Microsoft-Windows-Bluetooth-Policy

Event ID 1: A Bluetooth policy has changed.

#
Channel
Operational
Opcode
Info

Description

A Bluetooth policy has changed. Policy PolicyPath\PolicyName has value of: PolicyValue.

Message #

A Bluetooth policy has changed.  Policy %1\%2 has value of: %3

Fields #

NameDescription
PolicyPath UnicodeString
PolicyName UnicodeString
PolicyValue UnicodeString

Event ID 2: Bluetooth radio enablement has been PolicyState due to policy PolicyPath\PolicyName.

#
Channel
Operational
Opcode
Info

Message #

Bluetooth radio enablement has been %3 due to policy %1\%2.

Fields #

NameDescription
PolicyPath UnicodeString
PolicyName UnicodeString
PolicyState UnicodeString

Event ID 3: Bluetooth radio has PolicyState advertising due to policy PolicyPath\PolicyName.

#
Channel
Operational
Opcode
Info

Message #

Bluetooth radio has %3 advertising due to policy %1\%2.

Fields #

NameDescription
PolicyPath UnicodeString
PolicyName UnicodeString
PolicyState UnicodeString

Event ID 4: Bluetooth radio has PolicyState discoverability due to policy PolicyPath\PolicyName.

#
Channel
Operational
Opcode
Info

Message #

Bluetooth radio has %3 discoverability due to policy %1\%2.

Fields #

NameDescription
PolicyPath UnicodeString
PolicyName UnicodeString
PolicyState UnicodeString

Event ID 5: Bluetooth radio has PolicyState radio name as RadioName due to policy PolicyPath\PolicyName.

#
Channel
Operational
Opcode
Info

Message #

Bluetooth radio has %3 radio name as %4 due to policy %1\%2.

Fields #

NameDescription
PolicyPath UnicodeString
PolicyName UnicodeString
PolicyState UnicodeString
RadioName UnicodeString

Event ID 6: Process Service has attempted to pair to radio BtAddr.

#
Channel
Operational
Opcode
Info

Message #

Process %2 has attempted to pair to radio %1.

Fields #

NameDescription
BtAddr UInt64
Service UnicodeString

Event ID 7: Bluetooth has Accepted service ServiceGuid on remote device BtAddr due to policy PolicyPath\PolicyName.

#
Channel
Operational
Opcode
Info

Message #

Bluetooth has %1 service %2 on remote device %3 due to policy %4\%5...

Fields #

NameDescription
Accepted UnicodeString
ServiceGuid GUID
BtAddr UInt64
PolicyPath UnicodeString
PolicyName UnicodeString

Event ID 8: Bluetooth has Accepted PSM Psm on remote device BtAddr due to policy PolicyPath\PolicyName.

#
Channel
Operational
Opcode
Info

Message #

Bluetooth has %1 PSM %2 on remote device %3 due to policy %4\%5...

Fields #

NameDescription
Accepted UnicodeString
Psm Int16
BtAddr UInt64
PolicyPath UnicodeString
PolicyName UnicodeString

Event ID 9: A connection to a remote device bthAddr was successfully established.

#
Channel
Operational
Opcode
Info

Message #

A connection to a remote device %1 was successfully established.

Fields #

NameDescription
bthAddr UInt64

Event ID 10: An attempt to connect to a remote device bthAddr failed.

#
Channel
Operational
Opcode
Info

Message #

An attempt to connect to a remote device %1 failed.

Fields #

NameDescription
bthAddr UInt64

Event ID 11: The minimum encryption key size requirement of requiredKeySize octets was enforced on a connection to the remote device bthAddr.

#
Channel
Operational
Opcode
Info

Description

The minimum encryption key size requirement of requiredKeySize octets was enforced on a connection to the remote device bthAddr. The key size is actualKeySize octets.

Message #

The minimum encryption key size requirement of %2 octets was enforced on a connection to the remote device %1. The key size is %3 octets.

Fields #

NameDescription
bthAddr UInt64
requiredKeySize UInt8
actualKeySize UInt8

Event ID 12: A connection to the remote device bthAddr was rejected because it did not meet the minimum encryption key size requirement of requiredKeySize octets.

#
Channel
Operational
Opcode
Info

Description

A connection to the remote device bthAddr was rejected because it did not meet the minimum encryption key size requirement of requiredKeySize octets. The key size was actualKeySize octets.

Message #

A connection to the remote device %1 was rejected because it did not meet the minimum encryption key size requirement of %2 octets. The key size was %3 octets.

Fields #

NameDescription
bthAddr UInt64
requiredKeySize UInt8
actualKeySize UInt8

Provenance

ETW provider GUID 0602ecef-6381-4bc0-aeda-eb9bb919b276

Defined in bthport.sys, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB