Microsoft-Windows-DistributedCOM

69 events across 2 channels

EventTitleChannelSample
10000Unable to start a DCOM Server: param3.OperationalN
10001Unable to start a DCOM Server: param3 as param4/param5.OperationalN
10002Access denied attempting to launch a DCOM ServerOperationalN
10003Access denied attempting to launch a DCOM Server using DefaultLaunchPermssionOperationalN
10004DCOM got error "param1" and was unable to logon param2\param3 in order to run …OperationalN
10005DCOM got error "param1" attempting to start the service param2 with arguments …OperationalN
10005DCOM got error "param1" attempting to start the service param2 with arguments …SystemY
10006DCOM got error "param1" from the computer param2 when attempting to activate the …OperationalY
10007DCOM got error "param1" when attempting to activate the server:OperationalN
10008DCOM got error "param1" from the computer param2 when attempting to the server.OperationalY
10009DCOM was unable to communicate with the computer param1 using any of the …OperationalN
10010The server param1 did not register with DCOM within the required timeout.OperationalY
10010The server param1 did not register with DCOM within the required timeoutSystemY
10011The server param1 could not be contacted to establish the connection to the …OperationalN
10012There is an assertion failure in DCOMOperationalN
10014The activation for CLSID param1 failed because remote activations for COM+ are …OperationalN
10015The machine wide limit settings do not grant param1 param2 permission for the …OperationalN
10016The param1 permission settings do not grant param2 param3 permission for the COM …OperationalY
10016The param1 permission settings do not grant param2 param3 permission for the COM …SystemY
10017The param1 permission settings do not grant param2 access permission to the COM …OperationalN
10018The application-specific permission settings do not grant param1 access …OperationalN
10019The machine wide limit settings do not grant param1 access permission to the COM …OperationalN
10020The machine wide param1 param2 security descriptor is invalid.OperationalN
10021The launch and activation security descriptor for the COM Server application …OperationalN
10022The param1 access security descriptor for the COM Server application param2 with …OperationalN
10023The application-specific access security descriptor for the COM Server …OperationalN
10024The machine wide group policy param1 Limits security descriptor is invalid.OperationalN
10026The COM sub system is suppressing duplicate event log entries for a duration of …OperationalN
10027The machine wide limit settings do not grant param1 param2 permission for COM …OperationalN
10028DCOM was unable to communicate with the computer param1 using any of the …OperationalY
10028DCOM was unable to communicate with the computer param1 using any of the …SystemY
10029The activation of the CLSID param1 timed out waiting for the service param2 to …OperationalN
10030Unable to start a COM Server for debugging: param3.OperationalN
10031An unmarshaling policy check was performed when unmarshaling a custom marshaled …OperationalN
10032An unmarshaling policy check was performed when unmarshaling a custom inproc …OperationalN
10033An unmarshaling policy check was performed when unmarshaling a COM+ envoy …OperationalN
10034An unmarshaling policy check was performed due to CLSCTX_NO_CUSTOM_MARSHAL and …OperationalN
10035The COM standard marshaler was unable to fix a mismatch between the IID …OperationalN
10036The server-side authentication level policy does not allow the user …OperationalN
10037Application ApplicationName with PID PID is requesting to activate CLSID CLSID …OperationalN
10038Application ApplicationName with PID PID is requesting to activate CLSID CLSID …OperationalN
1073751850The COM sub system is suppressing duplicate event log entries for a duration of …OperationalN
3221235472Unable to start a DCOM Server: {param3}.OperationalN
3221235473Unable to start a DCOM Server: {param3} as {param4}/{param5}.OperationalN
3221235474Access denied attempting to launch a DCOM Server.OperationalN
3221235475Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion.OperationalN
3221235476DCOM got error '{param1}' and was unable to logon {param2}\{param3} in order to …OperationalN
3221235477DCOM got error '{param1}' attempting to start the service {param2} with …OperationalN
3221235478DCOM got error '{param1}' from the computer {param2} when attempting to activate …OperationalN
3221235479DCOM got error "param1" when attempting to activate the server: param2.OperationalN
3221235480DCOM got error '{param1}' from the computer {param2} when attempting to the …OperationalN
3221235481DCOM was unable to communicate with the computer param1 using any of the …OperationalN
3221235482The server {param1} did not register with DCOM within the required timeout.OperationalY
3221235483The server param1 could not be contacted to establish the connection to the …OperationalN
3221235484There is an assertion failure in DCOM.OperationalN
3221235486The activation for CLSID {param1} failed because remote activations for COM+ are …OperationalN
3221235487The machine wide limit settings do not grant {param1} {param2} permission for …OperationalN
3221235488The {param1} permission settings do not grant {param2} {param3} permission for …OperationalY
3221235489The {param1} permission settings do not grant {param2} access permission to the …OperationalN
3221235490The application-specific permission settings do not grant {param1} access …OperationalN
3221235491The machine wide limit settings do not grant {param1} access permission to the …OperationalN
3221235492The machine wide {param1} {param2} security descriptor is invalid.OperationalN
3221235493The launch and activation security descriptor for the COM Server application …OperationalN
3221235494The {param1} access security descriptor for the COM Server application {param2} …OperationalN
3221235495The application-specific access security descriptor for the COM Server …OperationalN
3221235496The machine wide group policy {param1} Limits security descriptor is invalid.OperationalN
3221235499The machine wide limit settings do not grant {param1} {param2} permission for …OperationalN
3221235501DCOM started the service {param1} with arguments '{param2}' in order to run the …OperationalN
3221235507The COM standard marshaler was unable to fix a mismatch between the IID …OperationalN

Event ID 10000: Unable to start a DCOM Server: param3.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

Unable to start a DCOM Server: param3. The error.

Message #

Unable to start a DCOM Server: %3. The error:
"%2"
Happened while starting this command:
%1

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 10001: Unable to start a DCOM Server: param3 as param4/param5.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

Unable to start a DCOM Server: param3 as param4/param5. The error.

Message #

Unable to start a DCOM Server: %3 as %4/%5. The error:
"%2"
Happened while starting this command:
%1

Fields #

NameDescriptionRules
param1 UnicodeString1 detection rule
param2 UnicodeString1 detection rule
param3 UnicodeString1 detection rule
param4 UnicodeString
param5 UnicodeString

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

Event ID 10002: Access denied attempting to launch a DCOM Server

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 10003: Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 10004: DCOM got error "param1" and was unable to logon param2\param3 in order to run the server: param4.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

DCOM got error "param1" and was unable to logon param2\param3 in order to run the server.

Message #

DCOM got error "%1" and was unable to logon %2\%3 in order to run the server:
%4

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 10005: DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server: param4.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server.

Message #

DCOM got error "%1" attempting to start the service %2 with arguments "%3" in order to run the server:
%4

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 10005: DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server:

#
Provider
Microsoft-Windows-DistributedCOM
Channel
System
Level
Error

Description

DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server.

Message #

DCOM got error "%1" attempting to start the service %2 with arguments "%3" in order to run the server: %4

Fields #

NameDescription
param1
param2
param3
param4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "",
    "event_id": 10005,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-06-13T05:14:37.1593618+00:00",
    "event_record_id": 2166,
    "correlation": {
      "ActivityID": "{D57A5142-FAF2-0002-275B-7AD5F2FADC01}"
    },
    "execution": {
      "process_id": 660,
      "thread_id": 772
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "param1": "1053",
    "param2": "GoogleUpdaterService150.0.7863.0",
    "param3": "--com-service",
    "param4": "{8018F647-BF07-55BB-82BE-A2D7049F7CE4}"
  },
  "message": "DCOM got error \"1053\" attempting to start the service GoogleUpdaterService150.0.7863.0 with arguments \"--com-service\" in order to run the server:\r\n{8018F647-BF07-55BB-82BE-A2D7049F7CE4}"
}

Event ID 10006: DCOM got error "param1" from the computer param2 when attempting to activate the server: param3.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational
Level
Error

Description

DCOM got error "param1" from the computer param2 when attempting to activate the server.

Message #

DCOM got error "%1" from the computer %2 when attempting to activate the server:
%3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "",
    "event_id": 10006,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-04-16T22:13:33.9914282+00:00",
    "event_record_id": 5408,
    "correlation": {
      "ActivityID": "{AEA85543-92F4-4400-9B1C-03900CE328AA}"
    },
    "execution": {
      "process_id": 1360,
      "thread_id": 20244
    },
    "channel": "System",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "2148007941",
    "param2": "DESKTOP-A8D4L1Z",
    "param3": "{38FE8DFE-B129-452B-A215-119382B89E3D}"
  },
  "message": "DCOM got error \"2148007941\" from the computer DESKTOP-A8D4L1Z when attempting to activate the server:\r\n{38FE8DFE-B129-452B-A215-119382B89E3D}"
}

Event ID 10007: DCOM got error "param1" when attempting to activate the server:

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 10008: DCOM got error "param1" from the computer param2 when attempting to the server.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational
Level
Error

Description

DCOM got error "param1" from the computer param2 when attempting to the server.

Message #

DCOM got error "%1" from the computer %2 when attempting to the server:
%3 with file %4.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "",
    "event_id": 10008,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-04-16T22:36:00.7542779+00:00",
    "event_record_id": 5417,
    "correlation": {
      "ActivityID": "{921232B8-4EE8-402A-A3DA-B0729FF4991D}"
    },
    "execution": {
      "process_id": 1360,
      "thread_id": 7504
    },
    "channel": "System",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "2148007941",
    "param2": "DESKTOP-A8D4L1Z",
    "param3": "{38FE8DFE-B129-452B-A215-119382B89E3D}",
    "param4": "hello.stg"
  },
  "message": "DCOM got error \"2148007941\" from the computer DESKTOP-A8D4L1Z when attempting to the server:\r\n{38FE8DFE-B129-452B-A215-119382B89E3D} with file hello.stg."
}

Event ID 10009: DCOM was unable to communicate with the computer param1 using any of the configured protocols

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
__binLength UInt32
binary Binary

Event ID 10010: The server param1 did not register with DCOM within the required timeout.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The server param1 did not register with DCOM within the required timeout.

Message #

The server %1 did not register with DCOM within the required timeout.

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "event_id": 10010,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-16T20:35:38.5502237+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param1": "{38FE8DFE-B129-452B-A215-119382B89E3D}"
  }
}

Event ID 10010: The server param1 did not register with DCOM within the required timeout

#
Provider
Microsoft-Windows-DistributedCOM
Channel
System
Level
Error

Description

The server did not register with DCOM within the required timeout.

Message #

The server %1 did not register with DCOM within the required timeout.

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "",
    "event_id": 10010,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-06-13T05:12:05.5699142+00:00",
    "event_record_id": 2143,
    "correlation": {
      "ActivityID": "{D57A5142-FAF2-0001-8355-7AD5F2FADC01}"
    },
    "execution": {
      "process_id": 1048,
      "thread_id": 1084
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "param1": "{8018F647-BF07-55BB-82BE-A2D7049F7CE4}"
  },
  "message": "The server {8018F647-BF07-55BB-82BE-A2D7049F7CE4} did not register with DCOM within the required timeout."
}

Event ID 10011: The server param1 could not be contacted to establish the connection to the client

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 10012: There is an assertion failure in DCOM

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 10014: The activation for CLSID param1 failed because remote activations for COM+ are disabled.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The activation for CLSID param1 failed because remote activations for COM+ are disabled. To enable this functionality use Server Manager to install the COM+ Network Access feature in the Application Server role.

Message #

The activation for CLSID %1 failed because remote activations for COM+ are disabled. To enable this functionality use Server Manager to install the COM+ Network Access feature in the Application Server role.

Fields #

NameDescription
param1 UnicodeString

Event ID 10015: The machine wide limit settings do not grant param1 param2 permission for the COM Server application with CLSID.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The machine wide limit settings do not grant param1 param2 permission for the COM Server application with CLSID.

Message #

The machine wide limit settings do not grant %1 %2 permission for the COM Server application with CLSID 
%3
 and APPID 
%4
 to the user %5\%6 SID (%7) from address %8 running in the application container %9 SID (%10). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString
param10 UnicodeString

Event ID 10016: The param1 permission settings do not grant param2 param3 permission for the COM Server application with CLSID.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The param1 permission settings do not grant param2 param3 permission for the COM Server application with CLSID.

Message #

The %1 permission settings do not grant %2 %3 permission for the COM Server application with CLSID 
%4
 and APPID 
%5
 to the user %6\%7 SID (%8) from address %9 running in the application container %10 SID (%11). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString
param10 UnicodeString
param11 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "event_id": 10016,
    "level": "Warning",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-24T02:14:10.9499544+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param5": "{BDBED08B-7FB7-4EEA-AFD0-53DE534CB638}",
    "param8": "S-1-5-21-1006758700-2167138679-1475694448-1000",
    "param3": "Activation",
    "param6": "ludus",
    "param1": "application-specific",
    "param4": "{0DC1AB8B-A52D-4BA8-BD76-E2819386FB2F}",
    "param7": "localuser",
    "param11": "Unavailable",
    "param9": "LocalHost (Using LRPC)",
    "param10": "Unavailable",
    "param2": "Local"
  }
}

Event ID 10016: The param1 permission settings do not grant param2 param3 permission for the COM Server application with CLSID

#
Provider
Microsoft-Windows-DistributedCOM
Channel
System
Level
Warning

Description

The permission settings do not grant permission for the COM Server application with CLSID.

Message #

The %1 permission settings do not grant %2 %3 permission for the COM Server application with CLSID  %4  and APPID  %5  to the user %6\%7 SID (%8) from address %9 running in the application container %10 SID (%11). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7
param8
param9
param10
param11

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "",
    "event_id": 10016,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-05-29T16:33:58.8709146+00:00",
    "event_record_id": 6816,
    "correlation": {
      "ActivityID": "{BE1132E7-6849-4B6C-8578-E3BE57A71713}"
    },
    "execution": {
      "process_id": 848,
      "thread_id": 1484
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "application-specific",
    "param2": "Local",
    "param3": "Launch",
    "param4": "{21B896BF-008D-4D01-A27B-26061B960DD7}",
    "param5": "{03E09F3B-DCE4-44FE-A9CF-82D050827E1C}",
    "param6": "cell-a",
    "param7": "domainadmin",
    "param8": "S-1-5-21-1006758700-2167138679-1475694448-1105",
    "param9": "LocalHost (Using LRPC)",
    "param10": "Unavailable",
    "param11": "Unavailable"
  },
  "message": "The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID \r\n{21B896BF-008D-4D01-A27B-26061B960DD7}\r\n and APPID \r\n{03E09F3B-DCE4-44FE-A9CF-82D050827E1C}\r\n to the user cell-a\\domainadmin SID (S-1-5-21-1006758700-2167138679-1475694448-1105) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
}

Event ID 10017: The param1 permission settings do not grant param2 access permission to the COM Server application param3 with APPID.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The param1 permission settings do not grant param2 access permission to the COM Server application param3 with APPID.

Message #

The %1 permission settings do not grant %2 access permission to the COM Server application %3 with APPID 
%4
 to the user %5\%6 SID (%7) from address %8 running in the application container %9 SID (%10). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString
param10 UnicodeString

Event ID 10018: The application-specific permission settings do not grant param1 access permission to the COM Server application param2 with APPID.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The application-specific permission settings do not grant param1 access permission to the COM Server application param2 with APPID.

Message #

The application-specific permission settings do not grant %1 access permission to the COM Server application %2 with APPID 
%3
 to the user %4\%5 SID (%6) from address %7 running in the application container %8 SID (%9). The application set this security permission programmatically; to modify this security permission contact the application vendor.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString

Event ID 10019: The machine wide limit settings do not grant param1 access permission to the COM Server application param2 with APPID.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The machine wide limit settings do not grant param1 access permission to the COM Server application param2 with APPID.

Message #

The machine wide limit settings do not grant %1 access permission to the COM Server application %2 with APPID 
%3
 to the user %4\%5 SID (%6) from address %7 running in the application container %8 SID (%9). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString

Event ID 10020: The machine wide param1 param2 security descriptor is invalid.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The machine wide param1 param2 security descriptor is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Message #

The machine wide %1 %2 security descriptor is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 10021: The launch and activation security descriptor for the COM Server application with APPID.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The launch and activation security descriptor for the COM Server application with APPID.

Message #

The launch and activation security descriptor for the COM Server application with APPID 
%1
 is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString

Event ID 10022: The param1 access security descriptor for the COM Server application param2 with APPID.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The param1 access security descriptor for the COM Server application param2 with APPID.

Message #

The %1 access security descriptor for the COM Server application %2 with APPID 
%3
 is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 10023: The application-specific access security descriptor for the COM Server application param1 with APPID.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The application-specific access security descriptor for the COM Server application param1 with APPID.

Message #

The application-specific access security descriptor for the COM Server application %1 with APPID 
%2
 is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed.  The application set this security permission programmatically; to modify this security permission contact the application vendor.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 10024: The machine wide group policy param1 Limits security descriptor is invalid.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The machine wide group policy param1 Limits security descriptor is invalid. The security descriptor is defined as an invalid Security Descriptor Definitions Language (SDDL) string. The requested action was therefore not performed. Please contact your administrator to get the security descriptor corrected in the Group Policy settings.

Message #

The machine wide group policy %1 Limits security descriptor is invalid. The security descriptor is defined as an invalid Security Descriptor Definitions Language (SDDL) string. The requested action was therefore not performed. Please contact your administrator to get the security descriptor corrected in the Group Policy settings.

Fields #

NameDescription
param1 UnicodeString

Event ID 10026: The COM sub system is suppressing duplicate event log entries for a duration of param1 seconds

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 10027: The machine wide limit settings do not grant param1 param2 permission for COM Server applications to the user param3\param4 SID (param5) from address param6 running in the...

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The machine wide limit settings do not grant param1 param2 permission for COM Server applications to the user param3\param4 SID (param5) from address param6 running in the application container param7 SID (param8). This security permission can be modified using the Component Services administrative tool.

Message #

The machine wide limit settings do not grant %1 %2 permission for COM Server applications to the user %3\%4 SID (%5) from address %6 running in the application container %7 SID (%8). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString

Event ID 10028: DCOM was unable to communicate with the computer param1 using any of the configured protocols; requested by PID param2 (param3), while activating CLSID param4.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

DCOM was unable to communicate with the computer param1 using any of the configured protocols; requested by PID param2 (param3), while activating CLSID param4.

Message #

DCOM was unable to communicate with the computer %1 using any of the configured protocols; requested by PID %2 (%3), while activating CLSID %4.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
__binLength UInt32
binary Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "event_id": 10028,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-03-15T05:14:36.9508994+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param4": "{8BC3F05E-D86B-11D0-A075-00C04FB68820}",
    "param2": "    28e0",
    "param1": "JD-WIN11-22H2-1",
    "param3": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"
  }
}

Event ID 10028: DCOM was unable to communicate with the computer param1 using any of the configured protocols; requested by PID param2 (param3), while activating CLSID

#
Provider
Microsoft-Windows-DistributedCOM
Channel
System
Level
Error

Description

DCOM was unable to communicate with the computer using any of the configured protocols; requested by PID (), while activating CLSID .

Message #

DCOM was unable to communicate with the computer %1 using any of the configured protocols; requested by PID %2 (%3), while activating CLSID %4.

Fields #

NameDescription
param1
param2
param3
param4
__binLength
binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "DCOM",
    "event_id": 10028,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9259400833873739776,
    "time_created": "2026-03-13T23:06:00.558843+00:00",
    "event_record_id": 12279,
    "correlation": {
      "ActivityID": "2A8C090C-ABB5-42FC-ABDE-C1146B129851"
    },
    "execution": {
      "process_id": 1212,
      "thread_id": 6732
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "DC1",
    "param2": "    287c",
    "param3": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
    "param4": "{8BC3F05E-D86B-11D0-A075-00C04FB68820}",
    "Binary": "3C5265636F726423313A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D323B4465746C6F633D313731303B466C6167733D303B506172616D733D313B7B506172616D23303A307D3E3C5265636F726423323A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D31383B4465746C6F633D313434323B466C6167733D303B506172616D733D313B7B506172616D23303A4443317D3E3C5265636F726423333A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D31383B4465746C6F633D3332323B466C6167733D303B506172616D733D303B3E3C5265636F726423343A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D31313030313B47656E636F6D703D31383B4465746C6F633D3332303B466C6167733D303B506172616D733D313B7B506172616D23303A4443317D3E"
  },
  "message": ""
}

Event ID 10029: The activation of the CLSID param1 timed out waiting for the service param2 to stop.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The activation of the CLSID param1 timed out waiting for the service param2 to stop.

Message #

The activation of the CLSID %1 timed out waiting for the service %2 to stop.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 10030: Unable to start a COM Server for debugging: param3.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

Unable to start a COM Server for debugging: param3. The error.

Message #

Unable to start a COM Server for debugging: %3. The error:
"%2"
Happened while starting this command:
%1

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 10031: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class param1 was rejected.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class param1 was rejected.

Message #

An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class %1 was rejected

Fields #

NameDescription
param1 UnicodeString

Event ID 10032: An unmarshaling policy check was performed when unmarshaling a custom inproc handler and the class param1 was rejected.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

An unmarshaling policy check was performed when unmarshaling a custom inproc handler and the class param1 was rejected.

Message #

An unmarshaling policy check was performed when unmarshaling a custom inproc handler and the class %1 was rejected

Fields #

NameDescription
param1 UnicodeString

Event ID 10033: An unmarshaling policy check was performed when unmarshaling a COM+ envoy context property and the class param1 was rejected.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

An unmarshaling policy check was performed when unmarshaling a COM+ envoy context property and the class param1 was rejected.

Message #

An unmarshaling policy check was performed when unmarshaling a COM+ envoy context property and the class %1 was rejected

Fields #

NameDescription
param1 UnicodeString

Event ID 10034: An unmarshaling policy check was performed due to CLSCTX_NO_CUSTOM_MARSHAL and the class param1 was rejected.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

An unmarshaling policy check was performed due to CLSCTX_NO_CUSTOM_MARSHAL and the class param1 was rejected.

Message #

An unmarshaling policy check was performed due to CLSCTX_NO_CUSTOM_MARSHAL and the class %1 was rejected

Fields #

NameDescription
param1 UnicodeString

Event ID 10035: The COM standard marshaler was unable to fix a mismatch between the IID ProvidedIid provided by the server and the IID RequestedIid requested by the client, with hand...

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The COM standard marshaler was unable to fix a mismatch between the IID ProvidedIid provided by the server and the IID RequestedIid requested by the client, with handler CLSID HandlerClsid. The error code was HRESULT.

Message #

The COM standard marshaler was unable to fix a mismatch between the IID %1 provided by the server and the IID %2 requested by the client, with handler CLSID %3. The error code was %4.

Fields #

NameDescription
ProvidedIid UnicodeString
RequestedIid UnicodeString
HandlerClsid UnicodeString
HRESULT UnicodeString

Event ID 10036: The server-side authentication level policy does not allow the user DomainName\UserName SID (SID) from address ClientIPAddress to activate DCOM server.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The server-side authentication level policy does not allow the user DomainName\UserName SID (SID) from address ClientIPAddress to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.

Message #

The server-side authentication level policy does not allow the user %1\%2 SID (%3) from address %4 to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.

Fields #

NameDescription
DomainName UnicodeString
UserName UnicodeString
SID UnicodeString
ClientIPAddress UnicodeString

Event ID 10037: Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with explicitly set authentication level at ActivationAuthenticationLevel.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with explicitly set authentication level at ActivationAuthenticationLevel. The lowest activation authentication level required by DCOM is 5(RPC_C_AUTHN_LEVEL_PKT_INTEGRITY). To raise the activation authentication level, please contact the application vendor.

Message #

Application %1 with PID %2 is requesting to activate CLSID %3 on computer %4 with explicitly set authentication level at %5. The lowest activation authentication level required by DCOM is 5(RPC_C_AUTHN_LEVEL_PKT_INTEGRITY). To raise the activation authentication level, please contact the application vendor.

Fields #

NameDescription
ApplicationName UnicodeString
PID UnicodeString
CLSID UnicodeString
ComputerName UnicodeString
ActivationAuthenticationLevel UnicodeString

Event ID 10038: Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with default activation authentication level at ActivationAuthenticationLevel.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with default activation authentication level at ActivationAuthenticationLevel. The lowest activation authentication level required by DCOM is 5(RPC_C_AUTHN_LEVEL_PKT_INTEGRITY). To raise the activation authentication level, please contact the application vendor.

Message #

Application %1 with PID %2 is requesting to activate CLSID %3 on computer %4 with default activation authentication level at %5. The lowest activation authentication level required by DCOM is 5(RPC_C_AUTHN_LEVEL_PKT_INTEGRITY). To raise the activation authentication level, please contact the application vendor.

Fields #

NameDescription
ApplicationName UnicodeString
PID UnicodeString
CLSID UnicodeString
ComputerName UnicodeString
ActivationAuthenticationLevel UnicodeString

Event ID 1073751850: The COM sub system is suppressing duplicate event log entries for a duration of param1 seconds.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The COM sub system is suppressing duplicate event log entries for a duration of seconds. The suppression timeout can be controlled by a REG_DWORD value named under the following registry key: HKLM\.

Message #

The COM sub system is suppressing duplicate event log entries for a duration of %1 seconds.  The suppression timeout can be controlled by a REG_DWORD value named %2 under the following registry key: HKLM\%3.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 3221235472: Unable to start a DCOM Server: {param3}.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

Unable to start a DCOM Server: {param3}. The error:'{param2}'Happened while starting this command:{param1}.

Message #

Unable to start a DCOM Server: {param3}. The error:'{param2}'Happened while starting this command:{param1}

Fields #

NameDescription
param3
param2
param1

Event ID 3221235473: Unable to start a DCOM Server: {param3} as {param4}/{param5}.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

Unable to start a DCOM Server: {param3} as {param4}/{param5}. The error:'{param2}'Happened while starting this command:{param1}.

Message #

Unable to start a DCOM Server: {param3} as {param4}/{param5}. The error:'{param2}'Happened while starting this command:{param1}

Fields #

NameDescription
param3
param4
param5
param2
param1

Event ID 3221235474: Access denied attempting to launch a DCOM Server.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

Access denied attempting to launch a DCOM Server. The server is.

Message #

Access denied attempting to launch a DCOM Server. The server is:
%1
The user is %2/%3, SID=%4.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 3221235475: Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion. The server is.

Message #

Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion. The server is:
%1
The user is %2/%3, SID=%4.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 3221235476: DCOM got error '{param1}' and was unable to logon {param2}\{param3} in order to run the server:{param4}.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

DCOM got error '{param1}' and was unable to logon {param2}\{param3} in order to run the server:{param4}.

Message #

DCOM got error '{param1}' and was unable to logon {param2}\{param3} in order to run the server:{param4}

Fields #

NameDescription
param1
param2
param3
param4

Event ID 3221235477: DCOM got error '{param1}' attempting to start the service {param2} with arguments '{param3}' in order to run the server:{param4}.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

DCOM got error '{param1}' attempting to start the service {param2} with arguments '{param3}' in order to run the server:{param4}.

Message #

DCOM got error '{param1}' attempting to start the service {param2} with arguments '{param3}' in order to run the server:{param4}

Fields #

NameDescription
param1
param2
param3
param4

Event ID 3221235478: DCOM got error '{param1}' from the computer {param2} when attempting to activate the server:{param3}.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

DCOM got error '{param1}' from the computer {param2} when attempting to activate the server:{param3}.

Message #

DCOM got error '{param1}' from the computer {param2} when attempting to activate the server:{param3}

Fields #

NameDescription
param1
param2
param3

Event ID 3221235479: DCOM got error "param1" when attempting to activate the server: param2.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

DCOM got error "param1" when attempting to activate the server.

Message #

DCOM got error "%1" when attempting to activate the server:
%2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 3221235480: DCOM got error '{param1}' from the computer {param2} when attempting to the server:{param3} with file {param4}.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

DCOM got error '{param1}' from the computer {param2} when attempting to the server:{param3} with file {param4}.

Message #

DCOM got error '{param1}' from the computer {param2} when attempting to the server:{param3} with file {param4}.

Fields #

NameDescription
param1
param2
param3
param4

Event ID 3221235481: DCOM was unable to communicate with the computer param1 using any of the configured protocols.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

DCOM was unable to communicate with the computer param1 using any of the configured protocols.

Message #

DCOM was unable to communicate with the computer %1 using any of the configured protocols.

Fields #

NameDescription
param1 UnicodeString
binary Binary

Event ID 3221235482: The server {param1} did not register with DCOM within the required timeout.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The server {param1} did not register with DCOM within the required timeout.

Message #

The server {param1} did not register with DCOM within the required timeout.

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "event_id": 10010,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-16T20:35:38.5502237+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param1": "{38FE8DFE-B129-452B-A215-119382B89E3D}"
  }
}

Event ID 3221235483: The server param1 could not be contacted to establish the connection to the client.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

The server param1 could not be contacted to establish the connection to the client.

Message #

The server %1 could not be contacted to establish the connection to the client

Fields #

NameDescription
param1 UnicodeString

Event ID 3221235484: There is an assertion failure in DCOM.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

There is an assertion failure in DCOM. Context follows: ContextFollows param2 param3.

Message #

There is an assertion failure in DCOM.  Context follows: %1 %2 %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 3221235486: The activation for CLSID {param1} failed because remote activations for COM+ are disabled.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The activation for CLSID {param1} failed because remote activations for COM+ are disabled. To enable this functionality use Server Manager to install the COM+ Network Access feature in the Application Server role.

Fields #

NameDescription
param1

Event ID 3221235487: The machine wide limit settings do not grant {param1} {param2} permission for the COM Server application with CLSID {param3} and APPID {param4} to ...

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The machine wide limit settings do not grant {param1} {param2} permission for the COM Server application with CLSID {param3} and APPID {param4} to the user {param5}\{param6} SID ({param7}) from address {param8}. This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7
param8

Event ID 3221235488: The {param1} permission settings do not grant {param2} {param3} permission for the COM Server application with CLSID {param4} and APPID {param5} to...

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The {param1} permission settings do not grant {param2} {param3} permission for the COM Server application with CLSID {param4} and APPID {param5} to the user {param6}\{param7} SID ({param8}) from address {param9}. This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7
param8
param9

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "event_id": 10016,
    "level": "Warning",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-24T02:14:10.9499544+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param5": "{BDBED08B-7FB7-4EEA-AFD0-53DE534CB638}",
    "param8": "S-1-5-21-1006758700-2167138679-1475694448-1000",
    "param3": "Activation",
    "param6": "ludus",
    "param1": "application-specific",
    "param4": "{0DC1AB8B-A52D-4BA8-BD76-E2819386FB2F}",
    "param7": "localuser",
    "param11": "Unavailable",
    "param9": "LocalHost (Using LRPC)",
    "param10": "Unavailable",
    "param2": "Local"
  }
}

Event ID 3221235489: The {param1} permission settings do not grant {param2} access permission to the COM Server application {param3} with APPID {param4} to the user {pa...

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The {param1} permission settings do not grant {param2} access permission to the COM Server application {param3} with APPID {param4} to the user {param5}\{param6} SID ({param7}) from address {param8}. This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7
param8

Event ID 3221235490: The application-specific permission settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to ...

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The application-specific permission settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to the user {param4}\{param5} SID ({param6}) from address {param7}. The application set this security permission programmatically; to modify this security permission contact the application vendor.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7

Event ID 3221235491: The machine wide limit settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to the user {par...

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The machine wide limit settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to the user {param4}\{param5} SID ({param6}) from address {param7}. This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7

Event ID 3221235492: The machine wide {param1} {param2} security descriptor is invalid.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The machine wide {param1} {param2} security descriptor is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1
param2

Event ID 3221235493: The launch and activation security descriptor for the COM Server application with APPID {param1} is invalid.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The launch and activation security descriptor for the COM Server application with APPID {param1} is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1

Event ID 3221235494: The {param1} access security descriptor for the COM Server application {param2} with APPID %3 is invalid.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The {param1} access security descriptor for the COM Server application {param2} with APPID %3 is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1
param2

Event ID 3221235495: The application-specific access security descriptor for the COM Server application {param1} with APPID %2 is invalid.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The application-specific access security descriptor for the COM Server application {param1} with APPID %2 is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed.  The application set this security permission programmatically; to modify this security permission contact the application vendor.

Fields #

NameDescription
param1

Event ID 3221235496: The machine wide group policy {param1} Limits security descriptor is invalid.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The machine wide group policy {param1} Limits security descriptor is invalid. The security descriptor is defined as an invalid Security Descriptor Definitions Language (SDDL) string. The requested action was therefore not performed. Please contact your administrator to get the security descriptor corrected in the Group Policy settings.

Fields #

NameDescription
param1

Event ID 3221235499: The machine wide limit settings do not grant {param1} {param2} permission for COM Server applications to the user {param3}\{param4} SID ({param5}) ...

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The machine wide limit settings do not grant {param1} {param2} permission for COM Server applications to the user {param3}\{param4} SID ({param5}) from address {param6}. This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6

Event ID 3221235501: DCOM started the service {param1} with arguments '{param2}' in order to run the server:{param3}.

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Description

DCOM started the service {param1} with arguments '{param2}' in order to run the server:{param3}.

Message #

DCOM  started the service {param1} with arguments '{param2}' in order to run the server:{param3}

Fields #

NameDescription
param1
param2
param3

Event ID 3221235507: The COM standard marshaler was unable to fix a mismatch between the IID {ProvidedIid} provided by the server and the IID {RequestedIid} requested b...

#
Provider
Microsoft-Windows-DistributedCOM
Channel
Operational

Message #

The COM standard marshaler was unable to fix a mismatch between the IID {ProvidedIid} provided by the server and the IID {RequestedIid} requested by the client; with handler CLSID {HandlerClsid}. The error code was {HRESULT}.

Fields #

NameDescription
ProvidedIid
RequestedIid
HandlerClsid
HRESULT

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 1b562e86-b7aa-4131-badc-b6f3a001407e

Defined in combase.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads