing the use of stronger authentication such as Kerberos authentication?\r\n      If NTLM must be supported, is Extended Protection configured?\r\n \r\nDetails on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699."
}

Detection Patterns #

Event ID 6039: Microsoft Windows Server has detected that NTLM authentication is being used between clients and this server.

#
Provider
LsaSrv
Channel
System

Description

Microsoft Windows Server has detected that NTLM authentication is being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server. NTLM is a weaker authentication mechanism. Please check: Which applications are using NTLM authentication? Are there configuration issue preventing the use stronger authentication such as Kerberos authentication? If NTLM must be supported, is Extended Protection configured? Details on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699.

Message #

Microsoft Windows Server has detected that NTLM authentication is being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.
 
NTLM is a weaker authentication mechanism. Please check:
 
      Which applications are using NTLM authentication?
      Are there configuration issue preventing the use stronger authentication such as Kerberos authentication?
      If NTLM must be supported, is Extended Protection configured?
 
Details on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699.

Detection Patterns #

Event ID 6040: An authentication request for package Package was rejected because the target information was invalid.

#
Provider
LsaSrv
Channel
System

Description

An authentication request for package Package was rejected because the target information was invalid. The authentication request did not match the target name of TargetName.

Message #

An authentication request for package %1 was rejected because the target information was invalid.  The authentication request did not match the target name of %2.

Fields #

NameDescription
Package UnicodeString
TargetName UnicodeString

Event ID 6041: A CredSSP authentication to TargetName failed to negotiate a common protocol version.

#
Provider
LsaSrv
Channel
System

Description

A CredSSP authentication to TargetName failed to negotiate a common protocol version. The remote host offered version TargetVersion which is not permitted by Encryption Oracle Remediation.

Message #

A CredSSP authentication to %1 failed to negotiate a common protocol version.  The remote host offered version %2 which is not permitted by Encryption Oracle Remediation.

See https://go.microsoft.com/fwlink/?linkid=866660 for more information.

Fields #

NameDescription
TargetName UnicodeString
TargetVersion UnicodeString

Event ID 6144: A secret object private to LSA was queried by a client.

#
Provider
LsaSrv
Channel
System
Level
Informational

Description

A secret object private to LSA was queried by a client. This object was returned in encrypted format for security reasons.

Message #

A secret object private to LSA was queried by a client. This object was returned in encrypted format for security reasons.

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "199FE037-2B82-40A9-82AC-E1D46C792B99",
    "event_source_name": "",
    "event_id": 6144,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-09T00:56:02.886908+00:00",
    "event_record_id": 2014,
    "correlation": {
      "ActivityID": "4FECCB45-5562-44FC-B3DC-6A5D82E66B8A"
    },
    "execution": {
      "process_id": 764,
      "thread_id": 6788
    },
    "channel": "System",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 6145: An error occurred while retrieving new Central Access Policies for this machine.

#
Provider
LsaSrv
Channel
System

Description

An error occurred while retrieving new Central Access Policies for this machine.

Message #

An error occurred while retrieving new Central Access Policies for this machine.

Could not retrieve policies for the following DNs:
%1

Fields #

NameDescription
MissingCAPDNs UnicodeString

References #

Event ID 6146: An error occurred while processing new Central Access Policies for this machine.

#
Provider
LsaSrv
Channel
System

Description

An error occurred while processing new Central Access Policies for this machine. Validation failed for the following Central Access Rule referenced by one or more of the Central Access Policies.

Message #

An error occurred while processing new Central Access Policies for this machine. Validation failed for the following Central Access Rule referenced by one or more of the Central Access Policies:

	Error: %1

	Name: %2
	Description: %3

Fields #

NameDescription
Error UnicodeString[An error occurred while processing new Central Access Policies for this machine. Validation failed for the following Central Access Rule referenced by one or more of the Central Access Policies] Error.
CAPEName UnicodeString
CAPEDesc UnicodeString

Event ID 6147: Credential Guard is configured to run, but is not licensed.

#
Provider
LsaSrv
Channel
System

Description

Credential Guard is configured to run, but is not licensed. Credential Guard was not started.

Message #

Credential Guard is configured to run, but is not licensed. Credential Guard was not started.

Event ID 6148: The PDC completed an automatic trust scan operation for all trusts with no errors.

#
Provider
LsaSrv
Channel
System
Level
Informational

Description

The PDC completed an automatic trust scan operation for all trusts with no errors.

Message #

The PDC completed an automatic trust scan operation for all trusts with no errors.

More information can be found at https://go.microsoft.com/fwlink/?linkid=2162089.

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "{199FE037-2B82-40A9-82AC-E1D46C792B99}",
    "event_source_name": "",
    "event_id": 6148,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T23:47:51.1974213+00:00",
    "event_record_id": 6878,
    "correlation": {},
    "execution": {
      "process_id": 812,
      "thread_id": 5768
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The PDC completed an automatic trust scan operation for all trusts with no errors.\r\n\r\nMore information can be found at https://go.microsoft.com/fwlink/?linkid=2162089."
}

Event ID 6149: The PDC completed an automatic trust scan operation for all trusts and encountered at least one error.

#
Provider
LsaSrv
Channel
System

Description

The PDC completed an automatic trust scan operation for all trusts and encountered at least one error.

Message #

The PDC completed an automatic trust scan operation for all trusts and encountered at least one error.

More information can be found at https://go.microsoft.com/fwlink/?linkid=2162089.

Event ID 6150: The PDC completed an administrator-requested trust scan operation for the trust 'TrustName' with no errors.

#
Provider
LsaSrv
Channel
System

Description

The PDC completed an administrator-requested trust scan operation for the trust 'TrustName' with no errors.

Message #

The PDC completed an administrator-requested trust scan operation for the trust '%1' with no errors.

More information can be found at https://go.microsoft.com/fwlink/?linkid=2162089.

Fields #

NameDescription
TrustName UnicodeString

Event ID 6151: The PDC was unable to find the specified trust 'TrustName' to scan.

#
Provider
LsaSrv
Channel
System

Description

The PDC was unable to find the specified trust 'TrustName' to scan. The trust either does not exist or it is neither an inbound or bidirectional trust.

Message #

The PDC was unable to find the specified trust '%1' to scan. The trust either does not exist or it is neither an inbound or bidirectional trust.

More information can be found at https://go.microsoft.com/fwlink/?linkid=2162089.

Fields #

NameDescription
TrustName UnicodeString

Event ID 6152: The PDC completed an administrator-requested trust scan operation for the trust 'TrustName' and encountered an error.

#
Provider
LsaSrv
Channel
System

Description

The PDC completed an administrator-requested trust scan operation for the trust 'TrustName' and encountered an error. More information can be found at https://go.microsoft.com/fwlink/?linkid=2162089.

Message #

The PDC completed an administrator-requested trust scan operation for the trust '%1' and encountered an error. The security of the local forest is unaffected by this error. The trusting forest may be at risk until the issue is resolved.

More information can be found at https://go.microsoft.com/fwlink/?linkid=2162089.

Fields #

NameDescription
TrustName UnicodeString

Event ID 6153: The PDC encountered an error trying to scan the named trust.

#
Provider
LsaSrv
Channel
System

Description

The PDC encountered an error trying to scan the named trust. The security of the local forest is unaffected by this error. The trusting forest may be at risk until the issue is resolved.

Message #

The PDC encountered an error trying to scan the named trust. The security of the local forest is unaffected by this error. The trusting forest may be at risk until the issue is resolved.

Trust: %1

Error: %2(%3)

More information can be found at https://go.microsoft.com/fwlink/?linkid=2162089.

Fields #

NameDescription
TrustName UnicodeString
ErrorCodeHex HexInt32
ErrorCode UInt32

Event ID 6154: Possible use of roaming Credential Manager credentials with Credential Guard detected.

#
Provider
LsaSrv
Channel
System

Description

Possible use of roaming Credential Manager credentials with Credential Guard detected. This feature is unsupported. Refer to Credential Guard documentation for more details.

Message #

Possible use of roaming Credential Manager credentials with Credential Guard detected. This feature is unsupported. Refer to Credential Guard documentation for more details.

Event ID 6155: LSA package is not signed as expected.

#
Provider
LsaSrv
Channel
System
Level
Warning

Description

LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.

Message #

LSA package is not signed as expected. This can cause unexpected behavior with Credential Guard.

PackageName: %1

Fields #

NameDescription
PackageName UnicodeString

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "199FE037-2B82-40A9-82AC-E1D46C792B99",
    "event_source_name": "",
    "event_id": 6155,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-06T06:25:27.966390+00:00",
    "event_record_id": 1665,
    "correlation": {
      "ActivityID": "F590C418-1079-0001-5BC5-90F57910DA01"
    },
    "execution": {
      "process_id": 808,
      "thread_id": 812
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PackageName": "msv1_0"
  },
  "message": ""
}

References #

Event ID 6156: Credential Guard auto enablement status.

#
Provider
LsaSrv
Channel
System
Level
Informational

Description

Credential Guard auto enablement status.

Message #

Credential Guard auto enablement status.

Hardware Requirements for Virtualization Based Security: %1
Domain Joined: %2
Azure AD Joined: %3
 Licensed for Credential Guard: %4
Domain Controller: %5

Fields #

NameDescription
HardwareChecks UInt32Hardware Requirements.
ADDomainJoin UInt32Domain Joined.
AADDomainJoin UInt32Azure AD Joined.
IsLicensed
DomainController

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "{199FE037-2B82-40A9-82AC-E1D46C792B99}",
    "event_source_name": "",
    "event_id": 6156,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T13:53:47.1899515+00:00",
    "event_record_id": 2663,
    "correlation": {},
    "execution": {
      "process_id": 968,
      "thread_id": 972
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "HardwareChecks": "1",
    "ADDomainJoin": "1",
    "AADDomainJoin": "0",
    "IsLicensed": "1",
    "DomainController": "0"
  },
  "message": "Credential Guard auto enablement status.\r\n\r\nHardware Requirements for Virtualization Based Security:\t1\r\nDomain Joined:\t1\r\nAzure AD Joined:\t0\r\n Licensed for Credential Guard:\t1\r\nDomain Controller:\t0"
}

Event ID 6157: The PDC completed a background trust scan operation of the named trust.

#
Provider
LsaSrv
Channel
System

Description

The PDC completed a background trust scan operation of the named trust.

Message #

The PDC completed a background trust scan operation of the named trust.

Trust: %1

More information can be found at https://go.microsoft.com/fwlink/?linkid=2162089.

Fields #

NameDescription
TrustName UnicodeString

Event ID 6158: Error reading Credential Guard.

#
Provider
LsaSrv
Channel
System

Description

Error reading Credential Guard (LsaIso.exe) UEFI configuration: Status.

Message #

Error reading Credential Guard (LsaIso.exe) UEFI configuration: %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 6160: LsaIso.

#
Provider
LsaSrv
Channel
System

Description

LsaIso.exe, the host process for Credential Guard and Key Guard, failed to launch: Status.

Message #

LsaIso.exe, the host process for Credential Guard and Key Guard, failed to launch: %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 6161: Credential Guard configuration: Config, IsTestConfig, AutoEnabled.

#
Provider
LsaSrv
Channel
System

Description

Credential Guard configuration: Config, IsTestConfig, AutoEnabled.

Message #

Credential Guard configuration: %1, %2, %3

Fields #

NameDescription
Config UInt32
IsTestConfig UInt32
AutoEnabled UInt32

Event ID 6162: Key Guard was started and will protect VSM-isolated keys.

#
Provider
LsaSrv
Channel
System

Description

Key Guard was started and will protect VSM-isolated keys.

Message #

Key Guard was started and will protect VSM-isolated keys.

Event ID 6163: Credential Guard was started and will protect LSA credentials.

#
Provider
LsaSrv
Channel
System

Description

Credential Guard was started and will protect LSA credentials.

Message #

Credential Guard was started and will protect LSA credentials.

Event ID 6164: Credential Guard is configured but the secure kernel is not running; continuing without Credential Guard.

#
Provider
LsaSrv
Channel
System

Description

Credential Guard is configured but the secure kernel is not running; continuing without Credential Guard.

Message #

Credential Guard is configured but the secure kernel is not running; continuing without Credential Guard.

Event ID 6165: VBS bound machine secret is present but falling back to LSA bound secret.

#
Provider
LsaSrv
Channel
System

Description

VBS bound machine secret is present but falling back to LSA bound secret.

Message #

VBS bound machine secret is present but falling back to LSA bound secret.
Credential Guard running status: %1
VBS bound secret validity: %2

Fields #

NameDescription
CredGuardRunning UInt32
IsPasswordValid UInt32

Event ID 6166: Machine Identity Isolation status.

#
Provider
LsaSrv
Channel
System

Description

Machine Identity Isolation status.

Message #

Machine Identity Isolation status:
Credential Guard running: %1
Group Policy: %2
Machine secret source: %3
VBS bound secret validity: %4

Fields #

NameDescription
CredGuardRunning UInt32
GroupPolicyStatus UInt32
MachinePasswordSource UInt32
MachinePasswordValidity UInt32
MachineCertificatePresent UInt32

Event ID 6167: There is a partial mismatch in the machine ID.

#
Provider
LsaSrv
Channel
System

Description

There is a partial mismatch in the machine ID. This indicates that the ticket has either been manipulated or it belongs to a different boot session. Failing authentication.

Message #

There is a partial mismatch in the machine ID. This indicates that the ticket has either been manipulated or it belongs to a different boot session. Failing authentication.

Event ID 6167: There is a partial mismatch in the machine ID

#
Provider
LsaSrv
Channel
Unknown

Description

There is a partial mismatch in the machine ID. This indicates that the ticket has either been manipulated or it belongs to a different boot session. Failing authentication.

Event ID 6182: LogonSession alive after interactive user logoff.

#
Provider
LsaSrv
Channel
Diagnostic

Description

LogonSession alive after interactive user logoff. Indicates a possible token leak in one of the services.

Message #

LogonSession alive after interactive user logoff. Indicates a possible token leak in one of the services. 
Logon ID:%1
Account Name:%2
Domain Name:%3

Fields #

NameDescription
TargetLogonId HexInt64Logon session identifier (LUID) for the target.
AccountName UnicodeString
DomainName UnicodeString

Event ID 6225: CATEGORY_LSA_LOGON

#
Provider
LsaSrv
Channel
Performance
Level
Informational
Task
LSALogon
Opcode
Start

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "{199FE037-2B82-40A9-82AC-E1D46C792B99}",
    "event_source_name": "",
    "event_id": 6225,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": "0x4000000000000000",
    "time_created": "2026-06-02T05:18:30.747+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1A90F6D3-7DD5-4248-8637-2C16285553BB}"
    },
    "execution": {
      "process_id": 1132,
      "thread_id": 20716
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "CATEGORY_LSA_LOGON"
}

Event ID 6226: CATEGORY_LSA_LOGON

#
Provider
LsaSrv
Channel
Performance
Level
Informational
Task
LSALogon
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "{199FE037-2B82-40A9-82AC-E1D46C792B99}",
    "event_source_name": "",
    "event_id": 6226,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 2,
    "keywords": "0x4000000000000000",
    "time_created": "2026-06-02T05:18:30.748+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1A90F6D3-7DD5-4248-8637-2C16285553BB}"
    },
    "execution": {
      "process_id": 1132,
      "thread_id": 20716
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "CATEGORY_LSA_LOGON"
}

Event ID 6227: LSASID_NameLookupStart

#
Provider
LsaSrv
Channel
Performance
Task
LSASID_NameLookup
Opcode
Start

Event ID 6228: LSASID_NameLookupStop

#
Provider
LsaSrv
Channel
Performance
Task
LSASID_NameLookup
Opcode
Stop

Event ID 6229: LSASID_NameLookupStart6229

#
Provider
LsaSrv
Channel
Performance
Task
LSASID_NameLookup
Opcode
Start

Event ID 6230: LSASID_NameLookupStop6230

#
Provider
LsaSrv
Channel
Performance
Task
LSASID_NameLookup
Opcode
Stop

Event ID 6231: SecurityPackageManagerStart

#
Provider
LsaSrv
Channel
Performance
Task
SecurityPackageManager
Opcode
Start

Event ID 6232: SecurityPackageManagerStop

#
Provider
LsaSrv
Channel
Performance
Task
SecurityPackageManager
Opcode
Stop

Event ID 29186: Moving the existing logon scripts from {OldScripts} to {NewScripts} failed.

#
Provider
LsaSrv
Channel
System

Description

Moving the existing logon scripts from {OldScripts} to {NewScripts} failed. The return code is the data.

Message #

Moving the existing logon scripts from {OldScripts} to {NewScripts} failed.  The return code is the data.

Fields #

NameDescription
OldScripts
NewScripts

Event ID 29187: Running the Security Configuration Editor over the Domain Controller encountered a non-fatal error.

#
Provider
LsaSrv
Channel
System

Description

Running the Security Configuration Editor over the Domain Controller encountered a non-fatal error. Further details can be obtained by examining the log file {Logfile}. The return code is the data.

Message #

Running the Security Configuration Editor over the Domain Controller encountered a non-fatal error.  Further details can be obtained by examining the log file {Logfile}.  The return code is the data.

Fields #

NameDescription
Logfile

Event ID 29188: An existing; incompatible trust object was found on the parent server for domain {DomainName}.

#
Provider
LsaSrv
Channel
System

Description

An existing; incompatible trust object was found on the parent server for domain {DomainName}. It has been removed and replaced with an updated trust.

Message #

An existing; incompatible trust object was found on the parent server for domain {DomainName}.  It has been removed and replaced with an updated trust.

Fields #

NameDescription
DomainName

Event ID 29216: Failed to disable auto logon following the successful upgrade of a domain controller.

#
Provider
LsaSrv
Channel
System

Description

Failed to disable auto logon following the successful upgrade of a domain controller. Unable to delete registry key {Path}. The return code is the data.

Message #

Failed to disable auto logon following the successful upgrade of a domain controller.  Unable to delete registry key {Path}.  The return code is the data.

Fields #

NameDescription
Path

Event ID 29217: Failed to set the default logon domain to {DomainName}.

#
Provider
LsaSrv
Channel
System

Description

Failed to set the default logon domain to {DomainName}. The return code is the data.

Message #

Failed to set the default logon domain to {DomainName}.  The return code is the data.

Fields #

NameDescription
DomainName

Event ID 29221: During the demotion operation; the trust object on {ParentName} could not be removed.

#
Provider
LsaSrv
Channel
System

Description

During the demotion operation; the trust object on {ParentName} could not be removed.

Message #

During the demotion operation; the trust object on {ParentName} could not be removed.

Fields #

NameDescription
ParentName

Event ID 29241: Dcpromo failed to configure the new starttype of {Flags} for the service {ServiceName} during forced demotion.

#
Provider
LsaSrv
Channel
System

Description

Dcpromo failed to configure the new starttype of {Flags} for the service {ServiceName} during forced demotion.

Message #

Dcpromo failed to configure the new starttype of {Flags} for the service {ServiceName} during forced demotion.

Fields #

NameDescription
Flags
ServiceName

Event ID 29242: Dcpromo failed to remove the dependency of {ServiceName} on {Dependency} during forced demotion.

#
Provider
LsaSrv
Channel
System

Description

Dcpromo failed to remove the dependency of {ServiceName} on {Dependency} during forced demotion.

Message #

Dcpromo failed to remove the dependency of {ServiceName} on {Dependency} during forced demotion.

Fields #

NameDescription
ServiceName
Dependency

Event ID 32768: The interdomain trust account for the domain {Domain} could not be deleted.

#
Provider
LsaSrv
Channel
System

Description

The interdomain trust account for the domain {Domain} could not be deleted. The return code is the data.

Message #

The interdomain trust account for the domain {Domain} could not be deleted. The return code is the data.

Fields #

NameDescription
Domain

Event ID 32772: The interdomain trust account for the domain {Domain} could not be created.

#
Provider
LsaSrv
Channel
System

Description

The interdomain trust account for the domain {Domain} could not be created. The return code is the data.

Message #

The interdomain trust account for the domain {Domain} could not be created. The return code is the data.

Fields #

NameDescription
Domain

Event ID 32773: A lookup request was made that required connectivity to a domain controller in domain Domain.

#
Provider
LsaSrv
Channel
System

Description

A lookup request was made that required connectivity to a domain controller in domain Domain. The LSA was unable to find a domain controller in the domain and thus failed the request. Please check connectivity and secure channel setup from this domain controller to the domain TargetDomain.

Message #

A lookup request was made that required connectivity to a domain controller in domain %1. The LSA was unable to find a domain controller in the domain and thus failed the request. Please check connectivity and secure channel setup from this domain controller to the domain %2.

Fields #

NameDescription
Domain UnicodeString
TargetDomain UnicodeString
__binLength UInt32
status BinaryNTSTATUS reference

Event ID 32774: A lookup request was made that required connectivity to the domain controller Domain.

#
Provider
LsaSrv
Channel
System

Description

A lookup request was made that required connectivity to the domain controller Domain. The local LSA was unable to contact the LSA on the remote domain controller. Please check connectivity and secure channel setup from this domain controller to the domain controller TargetDomain.

Message #

A lookup request was made that required connectivity to the domain controller %1. The local LSA was unable to contact the LSA on the remote domain controller. Please check connectivity and secure channel setup from this domain controller to the domain controller %2.

Fields #

NameDescription
Domain UnicodeString
TargetDomain UnicodeString
__binLength UInt32
status BinaryNTSTATUS reference

Event ID 32775: A lookup request was made that required the lookup services on the remote domain controller Domain.

#
Provider
LsaSrv
Channel
System

Description

A lookup request was made that required the lookup services on the remote domain controller Domain. The remote domain controller failed the request thus the local LSA failed the original lookup request. Please check connectivity and secure channel setup from this domain controller to the domain controller TargetDomain.

Message #

A lookup request was made that required the lookup services on the remote domain controller %1. The remote domain controller failed the request thus the local LSA failed the original lookup request. Please check connectivity and secure channel setup from this domain controller to the domain controller %2.

Fields #

NameDescription
Domain UnicodeString
TargetDomain UnicodeString
__binLength UInt32
status BinaryNTSTATUS reference

Event ID 32777: The LSA was unable to register its RPC interface over the TCP/IP interface.

#
Provider
LsaSrv
Channel
System

Description

The LSA was unable to register its RPC interface over the TCP/IP interface. Please make sure that the protocol is properly installed.

Message #

The LSA was unable to register its RPC interface over the TCP/IP interface. Please make sure that the protocol is properly installed.

Event ID 32778: The name {Name} was translated to SID {SID} from the trusted forest {Forest}.

#
Provider
LsaSrv
Channel
System

Message #

The name {Name} was translated to SID {SID} from the trusted forest {Forest}. The domain portion of the SID is not in the list of acceptable SID's found on the trusted domain object; thus this name to SID translation has been ignored.

Fields #

NameDescription
Name
SID
Forest

Event ID 32779: task_032779

#
Provider
LsaSrv
Channel
Application

Fields #

NameDescription
SubCategoryGuid

Event ID 32779: task_032779

#
Provider
LsaSrv
Channel
Unknown

Fields #

NameDescription
SubCategoryGuid GUID

Event ID 32780: The LSA was unable to notify UBPM during startup with status Status.

#
Provider
LsaSrv
Channel
System

Description

The LSA was unable to notify UBPM during startup with status Status.

Message #

The LSA was unable to notify UBPM during startup with status %1.

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 40960: The Security System detected an authentication error for the server Target.

#
Provider
LsaSrv
Channel
System

Description

The Security System detected an authentication error for the server Target. The failure code from authentication protocol Protocol was Error.

Message #

The Security System detected an authentication error for the server %1. The failure code from authentication protocol %2 was %3.

Fields #

NameDescription
Target UnicodeString
Protocol UnicodeString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
Error UnicodeString

Event ID 40961: The Security System could not establish a secured connection with the server Target.

#
Provider
LsaSrv
Channel
System

Description

The Security System could not establish a secured connection with the server Target. No authentication protocol was available.

Message #

The Security System could not establish a secured connection with the server %1. No authentication protocol was available.

Fields #

NameDescription
Target UnicodeString

Event ID 40962: The Security System was unable to authenticate to the server Target because the server has completed the authentication, but the client authentication ...

#
Provider
LsaSrv
Channel
System

Description

The Security System was unable to authenticate to the server Target because the server has completed the authentication, but the client authentication protocol Protocol has not.

Message #

The Security System was unable to authenticate to the server %1 because the server has completed the authentication, but the client authentication protocol %2 has not.

Fields #

NameDescription
Target UnicodeString
Protocol UnicodeString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP

Event ID 40964: The Security System received an authentication attempt with an unknown authentication protocol.

#
Provider
LsaSrv
Channel
System

Description

The Security System received an authentication attempt with an unknown authentication protocol. The request has failed.

Message #

The Security System received an authentication attempt with an unknown authentication protocol. The request has failed.

Event ID 40965: The Security System has selected Protocol for the authentication protocol to server Target.

#
Provider
LsaSrv
Channel
System

Description

The Security System has selected Protocol for the authentication protocol to server Target.

Message #

The Security System has selected %2 for the authentication protocol to server %1.

Fields #

NameDescription
Target UnicodeString
Protocol UnicodeString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP

Event ID 40966: The Security System has received an authentication attempt, and determined that the protocol Protocol preferred by the client is acceptable.

#
Provider
LsaSrv
Channel
System

Description

The Security System has received an authentication attempt, and determined that the protocol Protocol preferred by the client is acceptable.

Message #

The Security System has received an authentication attempt, and determined that the protocol %1 preferred by the client is acceptable.

Fields #

NameDescription
Protocol UnicodeString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP

Event ID 40967: The Security System has received an authentication request directly for authentication protocol Protocol.

#
Provider
LsaSrv
Channel
System

Description

The Security System has received an authentication request directly for authentication protocol Protocol.

Message #

The Security System has received an authentication request directly for authentication protocol %1.

Fields #

NameDescription
Protocol UnicodeString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP

Event ID 40968: The Security System has received an authentication request that could not be decoded.

#
Provider
LsaSrv
Channel
System

Description

The Security System has received an authentication request that could not be decoded. The request has failed.

Message #

The Security System has received an authentication request that could not be decoded. The request has failed.

Event ID 40969: The Security System has received an authentication attempt, and determined that the protocol Protocol is the common protocol.

#
Provider
LsaSrv
Channel
System

Description

The Security System has received an authentication attempt, and determined that the protocol Protocol is the common protocol.

Message #

The Security System has received an authentication attempt, and determined that the protocol %1 is the common protocol.

Fields #

NameDescription
Protocol UnicodeString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP

Event ID 40970: The Security System has detected a downgrade attempt when contacting the 3-part SPN.

#
Provider
LsaSrv
Channel
System
Level
Warning

Description

The Security System has detected a downgrade attempt when contacting the 3-part SPN.

Message #

The Security System has detected a downgrade attempt when contacting the 3-part SPN 



 %1 



 with error code %2. Authentication was denied.

Fields #

NameDescription
Target UnicodeString
Error UnicodeString

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "199FE037-2B82-40A9-82AC-E1D46C792B99",
    "event_source_name": "",
    "event_id": 40970,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T23:06:30.699004+00:00",
    "event_record_id": 12309,
    "correlation": {},
    "execution": {
      "process_id": 936,
      "thread_id": 11176
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Target": "ldap/LAB-DC01.ludus.domain/ludus.domain@LUDUS.DOMAIN",
    "Error": "\"The attempted logon is invalid. This is either due to a bad username or authentication information.\r\n (0xc000006d)\""
  },
  "message": ""
}

Event ID 40971: The Security System is auditing a downgrade attempt when contacting the 3-part SPN

#
Provider
LsaSrv
Channel
Application

Description

The Security System is auditing a downgrade attempt when contacting the 3-part SPN

Message #

The Security System is auditing a downgrade attempt when contacting the 3-part SPN ____ %1 ____ with error code %2.

Fields #

NameDescription
Target UnicodeString
Error UnicodeString

Event ID 45056: Logon cache was disabled.

#
Provider
LsaSrv
Channel
System

Description

Logon cache was disabled. Intermittent authentication failures may result during periods of network latency or interrupts. Please contact your system administrator.

Message #

Logon cache was disabled. Intermittent authentication failures may result during periods of network latency or interrupts. Please contact your system administrator.

Event ID 45057: A failed logon attempt has caused a logon cache entry for user Username to be deleted.

#
Provider
LsaSrv
Channel
System
Level
Informational

Description

A failed logon attempt has caused a logon cache entry for user Username to be deleted. The authentication package was Package, and the error message was Error.

Message #

A failed logon attempt has caused a logon cache entry for user %1 to be deleted. The authentication package was %2, and the error message was %3.

Fields #

NameDescription
Data_0
Data_1
Data_2
Username UnicodeString
Package UnicodeString
Error UnicodeString

Example Event #

{
  "system": {
    "provider": "LsaSrv",
    "guid": "{199FE037-2B82-40A9-82AC-E1D46C792B99}",
    "event_source_name": "",
    "event_id": 45057,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-18T18:46:23.9415145+00:00",
    "event_record_id": 3127,
    "correlation": {},
    "execution": {
      "process_id": 1076,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "domainuser@LUDUS.DOMAIN",
    "Data_1": "Kerberos",
    "Data_2": "\"The referenced account is currently disabled and may not be logged on to.\n (0xc0000072)\""
  },
  "message": "A failed logon attempt has caused a logon cache entry for user domainuser@LUDUS.DOMAIN to be deleted. The authentication package was Kerberos, and the error message was \"The referenced account is currently disabled and may not be logged on to.\r\n (0xc0000072)\"."
}

Event ID 45058: A logon cache entry for user UserName was the oldest entry and was removed.

#
Provider
LsaSrv
Channel
System

Description

A logon cache entry for user UserName was the oldest entry and was removed. The timestamp of this entry was TimeStamp.

Message #

A logon cache entry for user %1 was the oldest entry and was removed. The timestamp of this entry was %2.

Fields #

NameDescription
UserName UnicodeString
TimeStamp SYSTEMTIME

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {199FE037-2B82-40A9-82AC-E1D46C792B99}

Defined in lsasrv.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.3804, captured 2026-06-02
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3804, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads