Microsoft-Windows-ACL-UI

12 events across 1 channel

Event ID 4000: LaunchAdvancedACLUIStart

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
LaunchAdvancedACLUI
Opcode
Start

Event ID 4001: LaunchAdvancedACLUIStop

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
LaunchAdvancedACLUI
Opcode
Stop

Event ID 4002: DownloadClaimIDsStart

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
DownloadClaimIDs
Opcode
Start

Event ID 4003: DownloadClaimIDsStop

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
DownloadClaimIDs
Opcode
Stop

Event ID 4004: DisplayPermissionsDialogwhenEditinganACEStart

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
DisplayPermissionsDialogwhenEditinganACE
Opcode
Start

Event ID 4005: DisplayPermissionsDialogwhenEditinganACEStop

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
DisplayPermissionsDialogwhenEditinganACE
Opcode
Stop

Event ID 4006: DisplayPermissionsDialogwhenAddinganACEStart

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
DisplayPermissionsDialogwhenAddinganACE
Opcode
Start

Event ID 4007: DisplayPermissionsDialogwhenAddinganACEStop

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
DisplayPermissionsDialogwhenAddinganACE
Opcode
Stop

Event ID 4008: DownloadCentralAccessPolicyIDsStart

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
DownloadCentralAccessPolicyIDs
Opcode
Start

Event ID 4009: DownloadCentralAccessPolicyIDsStop

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
DownloadCentralAccessPolicyIDs
Opcode
Stop

Event ID 4010: DisplayEffectivePermissionReportStart

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
DisplayEffectivePermissionReport
Opcode
Start

Event ID 4011: DisplayEffectivePermissionReportStop

#
Provider
Microsoft-Windows-ACL-UI
Channel
Operational
Task
DisplayEffectivePermissionReport
Opcode
Stop

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID ea4cc8b8-a150-47a3-afb9-c8d194b19452

Defined in aclui.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads