Microsoft-Windows-CloudRestoreLauncher

EventTitleChannelSampleRule
1Error ErrorCode occurred.OperationalNN
2A backup operation has started.OperationalYN
3A backup operation has completed.OperationalYN
4A restore operation has started.OperationalNN
5A restore operation has completed.OperationalNN
6Invoking backup restore handler HandlerId at index HandlerIndex.OperationalNN
7Skipping backup restore handler HandlerId at index HandlerIndex.OperationalNN
8Configuration is using variant Variant with payload Payload.OperationalNN
9Manifest-based OperationMode operation failed to initialize with error …OperationalNN
10Manifest-based OperationMode operation processed a backup unit and returned …OperationalNN
11Manifest-based OperationMode operation failed to process a backup with error …OperationalNN
12The backup operation is associated with a file.OperationalNN
13The backup operation is associated with a file.OperationalNN
14The restore operation is associated with a file.OperationalNN
15The restore operation is associated with a file.OperationalNN
16Loaded cloud data for TypeName.OperationalNN
17Unable to load cloud data for TypeName.OperationalNN
18Saved cloud data for TypeName.OperationalNN
19Windows backup preferences settings Cloud store APIs Call Event.OperationalNN
20Windows backup preferences settings Cloud store APIs Data Event.OperationalNN
21Information Message.OperationalYN
22The backup operation is associated with contrast theme.OperationalNN
23The restore operation is associated with contrast theme.OperationalNN
24The restore operation is associated with contrast theme.OperationalNN
25The backup operation is associated with Date and time.OperationalNN
26The restore operation is associated with Date and time.OperationalNN
27Background ColorOperationalNN
28Position of the PictureOperationalNN
29Updated backup time in device profile ProfileId and sent to server transport for …OperationalNN
30Updated backup time in device profile ProfileId in local cache; transport not …OperationalNN
31Error ErrorCode occurred while attempting to update backup time in device …OperationalNN
32The backup operation is associated with personalization theme.OperationalNN
33The restore service identified PlaceholderCount placeholder tiles requiring …OperationalNN
34The restore service was resumed to monitor placeholders.OperationalNN
35Origin for OriginContext: Product AppIdOrProducCode with tile TileId was …OperationalNN
36The backup operation is associated with Secondary Accounts.OperationalNN
37The restore operation is associated with Secondary Accounts.OperationalNN
38The API data returned to backup associated with Secondary Accounts.OperationalNN
39Processing packaged products startedOperationalNN
40Processing packaged products stoppedOperationalNN
41Processing unpackaged products startedOperationalNN
42Processing unpackaged products stoppedOperationalNN
43Creating process CommandLine.OperationalNN
44Created process ProcessId.OperationalNN
45Process ProcessId exited.OperationalNN
46The restore operation is associated with personalization theme.OperationalNN
47The backup operation is associated with ColorSettings.OperationalNN
48The restore operation is associated with ColorSettings.OperationalNN
49An app restore operation has started.OperationalNN
50A app restore operation has completed.OperationalNN
51Consulting compat providers started.OperationalNN
52Consulting compat providers stopped.OperationalNN
53The backup operation is associated with Lunar Calendar Settings.OperationalNN
54The restore operation is associated with Lunar Calendar Settings.OperationalNN
55The backup operation is associated with Nightlight settings.OperationalNN
56The backup operation is associated with Nightlight settings.OperationalNN
57The restore operation is associated with Nightlight settings.OperationalNN
58The restore operation is associated with Nightlight settings.OperationalNN
59The restore operation is associated with Sound settings.OperationalNN
60The restore operation data, Associated with Sound settings.OperationalNN
61The backup operation is associated with Ink Pen Settings.OperationalNN
62The restore operation is associated with Ink Pen Settings.OperationalNN
63Ink Pen Setting Status.OperationalNN
64The backup operation is associated with Background Slideshow Settings.OperationalNN
65The restore operation is associated with Background Slideshow Settings.OperationalNN
66The restore operation Error, Associated with Sound settings.OperationalNN
67CPL Excluded Event Name, Associated with Sound settings.OperationalNN
68The backup operation is associated with Device settings.OperationalNN
69The restore operation is associated with Device settings.OperationalNN
70The backup operation is associated with Device settings.OperationalNN
71The restore operation is associated with Device settings.OperationalNN
72The Bond Schema Activity backup associated with Device settings restore …OperationalNN
73The Bond Schema Activity backup associated with Device settings backup opration.OperationalNN
74The Skipping operation is associated with Device settings.OperationalNN
75Taskbar Pins are prevented for All App placeholders with App IDsOperationalYN
76Error: Type; See event details for more information.OperationalYN
77The backup operation is associated with contrast theme.OperationalNN
78The restore operation is associated with contrast theme.OperationalNN
79The backup operation is associated with personalization theme.OperationalNN
80The restore operation is associated with personalization theme.OperationalNN
81Manifest-based OperationMode operation processed a backup unit and returned …OperationalNN
82Manifest-based OperationMode operation failed to process a backup with error …OperationalNN
83No changes detected in HandlerType since last backup.OperationalNN
84Backup functionality is currently disabled due to policy settings.OperationalYN
85Unable to restore the time zone from backup because the required ?OperationalNN
86The backup operation was skipped because the functionality is currently disabled …OperationalNN
87Event ID 87OperationalNN
88Event ID 88OperationalNN
89Event ID 89OperationalNN
90Event ID 90OperationalNN
91Event ID 91OperationalNN

Event ID 1: Error ErrorCode occurred.

#
Channel
Operational

Description

Error ErrorCode occurred. See event details for more information.

Message #

Error %2 occurred. See event details for more information.

Fields #

NameDescription
Type UInt32
ErrorCode UInt32
File AnsiString
LineNumber UInt32

Event ID 2: A backup operation has started.

#
Channel
Operational
Level
Informational

Description

A backup operation has started. See event details for more information.

Message #

A backup operation has started. See event details for more information.

Fields #

NameDescription
activityId GUID
cv AnsiString
Trigger UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CloudRestoreLauncher",
    "event_id": 2,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T16:17:04.4467055+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-CloudRestoreLauncher"
  },
  "event_data": {
    "activityId": "{ea44b186-cedf-0003-a2a8-54eadfcedc01}",
    "cv": "KFClce1PikGO8ObbbDX0oA.1.0",
    "Trigger": "0"
  }
}

Event ID 3: A backup operation has completed.

#
Channel
Operational
Level
Informational

Description

A backup operation has completed. See event details for more information.

Message #

A backup operation has completed. See event details for more information.

Fields #

NameDescription
activityId GUID
cv AnsiString
Trigger UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CloudRestoreLauncher",
    "event_id": 3,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T16:17:04.4561698+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-CloudRestoreLauncher"
  },
  "event_data": {
    "activityId": "{ea44b186-cedf-0003-a2a8-54eadfcedc01}",
    "cv": "KFClce1PikGO8ObbbDX0oA.1.0",
    "Trigger": "0"
  }
}

Event ID 4: A restore operation has started.

#
Channel
Operational

Description

A restore operation has started. See event details for more information.

Message #

A restore operation has started. See event details for more information.

Fields #

NameDescription
activityId GUID
cv AnsiString
Trigger UInt32

Event ID 5: A restore operation has completed.

#
Channel
Operational

Description

A restore operation has completed. See event details for more information.

Message #

A restore operation has completed. See event details for more information.

Fields #

NameDescription
activityId GUID
cv AnsiString
Trigger UInt32

Event ID 6: Invoking backup restore handler HandlerId at index HandlerIndex.

#
Channel
Operational

Message #

Invoking backup restore handler %2 at index %1.

Fields #

NameDescription
HandlerIndex UInt32
HandlerId UnicodeString

Event ID 7: Skipping backup restore handler HandlerId at index HandlerIndex.

#
Channel
Operational

Message #

Skipping backup restore handler %2 at index %1.

Fields #

NameDescription
HandlerIndex UInt32
HandlerId UnicodeString

Event ID 8: Configuration is using variant Variant with payload Payload.

#
Channel
Operational

Message #

Configuration is using variant %1 with payload %2.

Fields #

NameDescription
Variant UInt8
Payload UInt32

Event ID 9: Manifest-based OperationMode operation failed to initialize with error ErrorCode.

#
Channel
Operational

Description

Manifest-based OperationMode operation failed to initialize with error ErrorCode. See event details for more information.

Message #

Manifest-based %1 operation failed to initialize with error %2. See event details for more information.

Fields #

NameDescription
OperationMode UInt32
ErrorCode Int32

Event ID 10: Manifest-based OperationMode operation processed a backup unit and returned status StatusCode.

#
Channel
Operational

Description

Manifest-based OperationMode operation processed a backup unit and returned status StatusCode. See event details for more information.

Message #

Manifest-based %1 operation processed a backup unit and returned status %2. See event details for more information.

Fields #

NameDescription
OperationMode UInt32
StatusCode UInt32NTSTATUS reference
Context UInt32
ManifestId UnicodeString
Scope UnicodeString

Event ID 11: Manifest-based OperationMode operation failed to process a backup with error ErrorCode.

#
Channel
Operational

Description

Manifest-based OperationMode operation failed to process a backup with error ErrorCode. See event details for more information.

Message #

Manifest-based %1 operation failed to process a backup with error %2. See event details for more information.

Fields #

NameDescription
OperationMode UInt32
ErrorCode Int32
StatusCode UInt32NTSTATUS reference
Context UInt32
ManifestId UnicodeString
Scope UnicodeString

Event ID 12: The backup operation is associated with a file.

#
Channel
Operational

Description

The backup operation is associated with a file. See event details for more information.

Message #

The backup operation is associated with a file. See event details for more information.

Fields #

NameDescription
ItemId UnicodeString
ContentUri UnicodeString
SyncRootRelativePath UnicodeString

Event ID 13: The backup operation is associated with a file.

#
Channel
Operational

Description

The backup operation is associated with a file. See event details for more information.

Message #

The backup operation is associated with a file. See event details for more information.

Fields #

NameDescription
LocalPath UnicodeString

Event ID 14: The restore operation is associated with a file.

#
Channel
Operational

Description

The restore operation is associated with a file. See event details for more information.

Message #

The restore operation is associated with a file. See event details for more information.

Fields #

NameDescription
ItemId UnicodeString
ContentUri UnicodeString
SyncRootRelativePath UnicodeString

Event ID 15: The restore operation is associated with a file.

#
Channel
Operational

Description

The restore operation is associated with a file. See event details for more information.

Message #

The restore operation is associated with a file. See event details for more information.

Fields #

NameDescription
LocalPath UnicodeString

Event ID 16: Loaded cloud data for TypeName.

#
Channel
Operational

Description

Loaded cloud data for TypeName. See event details for more information.

Message #

Loaded cloud data for %1. See event details for more information.

Fields #

NameDescription
TypeName AnsiString
Version UInt64
IsDefault Boolean

Event ID 17: Unable to load cloud data for TypeName.

#
Channel
Operational

Description

Unable to load cloud data for TypeName. See event details for more information.

Message #

Unable to load cloud data for %1. See event details for more information.

Fields #

NameDescription
TypeName AnsiString
Version UInt64
IsDefault Boolean

Event ID 18: Saved cloud data for TypeName.

#
Channel
Operational

Description

Saved cloud data for TypeName. See event details for more information.

Message #

Saved cloud data for %1. See event details for more information.

Fields #

NameDescription
TypeName AnsiString
LoadedVersion UInt64
SavedVersion UInt64

Event ID 19: Windows backup preferences settings Cloud store APIs Call Event.

#
Channel
Operational

Description

Windows backup preferences settings Cloud store APIs Call Event. See event details for more information.

Message #

Windows backup preferences settings Cloud store APIs Call Event. See event details for more information.

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
PolicyName UnicodeString

Event ID 20: Windows backup preferences settings Cloud store APIs Data Event.

#
Channel
Operational

Description

Windows backup preferences settings Cloud store APIs Data Event. See event details for more information.

Message #

Windows backup preferences settings Cloud store APIs Data Event. See event details for more information.

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
PolicyName UnicodeString
CloudStorePolicyOption UnicodeString

Event ID 21: Information Message.

#
Channel
Operational
Level
Verbose

Description

Information Message. See event details for message details.

Message #

Information Message. See event details for message details

Fields #

NameDescription
HandlerType UnicodeString
Message UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CloudRestoreLauncher",
    "guid": "{DC327E90-7748-58ED-F39C-8A8987CFAC58}",
    "event_source_name": "",
    "event_id": 21,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-04-13T04:02:11.9587868+00:00",
    "event_record_id": 15,
    "correlation": {},
    "execution": {
      "process_id": 8528,
      "thread_id": 9012
    },
    "channel": "Microsoft-Windows-CloudRestoreLauncher/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
    }
  },
  "event_data": {
    "HandlerType": "Backup event",
    "Message": "Failed to get account type"
  },
  "message": "Information Message. See event details for message details"
}

Event ID 22: The backup operation is associated with contrast theme.

#
Channel
Operational

Description

The backup operation is associated with contrast theme. See event details for more information.

Message #

The backup operation is associated with contrast theme. See event details for more information.

Fields #

NameDescription
type UInt64
currentThemePath UnicodeString
contrastThemePath UnicodeString
baseContrastThemeName UnicodeString
customThemeName UnicodeString

Event ID 23: The restore operation is associated with contrast theme.

#
Channel
Operational

Description

The restore operation is associated with contrast theme. See event details for more information.

Message #

The restore operation is associated with contrast theme. See event details for more information.

Fields #

NameDescription
type UInt64
currentThemePath UnicodeString
contrastThemePath UnicodeString
baseContrastThemeName UnicodeString
customThemeName UnicodeString

Event ID 24: The restore operation is associated with contrast theme.

#
Channel
Operational

Description

The restore operation is associated with contrast theme. See event details for more information.

Message #

The restore operation is associated with contrast theme. See event details for more information.

Fields #

NameDescription
ContrastThemeLocalPath UnicodeString

Event ID 25: The backup operation is associated with Date and time.

#
Channel
Operational

Description

The backup operation is associated with Date and time. See event details for more information.

Message #

The backup operation is associated with Date and time. See event details for more information.

Fields #

NameDescription
isAutoTimeZoneEnabled UInt64
timezone UnicodeString

Event ID 26: The restore operation is associated with Date and time.

#
Channel
Operational

Description

The restore operation is associated with Date and time. See event details for more information.

Message #

The restore operation is associated with Date and time. See event details for more information.

Fields #

NameDescription
isAutoTimeZoneEnabled UInt64
timezone UnicodeString

Event ID 27: Background Color

#
Channel
Operational

Fields #

NameDescription
HandlerType UnicodeString
Red UInt8
Green UInt8
Blue UInt8

Event ID 28: Position of the Picture

#
Channel
Operational

Fields #

NameDescription
HandlerType UnicodeString
Position UInt64

Event ID 29: Updated backup time in device profile ProfileId and sent to server transport for delivery to cloud.

#
Channel
Operational

Message #

Updated backup time in device profile %1 and sent to server transport for delivery to cloud.

Fields #

NameDescription
ProfileId UnicodeString

Event ID 30: Updated backup time in device profile ProfileId in local cache; transport not available for delivery to cloud.

#
Channel
Operational

Message #

Updated backup time in device profile %1 in local cache; transport not available for delivery to cloud.

Fields #

NameDescription
ProfileId UnicodeString

Event ID 31: Error ErrorCode occurred while attempting to update backup time in device profile ProfileId.

#
Channel
Operational

Message #

Error %1 occurred while attempting to update backup time in device profile %2.

Fields #

NameDescription
ErrorCode Int32
ProfileId UnicodeString
Stage UInt8

Event ID 32: The backup operation is associated with personalization theme.

#
Channel
Operational

Description

The backup operation is associated with personalization theme. See event details for more information.

Message #

The backup operation is associated with personalization theme. See event details for more information.

Fields #

NameDescription
type UInt64
basePersonalizationThemeName UnicodeString

Event ID 33: The restore service identified PlaceholderCount placeholder tiles requiring replacement.

#
Channel
Operational

Message #

The restore service identified %1 placeholder tiles requiring replacement.

Fields #

NameDescription
PlaceholderCount UInt32

Event ID 34: The restore service was resumed to monitor placeholders.

#
Channel
Operational

Event ID 35: Origin for OriginContext: Product AppIdOrProducCode with tile TileId was RemoveKind with heuristic Heuristic and replaced by ReplacedByTileId.

#
Channel
Operational

Message #

%1 for %2: Product %3 with tile %4 was %5 with heuristic %6 and replaced by %7.

Fields #

NameDescription
Origin UInt32
OriginContext UnicodeString
AppIdOrProducCode UnicodeString
TileId UnicodeString
RemoveKind UInt32
Heuristic UInt32
ReplacedByTileId UnicodeString

Event ID 36: The backup operation is associated with Secondary Accounts.

#
Channel
Operational

Description

The backup operation is associated with Secondary Accounts. See event details for more information.

Message #

The backup operation is associated with Secondary Accounts. See event details for more information.

Fields #

NameDescription
accountName UnicodeString
safeCustomerID UnicodeString

Event ID 37: The restore operation is associated with Secondary Accounts.

#
Channel
Operational

Description

The restore operation is associated with Secondary Accounts. See event details for more information.

Message #

The restore operation is associated with Secondary Accounts. See event details for more information.

Fields #

NameDescription
accountName UnicodeString
safeCustomerID UnicodeString

Event ID 38: The API data returned to backup associated with Secondary Accounts.

#
Channel
Operational

Description

The API data returned to backup associated with Secondary Accounts. See event details for more information.

Message #

The API data returned to backup associated with Secondary Accounts. See event details for more information.

Fields #

NameDescription
propertyName UnicodeString
propertyValue UnicodeString

Event ID 39: Processing packaged products started

#
Channel
Operational

Event ID 40: Processing packaged products stopped

#
Channel
Operational

Event ID 41: Processing unpackaged products started

#
Channel
Operational

Event ID 42: Processing unpackaged products stopped

#
Channel
Operational

Event ID 43: Creating process CommandLine.

#
Channel
Operational

Message #

Creating process %1.

Fields #

NameDescription
CommandLine UnicodeString

Event ID 44: Created process ProcessId.

#
Channel
Operational

Message #

Created process %1.

Fields #

NameDescription
ProcessId UInt32

Event ID 45: Process ProcessId exited.

#
Channel
Operational

Message #

Process %1 exited.

Fields #

NameDescription
ProcessId UInt32

Event ID 46: The restore operation is associated with personalization theme.

#
Channel
Operational

Description

The restore operation is associated with personalization theme. See event details for more information.

Message #

The restore operation is associated with personalization theme. See event details for more information.

Fields #

NameDescription
type UInt64
basePersonalizationThemeName UnicodeString

Event ID 47: The backup operation is associated with ColorSettings.

#
Channel
Operational

Description

The backup operation is associated with ColorSettings. See event details for more information.

Message #

The backup operation is associated with ColorSettings. See event details for more information.

Fields #

NameDescription
AppColorMode UInt64
SystemColorMode UInt64
enableTransperency UInt64
colorPrevalnce UInt64
accentColorMode UInt64
dwmColorPrevalence UInt64
Red UInt8
Green UInt8
Blue UInt8

Event ID 48: The restore operation is associated with ColorSettings.

#
Channel
Operational

Description

The restore operation is associated with ColorSettings. See event details for more information.

Message #

The restore operation is associated with ColorSettings. See event details for more information.

Fields #

NameDescription
AppColorMode UInt64
SystemColorMode UInt64
enableTransperency UInt64
colorPrevalnce UInt64
accentColorMode UInt64
dwmColorPrevalence UInt64
Red UInt8
Green UInt8
Blue UInt8

Event ID 49: An app restore operation has started.

#
Channel
Operational

Event ID 50: A app restore operation has completed.

#
Channel
Operational

Event ID 51: Consulting compat providers started.

#
Channel
Operational

Event ID 52: Consulting compat providers stopped.

#
Channel
Operational

Description

Consulting compat providers stopped. Store returned: StoreResult; Appraiser returned: AppraiserResult.

Message #

Consulting compat providers stopped. Store returned: %1; Appraiser returned: %2

Fields #

NameDescription
StoreResult Int32
AppraiserResult Int32

Event ID 53: The backup operation is associated with Lunar Calendar Settings.

#
Channel
Operational

Description

The backup operation is associated with Lunar Calendar Settings. See event details for more information.

Message #

The backup operation is associated with Lunar Calendar Settings. See event details for more information.

Fields #

NameDescription
CalendarType UInt64

Event ID 54: The restore operation is associated with Lunar Calendar Settings.

#
Channel
Operational

Description

The restore operation is associated with Lunar Calendar Settings. See event details for more information.

Message #

The restore operation is associated with Lunar Calendar Settings. See event details for more information.

Fields #

NameDescription
CalendarType UInt64

Event ID 55: The backup operation is associated with Nightlight settings.

#
Channel
Operational

Description

The backup operation is associated with Nightlight settings. See event details for more information.

Message #

The backup operation is associated with Nightlight settings. See event details for more information.

Fields #

NameDescription
automaticOnSchedule UInt64
automaticOnSunset UInt64
manualScheduleBlueLightReductionOnHours UInt64
manualScheduleBlueLightReductionOffHours UInt64
targetColorTemperature UInt64
sunsetHours UInt64
sunriseHours UInt64
previewColorTemperatureChanges UInt64
darkMode UInt64

Event ID 56: The backup operation is associated with Nightlight settings.

#
Channel
Operational

Description

The backup operation is associated with Nightlight settings. See event details for more information.

Message #

The backup operation is associated with Nightlight settings. See event details for more information.

Fields #

NameDescription
state UInt64
source UInt64
isSupported UInt64

Event ID 57: The restore operation is associated with Nightlight settings.

#
Channel
Operational

Description

The restore operation is associated with Nightlight settings. See event details for more information.

Message #

The restore operation is associated with Nightlight settings. See event details for more information.

Fields #

NameDescription
automaticOnSchedule UInt64
automaticOnSunset UInt64
manualScheduleBlueLightReductionOnHours UInt64
manualScheduleBlueLightReductionOffHours UInt64
targetColorTemperature UInt64
sunsetHours UInt64
sunriseHours UInt64
previewColorTemperatureChanges UInt64
darkMode UInt64

Event ID 58: The restore operation is associated with Nightlight settings.

#
Channel
Operational

Description

The restore operation is associated with Nightlight settings. See event details for more information.

Message #

The restore operation is associated with Nightlight settings. See event details for more information.

Fields #

NameDescription
state UInt64
source UInt64
isSupported UInt64

Event ID 59: The restore operation is associated with Sound settings.

#
Channel
Operational

Description

The restore operation is associated with Sound settings. See event details for more information.

Message #

The restore operation is associated with Sound settings. See event details for more information.

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.

Event ID 60: The restore operation data, Associated with Sound settings.

#
Channel
Operational

Description

The restore operation data, Associated with Sound settings. See event details for more information.

Message #

The restore operation data, Associated with Sound settings. See event details for more information.

Fields #

NameDescription
CurrentSoundSchemeFile UnicodeString
DefaultSoundSchemeFile UnicodeString

Event ID 61: The backup operation is associated with Ink Pen Settings.

#
Channel
Operational

Description

The backup operation is associated with Ink Pen Settings. See event details for more information.

Message #

The backup operation is associated with Ink Pen Settings. See event details for more information.

Fields #

NameDescription
singleClickOverride UInt64
singleClickPenWorkspaceVerb UInt64
doubleClickOverride UInt64
doubleClickPenWorkspaceVerb UInt64
longPressOverride UInt64
longPressPenWorkspaceVerb UInt64
penWorkspaceAppLaunchOnPenDetachEnabled UInt64
penEnablePenButtonOverride UInt64
singleClickCustomAppPath UnicodeString
doubleClickCustomAppPath UnicodeString
longPressCustomAppPath UnicodeString
singleClickCustomAppID UnicodeString
doubleClickCustomAppID UnicodeString
longPressCustomAppID UnicodeString

Event ID 62: The restore operation is associated with Ink Pen Settings.

#
Channel
Operational

Description

The restore operation is associated with Ink Pen Settings. See event details for more information.

Message #

The restore operation is associated with Ink Pen Settings. See event details for more information.

Fields #

NameDescription
singleClickOverride UInt64
singleClickPenWorkspaceVerb UInt64
doubleClickOverride UInt64
doubleClickPenWorkspaceVerb UInt64
longPressOverride UInt64
longPressPenWorkspaceVerb UInt64
penWorkspaceAppLaunchOnPenDetachEnabled UInt64
penEnablePenButtonOverride UInt64
singleClickCustomAppPath UnicodeString
doubleClickCustomAppPath UnicodeString
longPressCustomAppPath UnicodeString
singleClickCustomAppID UnicodeString
doubleClickCustomAppID UnicodeString
longPressCustomAppID UnicodeString

Event ID 63: Ink Pen Setting Status.

#
Channel
Operational

Description

Ink Pen Setting Status. See event details for more information.

Message #

Ink Pen Setting Status. See event details for more information.

Fields #

NameDescription
Setting UnicodeString
Status UnicodeStringNTSTATUS reference

Event ID 64: The backup operation is associated with Background Slideshow Settings.

#
Channel
Operational

Description

The backup operation is associated with Background Slideshow Settings. See event details for more information.

Message #

The backup operation is associated with Background Slideshow Settings. See event details for more information.

Fields #

NameDescription
OneDrivefolder UInt64
Shuffle UInt64
TimeInMillSec UInt64

Event ID 65: The restore operation is associated with Background Slideshow Settings.

#
Channel
Operational

Description

The restore operation is associated with Background Slideshow Settings. See event details for more information.

Message #

The restore operation is associated with Background Slideshow Settings. See event details for more information.

Fields #

NameDescription
OneDrivefolder UInt64
Shuffle UInt64
TimeInMillSec UInt64

Event ID 66: The restore operation Error, Associated with Sound settings.

#
Channel
Operational

Description

The restore operation Error, Associated with Sound settings. See event details for more information.

Message #

The restore operation Error, Associated with Sound settings. See event details for more information.

Fields #

NameDescription
LogMessage UnicodeString
RegKeyPath UnicodeString
ErrorCode Int32

Event ID 67: CPL Excluded Event Name, Associated with Sound settings.

#
Channel
Operational

Description

CPL Excluded Event Name, Associated with Sound settings. See event details for more information.

Message #

CPL Excluded Event Name, Associated with Sound settings. See event details for more information.

Fields #

NameDescription
LogMessage UnicodeString
EventName UnicodeString

Event ID 68: The backup operation is associated with Device settings.

#
Channel
Operational

Description

The backup operation is associated with Device settings. See event details for more information.

Message #

The backup operation is associated with Device settings. See event details for more information.

Fields #

NameDescription
SettingName UnicodeString
SettingDataValue Boolean

Event ID 69: The restore operation is associated with Device settings.

#
Channel
Operational

Description

The restore operation is associated with Device settings. See event details for more information.

Message #

The restore operation is associated with Device settings. See event details for more information.

Fields #

NameDescription
SettingName UnicodeString
SettingDataValue Boolean

Event ID 70: The backup operation is associated with Device settings.

#
Channel
Operational

Description

The backup operation is associated with Device settings. See event details for more information.

Message #

The backup operation is associated with Device settings. See event details for more information.

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.

Event ID 71: The restore operation is associated with Device settings.

#
Channel
Operational

Description

The restore operation is associated with Device settings. See event details for more information.

Message #

The restore operation is associated with Device settings. See event details for more information.

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.

Event ID 72: The Bond Schema Activity backup associated with Device settings restore opration.

#
Channel
Operational

Description

The Bond Schema Activity backup associated with Device settings restore opration. See event details for more information.

Message #

The Bond Schema Activity backup associated with Device settings restore opration. See event details for more information.

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
LogMessage UnicodeString

Event ID 73: The Bond Schema Activity backup associated with Device settings backup opration.

#
Channel
Operational

Description

The Bond Schema Activity backup associated with Device settings backup opration. See event details for more information.

Message #

The Bond Schema Activity backup associated with Device settings backup opration. See event details for more information.

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
LogMessage UnicodeString

Event ID 74: The Skipping operation is associated with Device settings.

#
Channel
Operational

Description

The Skipping operation is associated with Device settings. See event details for more information.

Message #

The Skipping operation is associated with Device settings. See event details for more information.

Fields #

NameDescription
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
LogMessage UnicodeString

Event ID 75: Taskbar Pins are prevented for All App placeholders with App IDs

#
Channel
Operational
Level
Informational

Fields #

NameDescription
AppIDs UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CloudRestoreLauncher",
    "event_id": 75,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-18T01:46:57.9584544+00:00",
    "computer": "DESKTOP-FF3N5XK",
    "channel": "Microsoft-Windows-CloudRestoreLauncher"
  },
  "event_data": {
    "AppIDs": ""
  }
}

Event ID 76: Error: Type; See event details for more information.

#
Channel
Operational
Level
Error

Message #

Error: %2; See event details for more information.

Fields #

NameDescription
Type UInt32
ErrorCode Int32
File AnsiString
LineNumber UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CloudRestoreLauncher",
    "event_id": 76,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:01:17.7548926+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-CloudRestoreLauncher"
  },
  "event_data": {
    "ErrorCode": "-2147221231",
    "LineNumber": "171",
    "File": "pcshell\\shell\\cloudrestorelauncher\\dll\\dll.cpp",
    "Type": "1"
  }
}

Event ID 77: The backup operation is associated with contrast theme.

#
Channel
Operational

Description

The backup operation is associated with contrast theme. See event details for more information.

Message #

The backup operation is associated with contrast theme. See event details for more information.

Fields #

NameDescription
themeType UnicodeString
currentThemePath UnicodeString
contrastThemePath UnicodeString
baseContrastThemeName UnicodeString
customThemeName UnicodeString

Event ID 78: The restore operation is associated with contrast theme.

#
Channel
Operational

Description

The restore operation is associated with contrast theme. See event details for more information.

Message #

The restore operation is associated with contrast theme. See event details for more information.

Fields #

NameDescription
themeType UnicodeString
currentThemePath UnicodeString
contrastThemePath UnicodeString
baseContrastThemeName UnicodeString
customThemeName UnicodeString

Event ID 79: The backup operation is associated with personalization theme.

#
Channel
Operational

Description

The backup operation is associated with personalization theme. See event details for more information.

Message #

The backup operation is associated with personalization theme. See event details for more information.

Fields #

NameDescription
type UnicodeString
basePersonalizationThemeName UnicodeString

Event ID 80: The restore operation is associated with personalization theme.

#
Channel
Operational

Description

The restore operation is associated with personalization theme. See event details for more information.

Message #

The restore operation is associated with personalization theme. See event details for more information.

Fields #

NameDescription
type UnicodeString
basePersonalizationThemeName UnicodeString

Event ID 81: Manifest-based OperationMode operation processed a backup unit and returned status StatusCode.

#
Channel
Operational

Description

Manifest-based OperationMode operation processed a backup unit and returned status StatusCode. See event details for more information.

Message #

Manifest-based %1 operation processed a backup unit and returned status %2. See event details for more information.

Fields #

NameDescription
OperationMode UInt32
StatusCode UInt32NTSTATUS reference
Status UnicodeStringNTSTATUS reference
Context UInt32
ManifestId UnicodeString
Scope UnicodeString

Event ID 82: Manifest-based OperationMode operation failed to process a backup with error ErrorCode.

#
Channel
Operational

Description

Manifest-based OperationMode operation failed to process a backup with error ErrorCode. See event details for more information.

Message #

Manifest-based %1 operation failed to process a backup with error %2. See event details for more information.

Fields #

NameDescription
OperationMode UInt32
ErrorCode Int32
StatusCode UInt32NTSTATUS reference
Status UnicodeStringNTSTATUS reference
Context UInt32
ManifestId UnicodeString
Scope UnicodeString

Event ID 83: No changes detected in HandlerType since last backup.

#
Channel
Operational

Description

No changes detected in HandlerType since last backup. Skipping save operation.

Message #

No changes detected in %1 since last backup. Skipping save operation.

Fields #

NameDescription
HandlerType UnicodeString

Event ID 84: Backup functionality is currently disabled due to policy settings.

#
Channel
Operational
Level
Warning

Description

Backup functionality is currently disabled due to policy settings. For further assistance, please reach out to your administrator.

Message #

Backup functionality is currently disabled due to policy settings. For further assistance, please reach out to your administrator.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CloudRestoreLauncher",
    "event_id": 84,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T16:17:04.4561635+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-CloudRestoreLauncher"
  },
  "event_data": {}
}

Event ID 85: Unable to restore the time zone from backup because the required ?

#
Channel
Operational

Description

Unable to restore the time zone from backup because the required ?Change the time zone? permission is missing. For further assistance, please reach out to your administrator.

Message #

Unable to restore the time zone from backup because the required ?Change the time zone? permission is missing. For further assistance, please reach out to your administrator.

Event ID 86: The backup operation was skipped because the functionality is currently disabled due to policy settings.

#
Channel
Operational

Description

The backup operation was skipped because the functionality is currently disabled due to policy settings. For further assistance, please reach out to your administrator.

Message #

The backup operation was skipped because the functionality is currently disabled due to policy settings. For further assistance, please reach out to your administrator.

Fields #

NameDescription
activityId GUID
cv AnsiString
Trigger UInt32

Event ID 87

#
Channel
Operational

Event ID 88

#
Channel
Operational

Fields #

NameDescription
OperationStatus UInt32NTSTATUS reference

Event ID 89

#
Channel
Operational

Fields #

NameDescription
Result Boolean

Event ID 90

#
Channel
Operational

Fields #

NameDescription
Operation UInt32
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
PolicyName UnicodeString

Event ID 91

#
Channel
Operational

Fields #

NameDescription
Operation UInt32
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
PolicyName UnicodeString
CloudStorePolicyOption UnicodeString

Provenance

ETW provider GUID dc327e90-7748-58ed-f39c-8a8987cfac58

Defined in CloudRestoreLauncher.dll, which carries the event manifest.

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4202, captured 2026-06-02 — Manifest XML pack, 2.0 MB