Microsoft-Windows-Devices-AccessBroker
15 events across 1 channel
Event ID 100: ClientFileName (pid = ClientPid) successfully accessed InterfacePath.
#Event ID 101: ClientFileName (pid = ClientPid) successfully accessed InterfacePath, the device interface class is unrestricted and allows access for LPAC apps.
#Event ID 102: ClientFileName (pid = ClientPid) successfully accessed InterfacePath, the device interface class is unrestricted.
#Event ID 103: ClientFileName (pid = ClientPid) successfully accessed InterfacePath, the app is granted unrestricted access based on its capabilities.
#Event ID 104: ClientFileName (pid = ClientPid) successfully accessed InterfacePath, the device container grants this app unrestricted access.
#Event ID 105: ClientFileName (pid = ClientPid) successfully accessed InterfacePath, the system is in embedded mode and the app has the low level devices capability.
#Event ID 200: ClientFileName (pid = ClientPid) failed to access InterfacePath (error = Error).
#Event ID 201: ClientFileName (pid = ClientPid) failed to access InterfacePath, the user cannot access the device (error = Error).
#Event ID 202: ClientFileName (pid = ClientPid) failed to access InterfacePath, the interface class is unrestricted but does not allow LPAC apps access (error = Error).
#Event ID 203: ClientFileName (pid = ClientPid) failed to access InterfacePath, the interface class is restricted and the app is LPAC (error = Error).
#Event ID 204: ClientFileName (pid = ClientPid) failed to access InterfacePath, the interface class is custom and nothing gives the app access (error = Error).
#Event ID 205: ClientFileName (pid = ClientPid) failed to access InterfacePath, the interface class is restricted by policy (error = Error).
#Event ID 206: ClientFileName (pid = ClientPid) failed to access InterfacePath, the interface instance is restricted (error = Error).
#Event ID 207: ClientFileName (pid = ClientPid) failed to access InterfacePath, the interface class does not allow raw handles to the device (error = Error).
#Event ID 208: ClientFileName (pid = ClientPid) failed to access InterfacePath, the capability access check was denied (error = Error).
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 64fb8d23-f0b6-5d2d-b1f6-488303c1761f
Defined in deviceaccess.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02