Microsoft-Windows-AAD

204 events across 2 channels

EventTitleChannelSample
1001AadCloudAPPlugin Initialize StartAnalyticN
1002AadCloudAPPlugin Initialize Stop.AnalyticN
1003AadCloudAPPlugin Uninitialize StartAnalyticN
1004AadCloudAPPlugin ValidateUserInfo StartAnalyticN
1005AadCloudAPPlugin ValidateUserInfo Stop.AnalyticN
1006AadCloudAPPlugin GetToken StartAnalyticN
1007AadCloudAPPlugin GetToken Stop.AnalyticN
1008AadCloudAPPlugin GetKeys StartAnalyticN
1009AadCloudAPPlugin GetKeys Stop.AnalyticN
1010AadCloudAPPlugin GetUnlockKey StartAnalyticN
1011AadCloudAPPlugin GetUnlockKey Stop.AnalyticN
1012AadCloudAPPlugin PersistSSOTokens StartAnalyticN
1013AadCloudAPPlugin PersistSSOTokens Stop.AnalyticN
1015AadCloudAPPlugin Realm discovery response: …AnalyticN
1016AadCloudAPPlugin device is cloud domain joinedAnalyticN
1017AadCloudAPPlugin device is domain joinedAnalyticN
1018AadCloudAPPlugin GetToken Correlation ID: …AnalyticN
1019AadCloudAPPlugin GetKeys Correlation ID: …AnalyticN
1020AadCloudAPPlugin loaded as surrogateAnalyticN
1021AadCloudAPPlugin MEX request status: AadCloudAPPlugin_MEX_request_status.AnalyticN
1022Endpoint Uri: Endpoint_Uri.AnalyticN
1023NGC UserID Key: NGC_UserID_Key.AnalyticN
1024Http request status: Http_request_status.OperationalN
1025Http request status: Http_request_status.OperationalN
1026Credential type: Credential_type Correlation ID: Correlation_ID.AnalyticN
1027AadCloudAPPlugin managed logon flow for federated NGC user.AnalyticN
1028AadCloudAPPlugin RefreshToken StartAnalyticN
1029AadCloudAPPlugin RefreshToken Stop.AnalyticN
1030AadCloudAPPlugin RefreshToken Correlation ID: …AnalyticN
1031AadCloudAPPlugin encrypted OAuth response receivedAnalyticN
1032Number of groups received: value.AnalyticN
1033Validation needed: Validation_needed.AnalyticN
1034AadCloudAPPlugin GenericCallPkg StartAnalyticN
1035AadCloudAPPlugin GenericCallPkg Stop.AnalyticN
1081OAuth response error: OAuth_response_error.OperationalN
1082Key error: Key_error.OperationalN
1083Protected key error: Protected_key_error.OperationalN
1084Http transport error.OperationalN
1085Logon failure.OperationalN
1086Get user realm failure.OperationalN
1087Get credential keys failure.OperationalN
1088WSTrust response error: WSTrust_response_error.OperationalN
1089Device is not cloud domain joined: Status.OperationalN
1090NGC nonce response error: NGC_nonce_response_error.OperationalN
1091NGC auth ticket is not defined.OperationalN
1092OAuth request retry.OperationalN
1093NGC call API returned error: Result.OperationalN
1094Refresh token failure.OperationalN
1095Refresh token user SIDs don't match.OperationalN
1096Refresh token is expired.OperationalN
1097Error: Error ErrorMessage AdditionalInformation.OperationalY
1098Error: Error ErrorMessage AdditionalInformation.OperationalY
1099Code: Code OperationCode OperationMessage.AnalyticN
1100Error: Error ErrorMessage AdditionalInformation.OperationalN
1101Error: Error ErrorMessage AdditionalInformation.OperationalN
1102Code: Code OperationCode OperationMessage.AnalyticN
1103Can't decrypt OAuth response.OperationalN
1104AAD Cloud AP plugin call API returned error: Result.OperationalY
1105Device registration API call API returned error: Result.OperationalN
1106Number of security groups received value.OperationalN
1107Error: Error ErrorMessage AdditionalInformation.AnalyticN
1108Error: Error ErrorMessage AdditionalInformation.AnalyticN
1109Error: Error ErrorMessage AdditionalInformation.AnalyticN
1110Error: Error ErrorMessage AdditionalInformation.AnalyticN
1111Error: Error ErrorMessage AdditionalInformation.OperationalN
1112Error: Error ErrorMessage AdditionalInformation.OperationalN
1113Code: Code OperationCode OperationMessage.AnalyticN
1114Error: Error ErrorMessage AdditionalInformation.AnalyticN
1115Error: Error ErrorMessage AdditionalInformation.AnalyticN
1116Get Enterprise STS OAuth Info failure.OperationalN
1117Enterprise STS Refresh token failure.OperationalN
1118Enterprise STS Logon failure.OperationalN
1119Enterprise STS OAuth Info response: Enterprise_STS_OAuth_Info_response.AnalyticN
1120Enterprise STS Refresh token is expired.OperationalN
1121Enterprise STS RefreshToken Correlation ID: value.AnalyticN
1122Refresh token subject don't match.OperationalN
1123AadCloudAPPlugin smart card logon for non-federated user.OperationalN
1124Device is DRS joined but Enterprise STS is disabled: Status.OperationalN
1125AadCloudAPPlugin loaded as surrogate, no key recoveryAnalyticN
1126AadCloudAPPlugin device is Enterprise joinedAnalyticN
1127AadCloudAPPlugin device P2P certificate update thread startedAnalyticN
1128AadCloudAPPlugin device P2P certificate update thread stoppedAnalyticN
1129AadCloudAPPlugin Uninitialize StopAnalyticN
1130AadCloudAPPlugin DeviceP2PCertificateUpdate Correlation ID: …AnalyticN
1131Update P2P device certificate failure.OperationalN
1132AadCloudAPPlugin GetCertificateFromCred Correlation ID: …AnalyticN
1133Update P2P user certificate failure.OperationalN
1134AAD Cloud AP plugin call API returned error: Result.AnalyticN
1135AadCloudAPPlugin RenewCertificate Correlation ID: …AnalyticN
1136AadCloudAPPlugin AcceptPeerCertificate StartAnalyticN
1137AadCloudAPPlugin AcceptPeerCertificate Stop.AnalyticN
1138AadCloudAPPlugin RenewCertificate StartAnalyticN
1139AadCloudAPPlugin RenewCertificate Stop.AnalyticN
1140AadCloudAPPlugin GetCertificateFromCred StartAnalyticN
1141AadCloudAPPlugin GetCertificateFromCred Stop.AnalyticN
1142Get token user names don't match.OperationalN
1143Generic Call Package call type: Generic_Call_Packate_call_type.AnalyticN
1144Realm discovery for: Method authority: EndpointUri fallback domain hint: …AnalyticN
1145AAD Cloud AP plugin token needs refresh reason: value.AnalyticN
1146Token is not refreshed.AnalyticN
1147AadCloudAPPlugin AssembleOpaqueData StartAnalyticN
1148AadCloudAPPlugin AssembleOpaqueData Stop.AnalyticN
1149AadCloudAPPlugin DisassembleOpaqueData StartAnalyticN
1150AadCloudAPPlugin DisassembleOpaqueData Stop.AnalyticN
1151AadCloudAPPlugin P2P device certificate update error: Status.OperationalN
1152AadCloudAPPlugin device certificate key error: Result.OperationalN
1153AadCloudAPPlugin device certificate not available for logon: value.OperationalN
1154Password expiration claims.AnalyticN
1155Logon with session key failure.OperationalN
1156Password expiration fields.AnalyticN
1157AadCloudAPPlugin PostLogonProcessing StartAnalyticN
1158AadCloudAPPlugin PostLogonProcessing Stop.AnalyticN
1159AadCloudAPPlugin S4U logon failed.OperationalN
1160Logon failure.OperationalN
1161Logon failure.OperationalN
1162Logon failure.OperationalN
1163Logon failure.OperationalN
1164Logon failure.OperationalN
1165Logon failure.OperationalN
1200BrowserCore operation startedAnalyticN
1201BrowserCore operation completed successfullyAnalyticN
1202BrowserCore operation completed with a failure.OperationalN
1203BrowserCore inner operation FunctionName completed with error: Result.OperationalN
1204AadCloudAPPlugin LookupSIDFromIdentityName StartAnalyticN
1205AadCloudAPPlugin LookupSIDFromIdentityName Stop.AnalyticN
1206AadCloudAPPlugin LookupIdentityFromSIDName StartAnalyticN
1207AadCloudAPPlugin LookupIdentityFromSIDName Stop.AnalyticN
1208AadCloudAPPlugin LookupSIDFromIdentity Identity: …AnalyticN
1209AadCloudAPPlugin LookupIdentityFromSID SID: …AnalyticN
1210AadCloudAPPlugin password expired, password change URI: value.OperationalN
1211Writing RunRecovery registry value failed.OperationalN
1212Enterprise logon.OperationalN
1213WamExtension process token operation startedAnalyticN
1214WamExtension process token operation completed successfullyAnalyticN
1215WamExtension process token operation completed with error: Data.OperationalY
1216WamExtension device authentication call status: Result Correlation ID: Target.AnalyticN
1217Get device token.AnalyticN
1218StartFidoAuthenticationSession startAnalyticN
1219StartFidoAuthenticationSession stop.AnalyticN
1220CloseFidoAuthenticationSession startAnalyticN
1221CloseFidoAuthenticationSession stop.AnalyticN
1222GetClientData startAnalyticN
1223GetClientData stop.AnalyticN
1224SignClientDataFido startAnalyticN
1225SignClientDataFido stop.AnalyticN
1226ChangePin startAnalyticN
1227ChangePin stop.AnalyticN
1228GetSerializedAuthBuffer startAnalyticN
1229GetSerializedAuthBuffer stop.AnalyticN
1230AuthHelper call API returned error: Result.OperationalN
1231AadCloudAPPlugin Resource infomation: AadCloudAPPlugin_Resource_infomation.AnalyticN
1232AadCloudAPPlugin RBAC authorization code response: Response.AnalyticN
1233AadCloudAPPlugin User access control role: value.AnalyticN
1234AadCloudAPPlugin using resource id from the Idtoken: value.AnalyticN
1235RBAC Status: RBAC_Status Correlation ID: Correlation_ID.AnalyticN
1236Failed to create the resource idAnalyticN
1237Device is configured for RBAC authorizationOperationalN
1238Not sending the client certificate as it is optional on the serverAnalyticN
1239Doing RBAC logon of the device type: value.AnalyticN
1240Skipping Rbac Logon because AadCloudAPPlugin is loaded as surrogateAnalyticN
1241On-prem tgt error: Onprem_tgt_error.OperationalN
1242Added user to admins security groupAnalyticN
1243Removed user from admins security groupAnalyticN
1244Security groups were not loaded.OperationalN
1245Security groups were not updated.OperationalN
1246User sid: User_sid Group sids: Group_sids.AnalyticN
1247RunRecovery registry value (Context) successfully written.OperationalN
1248AuthHelper auth buff local nonceOperationalN
1249Cloud tgt error: Cloud_tgt_error.OperationalN
1250DoGetToken Diagnostic Event.OperationalN
1251DoGetEnterpriseToken Diagnostic Event.OperationalN
1252DoRefreshToken Diagnostic Event.OperationalN
1253DoRefreshEnterpriseToken Diagnostic Event.OperationalN
1254Response content type: Response_content_type.AnalyticN
1255AD TGT: AD_TGT Cloud TGT: Cloud_TGT.AnalyticN
1256P2P certificate update error.OperationalN
1257Credbuffer correlation ID: Credbuffer_correlation_ID Correlation ID: …AnalyticN
1258CA cert hash (keyID): CA_cert_hash_keyID Correlation ID: Correlation_ID.AnalyticN
1259CA certificate update error.OperationalN
1260RetryGetClientData startAnalyticN
1261RetryGetClientData stop.AnalyticN
1262Binding key tag check failed: Binding_key_tag_check_failed.OperationalN
1263BrowserCore inner operation FunctionName with account pairwiseID PairwiseID not …OperationalN
1264Token binding key created.AnalyticN
1265WamExtension preprocess token operation started.AnalyticN
1266WamExtension preprocess token operation completed successfullyAnalyticN
1267WamExtension preprocess token operation completed with error: Result.OperationalN
1268WamExtension postprocess token operation started.AnalyticN
1269WamExtension postprocess token operation completed successfully.AnalyticN
1270WamExtension postprocess token operation completed with error: Result.OperationalN
1271Token binding claim(s) included in the request.AnalyticN
1272Token binding key is not healthy and needs to be re-created.AnalyticN
1273Token binding claims need to be re-generated due to changes in attestation …AnalyticN
1274Token binding claims generated.AnalyticN
1275Token binding claims generated for UI request.AnalyticN
1276Token binding claims count: ClaimsCount.AnalyticN
1277KeyGuard availability detection failed.OperationalN
1278KeyGuard with attestation support is not detected.OperationalN
1279Token binding claims of type KeyType could not be generated because AIK does not …AnalyticN
1280PRT session key needs to be rolled.OperationalN
1281Token binding key deleted.AnalyticN
1282SHR property in request is not allowed.OperationalN
1283Invalid registry value was ignored.AnalyticN
1284Token binding claims need to be re-generated as cached claims were generated for …AnalyticN

Event ID 1001: AadCloudAPPlugin Initialize Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin Initialize Start.

Message #

AadCloudAPPlugin Initialize Start

Event ID 1002: AadCloudAPPlugin Initialize Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin Initialize Stop.

Message #

AadCloudAPPlugin Initialize Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1003: AadCloudAPPlugin Uninitialize Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin Uninitialize Start.

Message #

AadCloudAPPlugin Uninitialize Start

Event ID 1004: AadCloudAPPlugin ValidateUserInfo Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin ValidateUserInfo Start.

Message #

AadCloudAPPlugin ValidateUserInfo Start

Event ID 1005: AadCloudAPPlugin ValidateUserInfo Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin ValidateUserInfo Stop.

Message #

AadCloudAPPlugin ValidateUserInfo Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1006: AadCloudAPPlugin GetToken Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin GetToken Start.

Message #

AadCloudAPPlugin GetToken Start

Event ID 1007: AadCloudAPPlugin GetToken Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin GetToken Stop.

Message #

AadCloudAPPlugin GetToken Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1008: AadCloudAPPlugin GetKeys Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin GetKeys Start.

Message #

AadCloudAPPlugin GetKeys Start

Event ID 1009: AadCloudAPPlugin GetKeys Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin GetKeys Stop.

Message #

AadCloudAPPlugin GetKeys Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1010: AadCloudAPPlugin GetUnlockKey Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin GetUnlockKey Start.

Message #

AadCloudAPPlugin GetUnlockKey Start

Event ID 1011: AadCloudAPPlugin GetUnlockKey Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin GetUnlockKey Stop.

Message #

AadCloudAPPlugin GetUnlockKey Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1012: AadCloudAPPlugin PersistSSOTokens Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin PersistSSOTokens Start.

Message #

AadCloudAPPlugin PersistSSOTokens Start

Event ID 1013: AadCloudAPPlugin PersistSSOTokens Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin PersistSSOTokens Stop.

Message #

AadCloudAPPlugin PersistSSOTokens Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1015: AadCloudAPPlugin Realm discovery response: AadCloudAPPlugin_Realm_discovery_response.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin Realm discovery response: AadCloudAPPlugin_Realm_discovery_response.

Message #

AadCloudAPPlugin Realm discovery response: %1.
Request status: %2

Fields #

NameDescription
Response UnicodeString
Status Int32NTSTATUS reference

Event ID 1016: AadCloudAPPlugin device is cloud domain joined

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin device is cloud domain joined.

Message #

AadCloudAPPlugin device is cloud domain joined

Event ID 1017: AadCloudAPPlugin device is domain joined

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin device is domain joined.

Message #

AadCloudAPPlugin device is domain joined

Event ID 1018: AadCloudAPPlugin GetToken Correlation ID: AadCloudAPPlugin_GetToken_Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin GetToken Correlation ID: AadCloudAPPlugin_GetToken_Correlation_ID.

Message #

AadCloudAPPlugin GetToken Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1019: AadCloudAPPlugin GetKeys Correlation ID: AadCloudAPPlugin_GetKeys_Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin GetKeys Correlation ID: AadCloudAPPlugin_GetKeys_Correlation_ID.

Message #

AadCloudAPPlugin GetKeys Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1020: AadCloudAPPlugin loaded as surrogate

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin loaded as surrogate.

Message #

AadCloudAPPlugin loaded as surrogate

Event ID 1021: AadCloudAPPlugin MEX request status: AadCloudAPPlugin_MEX_request_status.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin MEX request status: AadCloudAPPlugin_MEX_request_status.

Message #

AadCloudAPPlugin MEX request status: %1

Fields #

NameDescription
Status Int32NTSTATUS reference

Event ID 1022: Endpoint Uri: Endpoint_Uri.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

Endpoint Uri: Endpoint_Uri.

Message #

Endpoint Uri: %1

Fields #

NameDescription
value UnicodeString

Event ID 1023: NGC UserID Key: NGC_UserID_Key.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

NGC UserID Key: NGC_UserID_Key.

Message #

NGC UserID Key: %1

Fields #

NameDescription
value UnicodeString

Event ID 1024: Http request status: Http_request_status.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Http request status: Http_request_status.

Message #

Http request status: %1

Fields #

NameDescription
value Int32

Event ID 1025: Http request status: Http_request_status.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Http request status: Http_request_status. Method: Method Endpoint Uri: Endpoint_Uri Correlation ID: Correlation_ID.

Message #

Http request status: %1. Method: %2 Endpoint Uri: %3 Correlation ID: %4

Fields #

NameDescription
value Int32
Method UnicodeString
EndpointUri UnicodeString
CorrelationID UnicodeString

Event ID 1026: Credential type: Credential_type Correlation ID: Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Credential type: Credential_type Correlation ID: Correlation_ID.

Message #

Credential type: %1 Correlation ID: %2

Fields #

NameDescription
value Int32
CorrelationID UnicodeString

Event ID 1027: AadCloudAPPlugin managed logon flow for federated NGC user.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin managed logon flow for federated NGC user.

Message #

AadCloudAPPlugin managed logon flow for federated NGC user.

Event ID 1028: AadCloudAPPlugin RefreshToken Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin RefreshToken Start.

Message #

AadCloudAPPlugin RefreshToken Start

Event ID 1029: AadCloudAPPlugin RefreshToken Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin RefreshToken Stop.

Message #

AadCloudAPPlugin RefreshToken Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1030: AadCloudAPPlugin RefreshToken Correlation ID: AadCloudAPPlugin_RefreshToken_Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin RefreshToken Correlation ID: AadCloudAPPlugin_RefreshToken_Correlation_ID.

Message #

AadCloudAPPlugin RefreshToken Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1031: AadCloudAPPlugin encrypted OAuth response received

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin encrypted OAuth response received.

Message #

AadCloudAPPlugin encrypted OAuth response received

Event ID 1032: Number of groups received: value.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Number of groups received: value.

Message #

Number of groups received: %1

Fields #

NameDescription
value Int32

Event ID 1033: Validation needed: Validation_needed.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Validation needed: Validation_needed.

Message #

Validation needed: %1

Fields #

NameDescription
value Int32

Event ID 1034: AadCloudAPPlugin GenericCallPkg Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin GenericCallPkg Start.

Message #

AadCloudAPPlugin GenericCallPkg Start

Event ID 1035: AadCloudAPPlugin GenericCallPkg Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin GenericCallPkg Stop.

Message #

AadCloudAPPlugin GenericCallPkg Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1081: OAuth response error: OAuth_response_error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

OAuth response error: OAuth_response_error.

Message #

OAuth response error: %1
Error description: %2
CorrelationID: %3

Fields #

NameDescription
Error UnicodeString
ErrorDescription UnicodeString
CorrelationID UnicodeString

Event ID 1082: Key error: Key_error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Key error: Key_error.

Message #

Key error: %1
Error description: %2
CorrelationID: %3

Fields #

NameDescription
Error UnicodeString
ErrorDescription UnicodeString
CorrelationID UnicodeString

Event ID 1083: Protected key error: Protected_key_error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Protected key error: Protected_key_error.

Message #

Protected key error: %1
Error description: %2
CorrelationID: %3

Fields #

NameDescription
Error UnicodeString
ErrorDescription UnicodeString
CorrelationID UnicodeString

References #

Event ID 1084: Http transport error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Http transport error. Status: Http_transport_error_Status Correlation ID: Correlation_ID.

Message #

Http transport error. Status: %1 Correlation ID: %2

Fields #

NameDescription
Result Int32
Target UnicodeString

References #

Event ID 1085: Logon failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Logon failure. Status: Logon_failure_Status Correlation ID: Correlation_ID.

Message #

Logon failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1086: Get user realm failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Get user realm failure. Status: Get_user_realm_failure_Status Correlation ID: Correlation_ID.

Message #

Get user realm failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1087: Get credential keys failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Get credential keys failure. Status: Get_credential_keys_failure_Status Correlation ID: Correlation_ID.

Message #

Get credential keys failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1088: WSTrust response error: WSTrust_response_error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

WSTrust response error: WSTrust_response_error.

Message #

WSTrust response error: %1
Error description: %2

Fields #

NameDescription
Error UnicodeString
ErrorDescription UnicodeString

Event ID 1089: Device is not cloud domain joined: Status.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Device is not cloud domain joined: Status.

Message #

Device is not cloud domain joined: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1090: NGC nonce response error: NGC_nonce_response_error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

NGC nonce response error: NGC_nonce_response_error.

Message #

NGC nonce response error: %1
Error description: %2
CorrelationID: %3

Fields #

NameDescription
Error UnicodeString
ErrorDescription UnicodeString
CorrelationID UnicodeString

Event ID 1091: NGC auth ticket is not defined.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

NGC auth ticket is not defined. Error: Result.

Message #

NGC auth ticket is not defined. Error: %1

Fields #

NameDescription
Result Int32

Event ID 1092: OAuth request retry.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

OAuth request retry. Correlation ID: OAuth_request_retry_Correlation_ID Retry: Retry.

Message #

OAuth request retry. Correlation ID: %1 Retry: %2

Fields #

NameDescription
CorrelationID UnicodeString
RetryNumber Int32

Event ID 1093: NGC call API returned error: Result.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

NGC call API returned error: Result.

Message #

NGC call %1 returned error: %2

Fields #

NameDescription
API UnicodeString
Result Int32

References #

Event ID 1094: Refresh token failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Refresh token failure. Status: Refresh_token_failure_Status Correlation ID: Correlation_ID.

Message #

Refresh token failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1095: Refresh token user SIDs don't match.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Refresh token user SIDs don't match. Correlation ID: value.

Message #

Refresh token user SIDs don't match. Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1096: Refresh token is expired.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Refresh token is expired. Correlation ID: value.

Message #

Refresh token is expired. Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1097: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Level
Warning
Task
AadTokenBrokerPluginOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-AAD",
    "guid": "{4DE9BC9C-B27A-43C9-8994-0915F1A5E24F}",
    "event_source_name": "",
    "event_id": 1097,
    "version": 0,
    "level": 3,
    "task": 103,
    "opcode": 0,
    "keywords": 4611686018427387952,
    "time_created": "2026-05-28T11:13:20.8708234+00:00",
    "event_record_id": 15,
    "correlation": {
      "ActivityID": "{AFDF3271-EE92-0000-B545-DFAF92EEDC01}"
    },
    "execution": {
      "process_id": 7736,
      "thread_id": 7784
    },
    "channel": "Microsoft-Windows-AAD/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Error": "2325807322",
    "ErrorMessage": "Upgrade default pawn task complete.",
    "AdditionalInformation": "Logged at UpdateDefaultPawn.cpp, line: 43, method: UpdateDefaultPawn::Apply."
  },
  "message": "Error: 0x8AA100DA Upgrade default pawn task complete.\r\nLogged at UpdateDefaultPawn.cpp, line: 43, method: UpdateDefaultPawn::Apply."
}

Event ID 1098: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Level
Error
Task
AadTokenBrokerPluginOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-AAD",
    "guid": "4DE9BC9C-B27A-43C9-8994-0915F1A5E24F",
    "event_source_name": "",
    "event_id": 1098,
    "version": 0,
    "level": 2,
    "task": 103,
    "opcode": 0,
    "keywords": 4611686018427387922,
    "time_created": "2026-03-14T21:11:21.909514+00:00",
    "event_record_id": 25,
    "correlation": {},
    "execution": {
      "process_id": 10584,
      "thread_id": 10312
    },
    "channel": "Microsoft-Windows-AAD/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Error": 3399811278,
    "ErrorMessage": "User requested add account.",
    "AdditionalInformation": "UI flow is completed with error\r\nLogged at WebUITokenRequest.cpp, line: 180, method: WebUITokenRequest::FinalizeUIFlow.\r\n\r\nRequest: authority: https://login.microsoftonline.com/organizations, client: d3590ed6-52b3-4102-aeff-aad2292ab01c, redirect URI: ms-appx-web://Microsoft.AAD.BrokerPlugin/d3590ed6-52b3-4102-aeff-aad2292ab01c, resource: , correlation ID (request): a315d45d-ad27-4338-a603-c6283cfa75d2"
  },
  "message": ""
}

Event ID 1099: Code: Code OperationCode OperationMessage.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadTokenBrokerPluginOperation

Description

Code: OperationCode OperationMessage AdditionalInformation

Message #

Code: %1 %2
%3

Fields #

NameDescription
OperationCode UInt32
OperationMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1100: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadAdalrtOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1101: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadAdalrtOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1102: Code: Code OperationCode OperationMessage.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadAdalrtOperation

Description

Code: OperationCode OperationMessage AdditionalInformation

Message #

Code: %1 %2
%3

Fields #

NameDescription
OperationCode UInt32
OperationMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1103: Can't decrypt OAuth response.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Can't decrypt OAuth response. Error: Cant_decrypt_OAuth_response_Error.

Message #

Can't decrypt OAuth response. Error: %1

Fields #

NameDescription
Result Int32

Event ID 1104: AAD Cloud AP plugin call API returned error: Result.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Level
Error
Task
AadCloudAPPluginOperation

Description

AAD Cloud AP plugin call API returned error: Result.

Message #

AAD Cloud AP plugin call %1 returned error: %2

Fields #

NameDescription
API UnicodeString
Result UInt321 returned error.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-AAD",
    "guid": "{4DE9BC9C-B27A-43C9-8994-0915F1A5E24F}",
    "event_source_name": "",
    "event_id": 1104,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 0,
    "keywords": 4611686018427387922,
    "time_created": "2026-05-29T16:32:50.6948431+00:00",
    "event_record_id": 25,
    "correlation": {
      "ActivityID": "{C6821FB2-EF88-0001-1820-82C688EFDC01}"
    },
    "execution": {
      "process_id": 812,
      "thread_id": 816
    },
    "channel": "Microsoft-Windows-AAD/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "API": "Plugin initialize",
    "Result": "3221521494"
  },
  "message": "AAD Cloud AP plugin call Plugin initialize returned error: 0xC0048456"
}

Event ID 1105: Device registration API call API returned error: Result.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Device registration API call API returned error: Result.

Message #

Device registration API call %1 returned error: %2

Fields #

NameDescription
API UnicodeString
Result UInt32

Event ID 1106: Number of security groups received value.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Number of security groups received value. CorrelationID: CorrelationID.

Message #

Number of security groups received %1. CorrelationID: %2

Fields #

NameDescription
value Int32
CorrelationID UnicodeString

Event ID 1107: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadTokenBrokerPluginOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1108: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadTokenBrokerPluginOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1109: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadAdalrtOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1110: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadAdalrtOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1111: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadAadtbOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1112: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadAadtbOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1113: Code: Code OperationCode OperationMessage.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadAadtbOperation

Description

Code: OperationCode OperationMessage AdditionalInformation

Message #

Code: %1 %2
%3

Fields #

NameDescription
OperationCode UInt32
OperationMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1114: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadAadtbOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1115: Error: Error ErrorMessage AdditionalInformation.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadAadtbOperation

Description

Error: Error ErrorMessage AdditionalInformation

Message #

Error: %1 %2
%3

Fields #

NameDescription
Error UInt32
ErrorMessage UnicodeString
AdditionalInformation UnicodeString

Event ID 1116: Get Enterprise STS OAuth Info failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Get Enterprise STS OAuth Info failure. Status: Status Correlation ID: CorrelationID.

Message #

Get Enterprise STS OAuth Info failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

References #

Event ID 1117: Enterprise STS Refresh token failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Enterprise STS Refresh token failure. Status: Status Correlation ID: CorrelationID.

Message #

Enterprise STS Refresh token failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

References #

Event ID 1118: Enterprise STS Logon failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Enterprise STS Logon failure. Status: Enterprise_STS_Logon_failure_Status Correlation ID: Correlation_ID.

Message #

Enterprise STS Logon failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

References #

Event ID 1119: Enterprise STS OAuth Info response: Enterprise_STS_OAuth_Info_response.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Enterprise STS OAuth Info response: Enterprise_STS_OAuth_Info_response.

Message #

Enterprise STS OAuth Info response: %1.
Request status: %2

Fields #

NameDescription
Response UnicodeString
Status Int32NTSTATUS reference

References #

Event ID 1120: Enterprise STS Refresh token is expired.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Enterprise STS Refresh token is expired. Correlation ID: value.

Message #

Enterprise STS Refresh token is expired. Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1121: Enterprise STS RefreshToken Correlation ID: value.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

Enterprise STS RefreshToken Correlation ID: value.

Message #

Enterprise STS RefreshToken Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1122: Refresh token subject don't match.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Refresh token subject don't match. Correlation ID: value.

Message #

Refresh token subject don't match. Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1123: AadCloudAPPlugin smart card logon for non-federated user.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin smart card logon for non-federated user.

Message #

AadCloudAPPlugin smart card logon for non-federated user.

Event ID 1124: Device is DRS joined but Enterprise STS is disabled: Status.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Device is DRS joined but Enterprise STS is disabled: Status.

Message #

Device is DRS joined but Enterprise STS is disabled: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1125: AadCloudAPPlugin loaded as surrogate, no key recovery

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin loaded as surrogate, no key recovery.

Message #

AadCloudAPPlugin loaded as surrogate, no key recovery

Event ID 1126: AadCloudAPPlugin device is Enterprise joined

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin device is Enterprise joined.

Message #

AadCloudAPPlugin device is Enterprise joined

Event ID 1127: AadCloudAPPlugin device P2P certificate update thread started

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin device P2P certificate update thread started.

Message #

AadCloudAPPlugin device P2P certificate update thread started

References #

Event ID 1128: AadCloudAPPlugin device P2P certificate update thread stopped

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin device P2P certificate update thread stopped.

Message #

AadCloudAPPlugin device P2P certificate update thread stopped

Event ID 1129: AadCloudAPPlugin Uninitialize Stop

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin Uninitialize Stop.

Message #

AadCloudAPPlugin Uninitialize Stop

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1130: AadCloudAPPlugin DeviceP2PCertificateUpdate Correlation ID: AadCloudAPPlugin_DeviceP2PCertificateUpdate_Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin DeviceP2PCertificateUpdate Correlation ID: AadCloudAPPlugin_DeviceP2PCertificateUpdate_Correlation_ID.

Message #

AadCloudAPPlugin DeviceP2PCertificateUpdate Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1131: Update P2P device certificate failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Update P2P device certificate failure. Status: Status Correlation ID: CorrelationID.

Message #

Update P2P device certificate failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1132: AadCloudAPPlugin GetCertificateFromCred Correlation ID: AadCloudAPPlugin_GetCertificateFromCred_Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin GetCertificateFromCred Correlation ID: AadCloudAPPlugin_GetCertificateFromCred_Correlation_ID.

Message #

AadCloudAPPlugin GetCertificateFromCred Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1133: Update P2P user certificate failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Update P2P user certificate failure. Status: Status Correlation ID: CorrelationID.

Message #

Update P2P user certificate failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1134: AAD Cloud AP plugin call API returned error: Result.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

AAD Cloud AP plugin call API returned error: Result.

Message #

AAD Cloud AP plugin call %1 returned error: %2

Fields #

NameDescription
API UnicodeString
Result UInt32

Event ID 1135: AadCloudAPPlugin RenewCertificate Correlation ID: AadCloudAPPlugin_RenewCertificate_Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin RenewCertificate Correlation ID: AadCloudAPPlugin_RenewCertificate_Correlation_ID.

Message #

AadCloudAPPlugin RenewCertificate Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1136: AadCloudAPPlugin AcceptPeerCertificate Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin AcceptPeerCertificate Start.

Message #

AadCloudAPPlugin AcceptPeerCertificate Start

Event ID 1137: AadCloudAPPlugin AcceptPeerCertificate Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin AcceptPeerCertificate Stop.

Message #

AadCloudAPPlugin AcceptPeerCertificate Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1138: AadCloudAPPlugin RenewCertificate Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin RenewCertificate Start.

Message #

AadCloudAPPlugin RenewCertificate Start

Event ID 1139: AadCloudAPPlugin RenewCertificate Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin RenewCertificate Stop.

Message #

AadCloudAPPlugin RenewCertificate Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1140: AadCloudAPPlugin GetCertificateFromCred Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin GetCertificateFromCred Start.

Message #

AadCloudAPPlugin GetCertificateFromCred Start

Event ID 1141: AadCloudAPPlugin GetCertificateFromCred Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin GetCertificateFromCred Stop.

Message #

AadCloudAPPlugin GetCertificateFromCred Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1142: Get token user names don't match.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Get token user names don't match. Correlation ID: value.

Message #

Get token user names don't match. Correlation ID: %1

Fields #

NameDescription
value UnicodeString

Event ID 1143: Generic Call Package call type: Generic_Call_Packate_call_type.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Generic Call Package call type: Generic_Call_Packate_call_type. Correlation ID: Correlation_ID.

Message #

Generic Call Package call type: %1. Correlation ID: %2

Fields #

NameDescription
value Int32
CorrelationID UnicodeString

Event ID 1144: Realm discovery for: Method authority: EndpointUri fallback domain hint: CorrelationID useUpn: value.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Realm discovery for: Method authority: EndpointUri fallback domain hint: CorrelationID useUpn: value.

Message #

Realm discovery for: %2 authority: %3 fallback domain hint: %4 useUpn: %1

Fields #

NameDescription
value Int32
Method UnicodeString
EndpointUri UnicodeString
CorrelationID UnicodeString

Event ID 1145: AAD Cloud AP plugin token needs refresh reason: value.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

AAD Cloud AP plugin token needs refresh reason: value.

Message #

AAD Cloud AP plugin token needs refresh reason: %1

Fields #

NameDescription
value UnicodeString

Event ID 1146: Token is not refreshed.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token is not refreshed. token time: NoOfTargets update time: RequestType.

Message #

Token is not refreshed. token time: %1 update time: %2

Fields #

NameDescription
NoOfTargets UInt64
RequestType UInt64

Event ID 1147: AadCloudAPPlugin AssembleOpaqueData Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin AssembleOpaqueData Start.

Message #

AadCloudAPPlugin AssembleOpaqueData Start

Event ID 1148: AadCloudAPPlugin AssembleOpaqueData Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin AssembleOpaqueData Stop.

Message #

AadCloudAPPlugin AssembleOpaqueData Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1149: AadCloudAPPlugin DisassembleOpaqueData Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin DisassembleOpaqueData Start.

Message #

AadCloudAPPlugin DisassembleOpaqueData Start

References #

Event ID 1150: AadCloudAPPlugin DisassembleOpaqueData Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin DisassembleOpaqueData Stop.

Message #

AadCloudAPPlugin DisassembleOpaqueData Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1151: AadCloudAPPlugin P2P device certificate update error: Status.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin P2P device certificate update error: Status.

Message #

AadCloudAPPlugin P2P device certificate update error: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1152: AadCloudAPPlugin device certificate key error: Result.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin device certificate key error: Result.

Message #

AadCloudAPPlugin device certificate key error: %1

Fields #

NameDescription
Result Int32

Event ID 1153: AadCloudAPPlugin device certificate not available for logon: value.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin device certificate not available for logon: value.

Message #

AadCloudAPPlugin device certificate not available for logon: %1

Fields #

NameDescription
value UnicodeString

Event ID 1154: Password expiration claims.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Password expiration claims. Seconds: Password_expiration_claims_Seconds URI: URI.

Message #

Password expiration claims. Seconds: %1 URI: %2

Fields #

NameDescription
seconds Int32
URI UnicodeString

Event ID 1155: Logon with session key failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Logon with session key failure. Retrying with device auth. Status: Status Correlation ID: CorrelationID.

Message #

Logon with session key failure. Retrying with device auth. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1156: Password expiration fields.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Password expiration fields. Status: Password_expiration_fields_Status Date: Date URI: URI.

Message #

Password expiration fields. Status: %1 Date: %2 URI: %3

Fields #

NameDescription
Status HexInt32NTSTATUS reference
ExpiryTime FILETIME
PasswordChangeURI UnicodeString

Event ID 1157: AadCloudAPPlugin PostLogonProcessing Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin PostLogonProcessing Start.

Message #

AadCloudAPPlugin PostLogonProcessing Start

Event ID 1158: AadCloudAPPlugin PostLogonProcessing Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin PostLogonProcessing Stop.

Message #

AadCloudAPPlugin PostLogonProcessing Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1159: AadCloudAPPlugin S4U logon failed.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin S4U logon failed. Status: AadCloudAPPlugin_S2U_logon_failed_Status.

Message #

AadCloudAPPlugin S4U logon failed. Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1160: Logon failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Logon failure. Status: Logon_failure_Status Correlation ID: Correlation_ID.

Message #

Logon failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1161: Logon failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Logon failure. Status: Logon_failure_Status Correlation ID: Correlation_ID.

Message #

Logon failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1162: Logon failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Logon failure. Status: Logon_failure_Status Correlation ID: Correlation_ID.

Message #

Logon failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1163: Logon failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Logon failure. Status: Logon_failure_Status Correlation ID: Correlation_ID.

Message #

Logon failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1164: Logon failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Logon failure. Status: Logon_failure_Status Correlation ID: Correlation_ID.

Message #

Logon failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1165: Logon failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Logon failure. Status: Logon_failure_Status Correlation ID: Correlation_ID.

Message #

Logon failure. Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1200: BrowserCore operation started

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
BrowserCoreOperation
Opcode
Start

Description

BrowserCore operation started.

Message #

BrowserCore operation started

Event ID 1201: BrowserCore operation completed successfully

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
BrowserCoreOperation
Opcode
Stop

Description

BrowserCore operation completed successfully.

Message #

BrowserCore operation completed successfully.
Method: %1
CorrelationID: %2

Fields #

NameDescription
Method UnicodeString
CorrelationID UnicodeString

Event ID 1202: BrowserCore operation completed with a failure.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
BrowserCoreOperation
Opcode
Stop

Description

BrowserCore operation completed with a failure.

Message #

BrowserCore operation completed with a failure.
Error: %1
Error Message: %2
Method: %3
CorrelationID: %4

Fields #

NameDescription
Result Int32
ErrorMessage UnicodeString
Method UnicodeString
CorrelationID UnicodeString

Event ID 1203: BrowserCore inner operation FunctionName completed with error: Result.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
BrowserCoreOperation

Description

BrowserCore inner operation FunctionName completed with error: Result.

Message #

BrowserCore inner operation %2 completed with error: %1

Fields #

NameDescription
Result Int32
FunctionName AnsiString

Event ID 1204: AadCloudAPPlugin LookupSIDFromIdentityName Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin LookupSIDFromIdentityName Start.

Message #

AadCloudAPPlugin LookupSIDFromIdentityName Start

Event ID 1205: AadCloudAPPlugin LookupSIDFromIdentityName Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin LookupSIDFromIdentityName Stop.

Message #

AadCloudAPPlugin LookupSIDFromIdentityName Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1206: AadCloudAPPlugin LookupIdentityFromSIDName Start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin LookupIdentityFromSIDName Start.

Message #

AadCloudAPPlugin LookupIdentityFromSIDName Start

Event ID 1207: AadCloudAPPlugin LookupIdentityFromSIDName Stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Stop

Description

AadCloudAPPlugin LookupIdentityFromSIDName Stop.

Message #

AadCloudAPPlugin LookupIdentityFromSIDName Stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1208: AadCloudAPPlugin LookupSIDFromIdentity Identity: AadCloudAPPlugin_LookupSIDFromIdentity_Identity Correlation ID: Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin LookupSIDFromIdentity Identity: AadCloudAPPlugin_LookupSIDFromIdentity_Identity Correlation ID: Correlation_ID.

Message #

AadCloudAPPlugin LookupSIDFromIdentity Identity: %1 Correlation ID: %2

Fields #

NameDescription
value1 UnicodeString
value2 UnicodeString

Event ID 1209: AadCloudAPPlugin LookupIdentityFromSID SID: AadCloudAPPlugin_LookupIdentityFromSID_SID Correlation ID: Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

AadCloudAPPlugin LookupIdentityFromSID SID: AadCloudAPPlugin_LookupIdentityFromSID_SID Correlation ID: Correlation_ID.

Message #

AadCloudAPPlugin LookupIdentityFromSID SID: %1 Correlation ID: %2

Fields #

NameDescription
value1 UnicodeString
value2 UnicodeString

Event ID 1210: AadCloudAPPlugin password expired, password change URI: value.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin password expired, password change URI: value.

Message #

AadCloudAPPlugin password expired, password change URI: %1

Fields #

NameDescription
value UnicodeString

Event ID 1211: Writing RunRecovery registry value failed.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Writing RunRecovery registry value failed.

Message #

Writing RunRecovery registry value failed.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1212: Enterprise logon.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Enterprise logon. Password is expired.

Message #

Enterprise logon. Password is expired.
Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1213: WamExtension process token operation started

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
WamExtensionOperation
Opcode
Start

Description

WamExtension process token operation started.

Message #

WamExtension process token operation started.

Event ID 1214: WamExtension process token operation completed successfully

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
WamExtensionOperation
Opcode
Stop

Description

WamExtension process token operation completed successfully.

Message #

WamExtension process token operation completed successfully

Event ID 1215: WamExtension process token operation completed with error: Data.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Level
Error
Task
WamExtensionOperation
Opcode
Stop

Description

WamExtension process token operation completed with error: Data.

Message #

WamExtension process token operation completed with error: %1

Fields #

NameDescription
Result

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-AAD",
    "guid": "4DE9BC9C-B27A-43C9-8994-0915F1A5E24F",
    "event_source_name": "",
    "event_id": 1215,
    "version": 0,
    "level": 2,
    "task": 107,
    "opcode": 2,
    "keywords": 4611686018427387922,
    "time_created": "2022-04-07T16:44:49.386586+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 2080,
      "thread_id": 2748
    },
    "channel": "Microsoft-Windows-AAD/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data": {
      "Name": "Result",
      "Value": "\u0004�\u0004�"
    }
  },
  "message": ""
}

References #

Event ID 1216: WamExtension device authentication call status: Result Correlation ID: Target.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
WamExtensionOperation
Opcode
Start

Description

WamExtension device authentication call status: Result Correlation ID: Target.

Message #

WamExtension device authentication call status: %1 Correlation ID: %2

Fields #

NameDescription
Result Int32
Target UnicodeString

Event ID 1217: Get device token.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Get device token. Resource: Get_device_token_Resource ClientID: ClientID Scope: Scope.

Message #

Get device token. Resource: %1 ClientID: %2 Scope: %3

Fields #

NameDescription
value1 UnicodeString
value2 UnicodeString
value3 UnicodeString

Event ID 1218: StartFidoAuthenticationSession start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Start

Description

StartFidoAuthenticationSession start.

Message #

StartFidoAuthenticationSession start

Event ID 1219: StartFidoAuthenticationSession stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Stop

Description

StartFidoAuthenticationSession stop.

Message #

StartFidoAuthenticationSession stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1220: CloseFidoAuthenticationSession start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Start

Description

CloseFidoAuthenticationSession start.

Message #

CloseFidoAuthenticationSession start

Event ID 1221: CloseFidoAuthenticationSession stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Stop

Description

CloseFidoAuthenticationSession stop.

Message #

CloseFidoAuthenticationSession stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1222: GetClientData start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Start

Description

GetClientData start.

Message #

GetClientData start

Event ID 1223: GetClientData stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Stop

Description

GetClientData stop.

Message #

GetClientData stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1224: SignClientDataFido start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Start

Description

SignClientDataFido start.

Message #

SignClientDataFido start

Event ID 1225: SignClientDataFido stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Stop

Description

SignClientDataFido stop.

Message #

SignClientDataFido stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1226: ChangePin start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Start

Description

ChangePin start.

Message #

ChangePin start

Event ID 1227: ChangePin stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Stop

Description

ChangePin stop.

Message #

ChangePin stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1228: GetSerializedAuthBuffer start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Start

Description

GetSerializedAuthBuffer start.

Message #

GetSerializedAuthBuffer start

Event ID 1229: GetSerializedAuthBuffer stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Stop

Description

GetSerializedAuthBuffer stop.

Message #

GetSerializedAuthBuffer stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1230: AuthHelper call API returned error: Result.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AuthHelper

Description

AuthHelper call API returned error: Result.

Message #

AuthHelper call %1 returned error: %2

Fields #

NameDescription
API UnicodeString
Result UInt32

Event ID 1231: AadCloudAPPlugin Resource infomation: AadCloudAPPlugin_Resource_infomation.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin Resource infomation: AadCloudAPPlugin_Resource_infomation.

Message #

AadCloudAPPlugin Resource infomation: %1.
Request status: %2

Fields #

NameDescription
Response UnicodeString
Status Int32NTSTATUS reference

Event ID 1232: AadCloudAPPlugin RBAC authorization code response: Response.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin RBAC authorization code response: Response.

Message #

AadCloudAPPlugin RBAC authorization code response: %1.
Request status: %2

Fields #

NameDescription
Response UnicodeString
Status Int32NTSTATUS reference

Event ID 1233: AadCloudAPPlugin User access control role: value.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin User access control role: value.

Message #

AadCloudAPPlugin User access control role: %1

Fields #

NameDescription
value UnicodeString

Event ID 1234: AadCloudAPPlugin using resource id from the Idtoken: value.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

AadCloudAPPlugin using resource id from the Idtoken: value.

Message #

AadCloudAPPlugin using resource id from the Idtoken: %1

Fields #

NameDescription
value UnicodeString

Event ID 1235: RBAC Status: RBAC_Status Correlation ID: Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

RBAC Status: RBAC_Status Correlation ID: Correlation_ID.

Message #

RBAC Status: %1 Correlation ID: %2

Fields #

NameDescription
Status HexInt32NTSTATUS reference
CorrelationID UnicodeString

Event ID 1236: Failed to create the resource id

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Failed to create the resource id.

Message #

Failed to create the resource id

Event ID 1237: Device is configured for RBAC authorization

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Device is configured for RBAC authorization.

Message #

Device is configured for RBAC authorization

Event ID 1238: Not sending the client certificate as it is optional on the server

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Not sending the client certificate as it is optional on the server.

Message #

Not sending the client certificate as it is optional on the server

Event ID 1239: Doing RBAC logon of the device type: value.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Doing RBAC logon of the device type: value.

Message #

Doing RBAC logon of the device type: %1

Fields #

NameDescription
value UnicodeString

Event ID 1240: Skipping Rbac Logon because AadCloudAPPlugin is loaded as surrogate

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Skipping Rbac Logon because AadCloudAPPlugin is loaded as surrogate.

Message #

Skipping Rbac Logon because AadCloudAPPlugin is loaded as surrogate

Event ID 1241: On-prem tgt error: Onprem_tgt_error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

On-prem tgt error: Onprem_tgt_error.

Message #

On-prem tgt error: %1

Fields #

NameDescription
value UnicodeString

Event ID 1242: Added user to admins security group

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Added user to admins security group.

Message #

Added user to admins security group

Event ID 1243: Removed user from admins security group

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Removed user from admins security group.

Message #

Removed user from admins security group

Event ID 1244: Security groups were not loaded.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Security groups were not loaded. Error: Status.

Message #

Security groups were not loaded. Error: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1245: Security groups were not updated.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Security groups were not updated. Error: Status.

Message #

Security groups were not updated. Error: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1246: User sid: User_sid Group sids: Group_sids.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

User sid: value1 Group sids: value2

Message #

User sid: %1
Group sids:
%2

Fields #

NameDescription
value1 UnicodeString
value2 UnicodeString

Event ID 1247: RunRecovery registry value (Context) successfully written.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

RunRecovery registry value (Context) successfully written.

Message #

RunRecovery registry value (%1) successfully written.
Context: %2
Reason: %3

Fields #

NameDescription
value Int32
Context UnicodeString
Result Int32

Event ID 1248: AuthHelper auth buff local nonce

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AuthHelper

Description

AuthHelper auth buff local nonce.

Message #

AuthHelper auth buff local nonce

Event ID 1249: Cloud tgt error: Cloud_tgt_error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Cloud tgt error: Cloud_tgt_error.

Message #

Cloud tgt error: %1

Fields #

NameDescription
value UnicodeString

Event ID 1250: DoGetToken Diagnostic Event.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

DoGetToken Diagnostic Event.

Message #

DoGetToken Diagnostic Event:
Result: %1
User Identity: %2
Credential Type: %3
Correlation ID: %4
Endpoint Uri: %5
HTTP Status: %6
HTTP Method: %7
ErrorCode: %8
Error Description: %9

Fields #

NameDescription
Result UInt32[DoGetToken Diagnostic Event] Result.
UserIdentity UnicodeString
CredentialType Int32
Known values
%%8096
Default credentials
%%8097
Credentials manager
%%8098
Fresh credentials
CorrelationID UnicodeString
EndpointUri UnicodeString
Method UnicodeString
HTTPTransportError Int32
HTTPStatus Int32
ErrorCode UnicodeString[DoGetToken Diagnostic Event] ErrorCode.
ErrorDescription UnicodeString

Event ID 1251: DoGetEnterpriseToken Diagnostic Event.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

DoGetEnterpriseToken Diagnostic Event.

Message #

DoGetEnterpriseToken Diagnostic Event:
Result: %1
User Identity: %2
Credential Type: %3
Correlation ID: %4
Endpoint Uri: %5
HTTP Status: %6
HTTP Method: %7
ErrorCode: %8
Error Description: %9

Fields #

NameDescription
Result UInt32[DoGetEnterpriseToken Diagnostic Event] Result.
UserIdentity UnicodeString
CredentialType Int32
Known values
%%8096
Default credentials
%%8097
Credentials manager
%%8098
Fresh credentials
CorrelationID UnicodeString
EndpointUri UnicodeString
Method UnicodeString
HTTPTransportError Int32
HTTPStatus Int32
ErrorCode UnicodeString[DoGetEnterpriseToken Diagnostic Event] ErrorCode.
ErrorDescription UnicodeString

Event ID 1252: DoRefreshToken Diagnostic Event.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

DoRefreshToken Diagnostic Event.

Message #

DoRefreshToken Diagnostic Event:
Result: %1
User Identity: %2
Credential Type: %3
Correlation ID: %4
Endpoint Uri: %5
HTTP Status: %6
HTTP Method: %7
ErrorCode: %8
Error Description: %9

Fields #

NameDescription
Result UInt32[DoRefreshToken Diagnostic Event] Result.
UserIdentity UnicodeString
CredentialType Int32
Known values
%%8096
Default credentials
%%8097
Credentials manager
%%8098
Fresh credentials
NewToken Boolean
CorrelationID UnicodeString
EndpointUri UnicodeString
Method UnicodeString
HTTPTransportError Int32
HTTPStatus Int32
ErrorCode UnicodeString[DoRefreshToken Diagnostic Event] ErrorCode.
ErrorDescription UnicodeString

Event ID 1253: DoRefreshEnterpriseToken Diagnostic Event.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

DoRefreshEnterpriseToken Diagnostic Event.

Message #

DoRefreshEnterpriseToken Diagnostic Event:
Result: %1
User Identity: %2
Credential Type: %3
Correlation ID: %4
Endpoint Uri: %5
HTTP Status: %6
HTTP Method: %7
ErrorCode: %8
Error Description: %9

Fields #

NameDescription
Result UInt32[DoRefreshEnterpriseToken Diagnostic Event] Result.
UserIdentity UnicodeString
CredentialType Int32
Known values
%%8096
Default credentials
%%8097
Credentials manager
%%8098
Fresh credentials
NewToken Boolean
CorrelationID UnicodeString
EndpointUri UnicodeString
Method UnicodeString
HTTPTransportError Int32
HTTPStatus Int32
ErrorCode UnicodeString[DoRefreshEnterpriseToken Diagnostic Event] ErrorCode.
ErrorDescription UnicodeString

Event ID 1254: Response content type: Response_content_type.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Response content type: Response_content_type.

Message #

Response content type: %1

Fields #

NameDescription
value UnicodeString

Event ID 1255: AD TGT: AD_TGT Cloud TGT: Cloud_TGT.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

AD TGT: AD_TGT Cloud TGT: Cloud_TGT.

Message #

AD TGT: %1 Cloud TGT: %2

Fields #

NameDescription
NoOfTargets UInt32
RequestType UInt32

Event ID 1256: P2P certificate update error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

P2P certificate update error. Status: P2P_certificate_update_error_Status Correlation ID: Correlation_ID.

Message #

P2P certificate update error. Status: %1 Correlation ID: %2

Fields #

NameDescription
Result Int32
Target UnicodeString

Event ID 1257: Credbuffer correlation ID: Credbuffer_correlation_ID Correlation ID: Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

Credbuffer correlation ID: Credbuffer_correlation_ID Correlation ID: Correlation_ID.

Message #

Credbuffer correlation ID: %1 Correlation ID: %2

Fields #

NameDescription
value1 UnicodeString
value2 UnicodeString

Event ID 1258: CA cert hash (keyID): CA_cert_hash_keyID Correlation ID: Correlation_ID.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation
Opcode
Start

Description

CA cert hash (keyID): CA_cert_hash_keyID Correlation ID: Correlation_ID.

Message #

CA cert hash (keyID): %1 Correlation ID: %2

Fields #

NameDescription
value1 UnicodeString
value2 UnicodeString

Event ID 1259: CA certificate update error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

CA certificate update error. Status: CA_certificate_update_error_Status Correlation ID: Correlation_ID.

Message #

CA certificate update error. Status: %1 Correlation ID: %2

Fields #

NameDescription
Result Int32
Target UnicodeString

Event ID 1260: RetryGetClientData start

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Start

Description

RetryGetClientData start.

Message #

RetryGetClientData start

Event ID 1261: RetryGetClientData stop.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AuthHelper
Opcode
Stop

Description

RetryGetClientData stop.

Message #

RetryGetClientData stop.
Status: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1262: Binding key tag check failed: Binding_key_tag_check_failed.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

Binding key tag check failed: Binding_key_tag_check_failed.

Message #

Binding key tag check failed: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1263: BrowserCore inner operation FunctionName with account pairwiseID PairwiseID not found error.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
BrowserCoreOperation

Description

BrowserCore inner operation FunctionName with account pairwiseID PairwiseID not found error.

Message #

BrowserCore inner operation %2 with account pairwiseID %1 not found error

Fields #

NameDescription
PairwiseID UnicodeString
FunctionName AnsiString

Event ID 1264: Token binding key created.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token binding key created.

Message #

Token binding key created.
Key Type: %1
Client: %2
Resource: %3
Scope: %4

Fields #

NameDescription
KeyType Int32
Known values
%%2499
Machine key
%%2500
User key
ClientId UnicodeString
Resource UnicodeString
Scope UnicodeString

Event ID 1265: WamExtension preprocess token operation started.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
WamExtensionOperation
Opcode
Start

Description

WamExtension preprocess token operation started.

Message #

WamExtension preprocess token operation started.

Event ID 1266: WamExtension preprocess token operation completed successfully

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
WamExtensionOperation
Opcode
Stop

Description

WamExtension preprocess token operation completed successfully.

Message #

WamExtension preprocess token operation completed successfully

Event ID 1267: WamExtension preprocess token operation completed with error: Result.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
WamExtensionOperation
Opcode
Stop

Description

WamExtension preprocess token operation completed with error: Result.

Message #

WamExtension preprocess token operation completed with error: %1

Fields #

NameDescription
Result Int32

Event ID 1268: WamExtension postprocess token operation started.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
WamExtensionOperation
Opcode
Start

Description

WamExtension postprocess token operation started.

Message #

WamExtension postprocess token operation started.
Stage: %1

Fields #

NameDescription
Stage UnicodeString

Event ID 1269: WamExtension postprocess token operation completed successfully.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
WamExtensionOperation
Opcode
Stop

Description

WamExtension postprocess token operation completed successfully.

Message #

WamExtension postprocess token operation completed successfully.
Stage: %1

Fields #

NameDescription
Stage UnicodeString

Event ID 1270: WamExtension postprocess token operation completed with error: Result.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
WamExtensionOperation
Opcode
Stop

Description

WamExtension postprocess token operation completed with error: Result.

Message #

WamExtension postprocess token operation completed with error: %2.
Stage: %1

Fields #

NameDescription
Stage UnicodeString
Result Int32

Event ID 1271: Token binding claim(s) included in the request.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token binding claim(s) included in the request. Correlation ID: CorrelationID.

Message #

Token binding claim(s) included in the request. Correlation ID: %1

Fields #

NameDescription
CorrelationID UnicodeString

Event ID 1272: Token binding key is not healthy and needs to be re-created.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token binding key is not healthy and needs to be re-created.

Message #

Token binding key is not healthy and needs to be re-created.
Key Type: %1
Client: %2
Resource: %3
Scope: %4
Test result: %5

Fields #

NameDescription
KeyType Int32
Known values
%%2499
Machine key
%%2500
User key
ClientId UnicodeString
Resource UnicodeString
Scope UnicodeString
KeyTestResult Int32

Event ID 1273: Token binding claims need to be re-generated due to changes in attestation key(s).

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token binding claims need to be re-generated due to changes in attestation key(s).

Message #

Token binding claims need to be re-generated due to changes in attestation key(s).
Key Type: %1
Client: %2
Resource: %3
Scope: %4

Fields #

NameDescription
KeyType Int32
Known values
%%2499
Machine key
%%2500
User key
ClientId UnicodeString
Resource UnicodeString
Scope UnicodeString

Event ID 1274: Token binding claims generated.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token binding claims generated.

Message #

Token binding claims generated.
Key Type: %1
Client: %2
Resource: %3
Scope: %4

Fields #

NameDescription
KeyType Int32
Known values
%%2499
Machine key
%%2500
User key
ClientId UnicodeString
Resource UnicodeString
Scope UnicodeString

Event ID 1275: Token binding claims generated for UI request.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token binding claims generated for UI request.

Message #

Token binding claims generated for UI request.
Key Type: %1
Client: %2
Resource: %3
Scope: %4

Fields #

NameDescription
KeyType Int32
Known values
%%2499
Machine key
%%2500
User key
ClientId UnicodeString
Resource UnicodeString
Scope UnicodeString

Event ID 1276: Token binding claims count: ClaimsCount.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token binding claims count: ClaimsCount.

Message #

Token binding claims count: %1

Fields #

NameDescription
ClaimsCount Int32

Event ID 1277: KeyGuard availability detection failed.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

KeyGuard availability detection failed. Error: Result.

Message #

KeyGuard availability detection failed. Error: %1

Fields #

NameDescription
Result Int32

Event ID 1278: KeyGuard with attestation support is not detected.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

KeyGuard with attestation support is not detected.

Message #

KeyGuard with attestation support is not detected.

Event ID 1279: Token binding claims of type KeyType could not be generated because AIK does not exist.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token binding claims of type KeyType could not be generated because AIK does not exist.

Message #

Token binding claims of type %1 could not be generated because AIK does not exist.
Join Type: %2
Tenant ID: %3

Fields #

NameDescription
KeyType Int32
Known values
%%2499
Machine key
%%2500
User key
JoinType Int32
TenantId UnicodeString

Event ID 1280: PRT session key needs to be rolled.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
AadCloudAPPluginOperation

Description

PRT session key needs to be rolled.

Message #

PRT session key needs to be rolled.
Reason: %1

Fields #

NameDescription
RollReason UnicodeString

Event ID 1281: Token binding key deleted.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token binding key deleted.

Message #

Token binding key deleted.
Key: %1

Fields #

NameDescription
Key UnicodeString

Event ID 1282: SHR property in request is not allowed.

#
Provider
Microsoft-Windows-AAD
Channel
Operational
Task
WamExtensionOperation

Description

SHR property in request is not allowed. Property: PropertyName.

Message #

SHR property in request is not allowed. Property: %1

Fields #

NameDescription
PropertyName UnicodeString

Event ID 1283: Invalid registry value was ignored.

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Invalid registry value was ignored.

Message #

Invalid registry value was ignored.
Location: %1
Value name: %2
Value: %3

Fields #

NameDescription
RegistryLocation UnicodeString
RegistryValueName UnicodeString
Value HexInt32

Event ID 1284: Token binding claims need to be re-generated as cached claims were generated for different attestation key(s).

#
Provider
Microsoft-Windows-AAD
Channel
Analytic
Task
AadCloudAPPluginOperation

Description

Token binding claims need to be re-generated as cached claims were generated for different attestation key(s).

Message #

Token binding claims need to be re-generated as cached claims were generated for different attestation key(s).
Key Type: %1
Client: %2
Resource: %3
Scope: %4

Fields #

NameDescription
KeyType Int32
Known values
%%2499
Machine key
%%2500
User key
ClientId UnicodeString
Resource UnicodeString
Scope UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 4de9bc9c-b27a-43c9-8994-0915f1a5e24f

Defined in aadcloudAP.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads