Microsoft-Windows-DistributedCOM

EventTitleChannelSampleRule
10000Unable to start a DCOM Server: param3.OperationalNN
10001Unable to start a DCOM Server: param3 as param4/param5.OperationalNY
10002Access denied attempting to launch a DCOM ServerOperationalNN
10003Access denied attempting to launch a DCOM Server using DefaultLaunchPermssionOperationalNN
10004DCOM got error "param1" and was unable to logon param2\param3 in order to run …OperationalNN
10005DCOM got error "param1" attempting to start the service param2 with arguments …OperationalNN
10005DCOM got error "param1" attempting to start the service param2 with arguments …SystemYN
10006DCOM got error "param1" from the computer param2 when attempting to activate the …OperationalYN
10007DCOM got error "param1" when attempting to activate the server:OperationalNN
10008DCOM got error "param1" from the computer param2 when attempting to the server.OperationalYN
10009DCOM was unable to communicate with the computer param1 using any of the …OperationalNN
10010The server param1 did not register with DCOM within the required timeout.OperationalYN
10010The server param1 did not register with DCOM within the required timeoutSystemYN
10011The server param1 could not be contacted to establish the connection to the …OperationalNN
10012There is an assertion failure in DCOMOperationalNN
10014The activation for CLSID param1 failed because remote activations for COM+ are …OperationalNN
10015The machine wide limit settings do not grant param1 param2 permission for the …OperationalNN
10016The param1 permission settings do not grant param2 param3 permission for the COM …OperationalYN
10016The param1 permission settings do not grant param2 param3 permission for the COM …SystemYN
10017The param1 permission settings do not grant param2 access permission to the COM …OperationalNN
10018The application-specific permission settings do not grant param1 access …OperationalNN
10019The machine wide limit settings do not grant param1 access permission to the COM …OperationalNN
10020The machine wide param1 param2 security descriptor is invalid.OperationalNN
10021The launch and activation security descriptor for the COM Server application …OperationalNN
10022The param1 access security descriptor for the COM Server application param2 with …OperationalNN
10023The application-specific access security descriptor for the COM Server …OperationalNN
10024The machine wide group policy param1 Limits security descriptor is invalid.OperationalNN
10026The COM sub system is suppressing duplicate event log entries for a duration of …OperationalNN
10027The machine wide limit settings do not grant param1 param2 permission for COM …OperationalNN
10028DCOM was unable to communicate with the computer param1 using any of the …OperationalYN
10028DCOM was unable to communicate with the computer param1 using any of the …SystemYN
10029The activation of the CLSID param1 timed out waiting for the service param2 to …OperationalNN
10030Unable to start a COM Server for debugging: param3.OperationalNN
10031An unmarshaling policy check was performed when unmarshaling a custom marshaled …OperationalNN
10032An unmarshaling policy check was performed when unmarshaling a custom inproc …OperationalNN
10033An unmarshaling policy check was performed when unmarshaling a COM+ envoy …OperationalNN
10034An unmarshaling policy check was performed due to CLSCTX_NO_CUSTOM_MARSHAL and …OperationalNN
10035The COM standard marshaler was unable to fix a mismatch between the IID …OperationalNN
10036The server-side authentication level policy does not allow the user …OperationalNN
10037Application ApplicationName with PID PID is requesting to activate CLSID CLSID …OperationalNN
10038Application ApplicationName with PID PID is requesting to activate CLSID CLSID …OperationalNN
1073751850The COM sub system is suppressing duplicate event log entries for a duration of …OperationalNN
3221235472Unable to start a DCOM Server: {param3}.OperationalNN
3221235473Unable to start a DCOM Server: {param3} as {param4}/{param5}.OperationalNN
3221235474Access denied attempting to launch a DCOM Server.OperationalNN
3221235475Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion.OperationalNN
3221235476DCOM got error '{param1}' and was unable to logon {param2}\{param3} in order to …OperationalNN
3221235477DCOM got error '{param1}' attempting to start the service {param2} with …OperationalNN
3221235478DCOM got error '{param1}' from the computer {param2} when attempting to activate …OperationalNN
3221235479DCOM got error "param1" when attempting to activate the server: param2.OperationalNN
3221235480DCOM got error '{param1}' from the computer {param2} when attempting to the …OperationalNN
3221235481DCOM was unable to communicate with the computer param1 using any of the …OperationalNN
3221235482The server {param1} did not register with DCOM within the required timeout.OperationalYN
3221235483The server param1 could not be contacted to establish the connection to the …OperationalNN
3221235484There is an assertion failure in DCOM.OperationalNN
3221235486The activation for CLSID {param1} failed because remote activations for COM+ are …OperationalNN
3221235487The machine wide limit settings do not grant {param1} {param2} permission for …OperationalNN
3221235488The {param1} permission settings do not grant {param2} {param3} permission for …OperationalYN
3221235489The {param1} permission settings do not grant {param2} access permission to the …OperationalNN
3221235490The application-specific permission settings do not grant {param1} access …OperationalNN
3221235491The machine wide limit settings do not grant {param1} access permission to the …OperationalNN
3221235492The machine wide {param1} {param2} security descriptor is invalid.OperationalNN
3221235493The launch and activation security descriptor for the COM Server application …OperationalNN
3221235494The {param1} access security descriptor for the COM Server application {param2} …OperationalNN
3221235495The application-specific access security descriptor for the COM Server …OperationalNN
3221235496The machine wide group policy {param1} Limits security descriptor is invalid.OperationalNN
3221235499The machine wide limit settings do not grant {param1} {param2} permission for …OperationalNN
3221235501DCOM started the service {param1} with arguments '{param2}' in order to run the …OperationalNN
3221235507The COM standard marshaler was unable to fix a mismatch between the IID …OperationalNN

Event ID 10000: Unable to start a DCOM Server: param3.

#
Channel
Operational

Description

Unable to start a DCOM Server: param3. The error.

Message #

Unable to start a DCOM Server: %3. The error:
"%2"
Happened while starting this command:
%1

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 10001: Unable to start a DCOM Server: param3 as param4/param5.

#
Channel
Operational

Description

Unable to start a DCOM Server: param3 as param4/param5. The error.

Message #

Unable to start a DCOM Server: %3 as %4/%5. The error:
"%2"
Happened while starting this command:
%1

Fields #

NameDescriptionRules
param1 UnicodeString1 detection rule
param2 UnicodeString1 detection rule
param3 UnicodeString1 detection rule
param4 UnicodeString
param5 UnicodeString

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Event ID 10002: Access denied attempting to launch a DCOM Server

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 10003: Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 10004: DCOM got error "param1" and was unable to logon param2\param3 in order to run the server: param4.

#
Channel
Operational

Description

DCOM got error "param1" and was unable to logon param2\param3 in order to run the server.

Message #

DCOM got error "%1" and was unable to logon %2\%3 in order to run the server:
%4

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 10005: DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server: param4.

#
Channel
Operational

Description

DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server.

Message #

DCOM got error "%1" attempting to start the service %2 with arguments "%3" in order to run the server:
%4

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 10005: DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server:

#
Channel
System
Level
Error

Description

DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server.

Message #

DCOM got error "%1" attempting to start the service %2 with arguments "%3" in order to run the server: %4

Fields #

NameDescription
param1
param2
param3
param4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "",
    "event_id": 10005,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-06-13T05:14:37.1593618+00:00",
    "event_record_id": 2166,
    "correlation": {
      "ActivityID": "{D57A5142-FAF2-0002-275B-7AD5F2FADC01}"
    },
    "execution": {
      "process_id": 660,
      "thread_id": 772
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "param1": "1053",
    "param2": "GoogleUpdaterService150.0.7863.0",
    "param3": "--com-service",
    "param4": "{8018F647-BF07-55BB-82BE-A2D7049F7CE4}"
  },
  "message": "DCOM got error \"1053\" attempting to start the service GoogleUpdaterService150.0.7863.0 with arguments \"--com-service\" in order to run the server:\r\n{8018F647-BF07-55BB-82BE-A2D7049F7CE4}"
}

Event ID 10006: DCOM got error "param1" from the computer param2 when attempting to activate the server: param3.

#
Channel
Operational
Level
Error

Description

DCOM got error "param1" from the computer param2 when attempting to activate the server.

Message #

DCOM got error "%1" from the computer %2 when attempting to activate the server:
%3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "",
    "event_id": 10006,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-04-16T22:13:33.9914282+00:00",
    "event_record_id": 5408,
    "correlation": {
      "ActivityID": "{AEA85543-92F4-4400-9B1C-03900CE328AA}"
    },
    "execution": {
      "process_id": 1360,
      "thread_id": 20244
    },
    "channel": "System",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "2148007941",
    "param2": "DESKTOP-A8D4L1Z",
    "param3": "{38FE8DFE-B129-452B-A215-119382B89E3D}"
  },
  "message": "DCOM got error \"2148007941\" from the computer DESKTOP-A8D4L1Z when attempting to activate the server:\r\n{38FE8DFE-B129-452B-A215-119382B89E3D}"
}

Event ID 10007: DCOM got error "param1" when attempting to activate the server:

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 10008: DCOM got error "param1" from the computer param2 when attempting to the server.

#
Channel
Operational
Level
Error

Message #

DCOM got error "%1" from the computer %2 when attempting to the server:
%3 with file %4.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "",
    "event_id": 10008,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-04-16T22:36:00.7542779+00:00",
    "event_record_id": 5417,
    "correlation": {
      "ActivityID": "{921232B8-4EE8-402A-A3DA-B0729FF4991D}"
    },
    "execution": {
      "process_id": 1360,
      "thread_id": 7504
    },
    "channel": "System",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "2148007941",
    "param2": "DESKTOP-A8D4L1Z",
    "param3": "{38FE8DFE-B129-452B-A215-119382B89E3D}",
    "param4": "hello.stg"
  },
  "message": "DCOM got error \"2148007941\" from the computer DESKTOP-A8D4L1Z when attempting to the server:\r\n{38FE8DFE-B129-452B-A215-119382B89E3D} with file hello.stg."
}

Event ID 10009: DCOM was unable to communicate with the computer param1 using any of the configured protocols

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
__binLength UInt32
binary Binary

Event ID 10010: The server param1 did not register with DCOM within the required timeout.

#
Channel
Operational

Message #

The server %1 did not register with DCOM within the required timeout.

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "event_id": 10010,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-16T20:35:38.5502237+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param1": "{38FE8DFE-B129-452B-A215-119382B89E3D}"
  }
}

Event ID 10010: The server param1 did not register with DCOM within the required timeout

#
Channel
System
Level
Error

Description

The server did not register with DCOM within the required timeout.

Message #

The server %1 did not register with DCOM within the required timeout.

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "",
    "event_id": 10010,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-06-13T05:12:05.5699142+00:00",
    "event_record_id": 2143,
    "correlation": {
      "ActivityID": "{D57A5142-FAF2-0001-8355-7AD5F2FADC01}"
    },
    "execution": {
      "process_id": 1048,
      "thread_id": 1084
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "param1": "{8018F647-BF07-55BB-82BE-A2D7049F7CE4}"
  },
  "message": "The server {8018F647-BF07-55BB-82BE-A2D7049F7CE4} did not register with DCOM within the required timeout."
}

Event ID 10011: The server param1 could not be contacted to establish the connection to the client

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 10012: There is an assertion failure in DCOM

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 10014: The activation for CLSID param1 failed because remote activations for COM+ are disabled.

#
Channel
Operational

Description

The activation for CLSID param1 failed because remote activations for COM+ are disabled. To enable this functionality use Server Manager to install the COM+ Network Access feature in the Application Server role.

Message #

The activation for CLSID %1 failed because remote activations for COM+ are disabled. To enable this functionality use Server Manager to install the COM+ Network Access feature in the Application Server role.

Fields #

NameDescription
param1 UnicodeString

Event ID 10015: The machine wide limit settings do not grant param1 param2 permission for the COM Server application with CLSID.

#
Channel
Operational

Message #

The machine wide limit settings do not grant %1 %2 permission for the COM Server application with CLSID 
%3
 and APPID 
%4
 to the user %5\%6 SID (%7) from address %8 running in the application container %9 SID (%10). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString
param10 UnicodeString

Event ID 10016: The param1 permission settings do not grant param2 param3 permission for the COM Server application with CLSID.

#
Channel
Operational

Message #

The %1 permission settings do not grant %2 %3 permission for the COM Server application with CLSID 
%4
 and APPID 
%5
 to the user %6\%7 SID (%8) from address %9 running in the application container %10 SID (%11). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString
param10 UnicodeString
param11 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "event_id": 10016,
    "level": "Warning",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-24T02:14:10.9499544+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param5": "{BDBED08B-7FB7-4EEA-AFD0-53DE534CB638}",
    "param8": "S-1-5-21-1006758700-2167138679-1475694448-1000",
    "param3": "Activation",
    "param6": "ludus",
    "param1": "application-specific",
    "param4": "{0DC1AB8B-A52D-4BA8-BD76-E2819386FB2F}",
    "param7": "localuser",
    "param11": "Unavailable",
    "param9": "LocalHost (Using LRPC)",
    "param10": "Unavailable",
    "param2": "Local"
  }
}

Event ID 10016: The param1 permission settings do not grant param2 param3 permission for the COM Server application with CLSID

#
Channel
System
Level
Warning

Description

The permission settings do not grant permission for the COM Server application with CLSID.

Message #

The %1 permission settings do not grant %2 %3 permission for the COM Server application with CLSID  %4  and APPID  %5  to the user %6\%7 SID (%8) from address %9 running in the application container %10 SID (%11). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7
param8
param9
param10
param11

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "",
    "event_id": 10016,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-05-29T16:33:58.8709146+00:00",
    "event_record_id": 6816,
    "correlation": {
      "ActivityID": "{BE1132E7-6849-4B6C-8578-E3BE57A71713}"
    },
    "execution": {
      "process_id": 848,
      "thread_id": 1484
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "application-specific",
    "param2": "Local",
    "param3": "Launch",
    "param4": "{21B896BF-008D-4D01-A27B-26061B960DD7}",
    "param5": "{03E09F3B-DCE4-44FE-A9CF-82D050827E1C}",
    "param6": "cell-a",
    "param7": "domainadmin",
    "param8": "S-1-5-21-1006758700-2167138679-1475694448-1105",
    "param9": "LocalHost (Using LRPC)",
    "param10": "Unavailable",
    "param11": "Unavailable"
  },
  "message": "The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID \r\n{21B896BF-008D-4D01-A27B-26061B960DD7}\r\n and APPID \r\n{03E09F3B-DCE4-44FE-A9CF-82D050827E1C}\r\n to the user cell-a\\domainadmin SID (S-1-5-21-1006758700-2167138679-1475694448-1105) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
}

Event ID 10017: The param1 permission settings do not grant param2 access permission to the COM Server application param3 with APPID.

#
Channel
Operational

Message #

The %1 permission settings do not grant %2 access permission to the COM Server application %3 with APPID 
%4
 to the user %5\%6 SID (%7) from address %8 running in the application container %9 SID (%10). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString
param10 UnicodeString

Event ID 10018: The application-specific permission settings do not grant param1 access permission to the COM Server application param2 with APPID.

#
Channel
Operational

Message #

The application-specific permission settings do not grant %1 access permission to the COM Server application %2 with APPID 
%3
 to the user %4\%5 SID (%6) from address %7 running in the application container %8 SID (%9). The application set this security permission programmatically; to modify this security permission contact the application vendor.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString

Event ID 10019: The machine wide limit settings do not grant param1 access permission to the COM Server application param2 with APPID.

#
Channel
Operational

Message #

The machine wide limit settings do not grant %1 access permission to the COM Server application %2 with APPID 
%3
 to the user %4\%5 SID (%6) from address %7 running in the application container %8 SID (%9). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString

Event ID 10020: The machine wide param1 param2 security descriptor is invalid.

#
Channel
Operational

Description

The machine wide param1 param2 security descriptor is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Message #

The machine wide %1 %2 security descriptor is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 10021: The launch and activation security descriptor for the COM Server application with APPID.

#
Channel
Operational

Message #

The launch and activation security descriptor for the COM Server application with APPID 
%1
 is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString

Event ID 10022: The param1 access security descriptor for the COM Server application param2 with APPID.

#
Channel
Operational

Message #

The %1 access security descriptor for the COM Server application %2 with APPID 
%3
 is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 10023: The application-specific access security descriptor for the COM Server application param1 with APPID.

#
Channel
Operational

Message #

The application-specific access security descriptor for the COM Server application %1 with APPID 
%2
 is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed.  The application set this security permission programmatically; to modify this security permission contact the application vendor.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 10024: The machine wide group policy param1 Limits security descriptor is invalid.

#
Channel
Operational

Description

The machine wide group policy param1 Limits security descriptor is invalid. The security descriptor is defined as an invalid Security Descriptor Definitions Language (SDDL) string. The requested action was therefore not performed. Please contact your administrator to get the security descriptor corrected in the Group Policy settings.

Message #

The machine wide group policy %1 Limits security descriptor is invalid. The security descriptor is defined as an invalid Security Descriptor Definitions Language (SDDL) string. The requested action was therefore not performed. Please contact your administrator to get the security descriptor corrected in the Group Policy settings.

Fields #

NameDescription
param1 UnicodeString

Event ID 10026: The COM sub system is suppressing duplicate event log entries for a duration of param1 seconds

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 10027: The machine wide limit settings do not grant param1 param2 permission for COM Server applications to the user param3\param4 SID (param5) from address param6 running in the...

#
Channel
Operational

Description

The machine wide limit settings do not grant param1 param2 permission for COM Server applications to the user param3\param4 SID (param5) from address param6 running in the application container param7 SID (param8). This security permission can be modified using the Component Services administrative tool.

Message #

The machine wide limit settings do not grant %1 %2 permission for COM Server applications to the user %3\%4 SID (%5) from address %6 running in the application container %7 SID (%8). This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString

Event ID 10028: DCOM was unable to communicate with the computer param1 using any of the configured protocols; requested by PID param2 (param3), while activating CLSID param4.

#
Channel
Operational

Message #

DCOM was unable to communicate with the computer %1 using any of the configured protocols; requested by PID %2 (%3), while activating CLSID %4.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
__binLength UInt32
binary Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "event_id": 10028,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-03-15T05:14:36.9508994+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param4": "{8BC3F05E-D86B-11D0-A075-00C04FB68820}",
    "param2": "    28e0",
    "param1": "JD-WIN11-22H2-1",
    "param3": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"
  }
}

Event ID 10028: DCOM was unable to communicate with the computer param1 using any of the configured protocols; requested by PID param2 (param3), while activating CLSID

#
Channel
System
Level
Error

Description

DCOM was unable to communicate with the computer using any of the configured protocols; requested by PID (), while activating CLSID .

Message #

DCOM was unable to communicate with the computer %1 using any of the configured protocols; requested by PID %2 (%3), while activating CLSID %4.

Fields #

NameDescription
param1
param2
param3
param4
__binLength
binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
    "event_source_name": "DCOM",
    "event_id": 10028,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9259400833873739776,
    "time_created": "2026-03-13T23:06:00.558843+00:00",
    "event_record_id": 12279,
    "correlation": {
      "ActivityID": "2A8C090C-ABB5-42FC-ABDE-C1146B129851"
    },
    "execution": {
      "process_id": 1212,
      "thread_id": 6732
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "DC1",
    "param2": "    287c",
    "param3": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
    "param4": "{8BC3F05E-D86B-11D0-A075-00C04FB68820}",
    "Binary": "3C5265636F726423313A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D323B4465746C6F633D313731303B466C6167733D303B506172616D733D313B7B506172616D23303A307D3E3C5265636F726423323A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D31383B4465746C6F633D313434323B466C6167733D303B506172616D733D313B7B506172616D23303A4443317D3E3C5265636F726423333A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D31383B4465746C6F633D3332323B466C6167733D303B506172616D733D303B3E3C5265636F726423343A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D31313030313B47656E636F6D703D31383B4465746C6F633D3332303B466C6167733D303B506172616D733D313B7B506172616D23303A4443317D3E"
  },
  "message": ""
}

Example keys not documented in the fields table: Binary

Event ID 10029: The activation of the CLSID param1 timed out waiting for the service param2 to stop.

#
Channel
Operational

Message #

The activation of the CLSID %1 timed out waiting for the service %2 to stop.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 10030: Unable to start a COM Server for debugging: param3.

#
Channel
Operational

Description

Unable to start a COM Server for debugging: param3. The error.

Message #

Unable to start a COM Server for debugging: %3. The error:
"%2"
Happened while starting this command:
%1

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 10031: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class param1 was rejected.

#
Channel
Operational

Message #

An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class %1 was rejected

Fields #

NameDescription
param1 UnicodeString

Event ID 10032: An unmarshaling policy check was performed when unmarshaling a custom inproc handler and the class param1 was rejected.

#
Channel
Operational

Message #

An unmarshaling policy check was performed when unmarshaling a custom inproc handler and the class %1 was rejected

Fields #

NameDescription
param1 UnicodeString

Event ID 10033: An unmarshaling policy check was performed when unmarshaling a COM+ envoy context property and the class param1 was rejected.

#
Channel
Operational

Message #

An unmarshaling policy check was performed when unmarshaling a COM+ envoy context property and the class %1 was rejected

Fields #

NameDescription
param1 UnicodeString

Event ID 10034: An unmarshaling policy check was performed due to CLSCTX_NO_CUSTOM_MARSHAL and the class param1 was rejected.

#
Channel
Operational

Message #

An unmarshaling policy check was performed due to CLSCTX_NO_CUSTOM_MARSHAL and the class %1 was rejected

Fields #

NameDescription
param1 UnicodeString

Event ID 10035: The COM standard marshaler was unable to fix a mismatch between the IID ProvidedIid provided by the server and the IID RequestedIid requested by the client, with hand...

#
Channel
Operational

Description

The COM standard marshaler was unable to fix a mismatch between the IID ProvidedIid provided by the server and the IID RequestedIid requested by the client, with handler CLSID HandlerClsid. The error code was HRESULT.

Message #

The COM standard marshaler was unable to fix a mismatch between the IID %1 provided by the server and the IID %2 requested by the client, with handler CLSID %3. The error code was %4.

Fields #

NameDescription
ProvidedIid UnicodeString
RequestedIid UnicodeString
HandlerClsid UnicodeString
HRESULT UnicodeString

Event ID 10036: The server-side authentication level policy does not allow the user DomainName\UserName SID (SID) from address ClientIPAddress to activate DCOM server.

#
Channel
Operational

Description

The server-side authentication level policy does not allow the user DomainName\UserName SID (SID) from address ClientIPAddress to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.

Message #

The server-side authentication level policy does not allow the user %1\%2 SID (%3) from address %4 to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.

Fields #

NameDescription
DomainName UnicodeString
UserName UnicodeString
SID UnicodeString
ClientIPAddress UnicodeString

Event ID 10037: Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with explicitly set authentication level at ActivationAuthenticationLevel.

#
Channel
Operational

Description

Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with explicitly set authentication level at ActivationAuthenticationLevel. The lowest activation authentication level required by DCOM is 5(RPC_C_AUTHN_LEVEL_PKT_INTEGRITY). To raise the activation authentication level, please contact the application vendor.

Message #

Application %1 with PID %2 is requesting to activate CLSID %3 on computer %4 with explicitly set authentication level at %5. The lowest activation authentication level required by DCOM is 5(RPC_C_AUTHN_LEVEL_PKT_INTEGRITY). To raise the activation authentication level, please contact the application vendor.

Fields #

NameDescription
ApplicationName UnicodeString
PID UnicodeString
CLSID UnicodeString
ComputerName UnicodeString
ActivationAuthenticationLevel UnicodeString

Event ID 10038: Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with default activation authentication level at ActivationAuthenticationLevel.

#
Channel
Operational

Description

Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with default activation authentication level at ActivationAuthenticationLevel. The lowest activation authentication level required by DCOM is 5(RPC_C_AUTHN_LEVEL_PKT_INTEGRITY). To raise the activation authentication level, please contact the application vendor.

Message #

Application %1 with PID %2 is requesting to activate CLSID %3 on computer %4 with default activation authentication level at %5. The lowest activation authentication level required by DCOM is 5(RPC_C_AUTHN_LEVEL_PKT_INTEGRITY). To raise the activation authentication level, please contact the application vendor.

Fields #

NameDescription
ApplicationName UnicodeString
PID UnicodeString
CLSID UnicodeString
ComputerName UnicodeString
ActivationAuthenticationLevel UnicodeString

Event ID 1073751850: The COM sub system is suppressing duplicate event log entries for a duration of param1 seconds.

#
Channel
Operational

Description

The COM sub system is suppressing duplicate event log entries for a duration of seconds. The suppression timeout can be controlled by a REG_DWORD value named under the following registry key: HKLM\.

Message #

The COM sub system is suppressing duplicate event log entries for a duration of %1 seconds.  The suppression timeout can be controlled by a REG_DWORD value named %2 under the following registry key: HKLM\%3.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 3221235472: Unable to start a DCOM Server: {param3}.

#
Channel
Operational

Description

Unable to start a DCOM Server: {param3}. The error:'{param2}'Happened while starting this command:{param1}.

Message #

Unable to start a DCOM Server: {param3}. The error:'{param2}'Happened while starting this command:{param1}

Fields #

NameDescription
param3
param2
param1

Event ID 3221235473: Unable to start a DCOM Server: {param3} as {param4}/{param5}.

#
Channel
Operational

Description

Unable to start a DCOM Server: {param3} as {param4}/{param5}. The error:'{param2}'Happened while starting this command:{param1}.

Message #

Unable to start a DCOM Server: {param3} as {param4}/{param5}. The error:'{param2}'Happened while starting this command:{param1}

Fields #

NameDescription
param3
param4
param5
param2
param1

Event ID 3221235474: Access denied attempting to launch a DCOM Server.

#
Channel
Operational

Description

Access denied attempting to launch a DCOM Server. The server is.

Message #

Access denied attempting to launch a DCOM Server. The server is:
%1
The user is %2/%3, SID=%4.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 3221235475: Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion.

#
Channel
Operational

Description

Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion. The server is.

Message #

Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion. The server is:
%1
The user is %2/%3, SID=%4.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 3221235476: DCOM got error '{param1}' and was unable to logon {param2}\{param3} in order to run the server:{param4}.

#
Channel
Operational

Fields #

NameDescription
param1
param2
param3
param4

Event ID 3221235477: DCOM got error '{param1}' attempting to start the service {param2} with arguments '{param3}' in order to run the server:{param4}.

#
Channel
Operational

Fields #

NameDescription
param1
param2
param3
param4

Event ID 3221235478: DCOM got error '{param1}' from the computer {param2} when attempting to activate the server:{param3}.

#
Channel
Operational

Fields #

NameDescription
param1
param2
param3

Event ID 3221235479: DCOM got error "param1" when attempting to activate the server: param2.

#
Channel
Operational

Description

DCOM got error "param1" when attempting to activate the server.

Message #

DCOM got error "%1" when attempting to activate the server:
%2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 3221235480: DCOM got error '{param1}' from the computer {param2} when attempting to the server:{param3} with file {param4}.

#
Channel
Operational

Fields #

NameDescription
param1
param2
param3
param4

Event ID 3221235481: DCOM was unable to communicate with the computer param1 using any of the configured protocols.

#
Channel
Operational

Message #

DCOM was unable to communicate with the computer %1 using any of the configured protocols.

Fields #

NameDescription
param1 UnicodeString
binary Binary

Event ID 3221235482: The server {param1} did not register with DCOM within the required timeout.

#
Channel
Operational

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "event_id": 10010,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-16T20:35:38.5502237+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param1": "{38FE8DFE-B129-452B-A215-119382B89E3D}"
  }
}

Event ID 3221235483: The server param1 could not be contacted to establish the connection to the client.

#
Channel
Operational

Message #

The server %1 could not be contacted to establish the connection to the client

Fields #

NameDescription
param1 UnicodeString

Event ID 3221235484: There is an assertion failure in DCOM.

#
Channel
Operational

Description

There is an assertion failure in DCOM. Context follows: ContextFollows param2 param3.

Message #

There is an assertion failure in DCOM.  Context follows: %1 %2 %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 3221235486: The activation for CLSID {param1} failed because remote activations for COM+ are disabled.

#
Channel
Operational

Message #

The activation for CLSID {param1} failed because remote activations for COM+ are disabled. To enable this functionality use Server Manager to install the COM+ Network Access feature in the Application Server role.

Fields #

NameDescription
param1

Event ID 3221235487: The machine wide limit settings do not grant {param1} {param2} permission for the COM Server application with CLSID {param3} and APPID {param4} to ...

#
Channel
Operational

Message #

The machine wide limit settings do not grant {param1} {param2} permission for the COM Server application with CLSID {param3} and APPID {param4} to the user {param5}\{param6} SID ({param7}) from address {param8}. This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7
param8

Event ID 3221235488: The {param1} permission settings do not grant {param2} {param3} permission for the COM Server application with CLSID {param4} and APPID {param5} to...

#
Channel
Operational

Message #

The {param1} permission settings do not grant {param2} {param3} permission for the COM Server application with CLSID {param4} and APPID {param5} to the user {param6}\{param7} SID ({param8}) from address {param9}. This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7
param8
param9

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DistributedCOM",
    "event_id": 10016,
    "level": "Warning",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-05-24T02:14:10.9499544+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param5": "{BDBED08B-7FB7-4EEA-AFD0-53DE534CB638}",
    "param8": "S-1-5-21-1006758700-2167138679-1475694448-1000",
    "param3": "Activation",
    "param6": "ludus",
    "param1": "application-specific",
    "param4": "{0DC1AB8B-A52D-4BA8-BD76-E2819386FB2F}",
    "param7": "localuser",
    "param11": "Unavailable",
    "param9": "LocalHost (Using LRPC)",
    "param10": "Unavailable",
    "param2": "Local"
  }
}

Example keys not documented in the fields table: param10, param11

Event ID 3221235489: The {param1} permission settings do not grant {param2} access permission to the COM Server application {param3} with APPID {param4} to the user {pa...

#
Channel
Operational

Message #

The {param1} permission settings do not grant {param2} access permission to the COM Server application {param3} with APPID {param4} to the user {param5}\{param6} SID ({param7}) from address {param8}. This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7
param8

Event ID 3221235490: The application-specific permission settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to ...

#
Channel
Operational

Message #

The application-specific permission settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to the user {param4}\{param5} SID ({param6}) from address {param7}. The application set this security permission programmatically; to modify this security permission contact the application vendor.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7

Event ID 3221235491: The machine wide limit settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to the user {par...

#
Channel
Operational

Message #

The machine wide limit settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to the user {param4}\{param5} SID ({param6}) from address {param7}. This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6
param7

Event ID 3221235492: The machine wide {param1} {param2} security descriptor is invalid.

#
Channel
Operational

Message #

The machine wide {param1} {param2} security descriptor is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1
param2

Event ID 3221235493: The launch and activation security descriptor for the COM Server application with APPID {param1} is invalid.

#
Channel
Operational

Message #

The launch and activation security descriptor for the COM Server application with APPID {param1} is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1

Event ID 3221235494: The {param1} access security descriptor for the COM Server application {param2} with APPID %3 is invalid.

#
Channel
Operational

Message #

The {param1} access security descriptor for the COM Server application {param2} with APPID %3 is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.

Fields #

NameDescription
param1
param2

Event ID 3221235495: The application-specific access security descriptor for the COM Server application {param1} with APPID %2 is invalid.

#
Channel
Operational

Message #

The application-specific access security descriptor for the COM Server application {param1} with APPID %2 is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed.  The application set this security permission programmatically; to modify this security permission contact the application vendor.

Fields #

NameDescription
param1

Event ID 3221235496: The machine wide group policy {param1} Limits security descriptor is invalid.

#
Channel
Operational

Message #

The machine wide group policy {param1} Limits security descriptor is invalid. The security descriptor is defined as an invalid Security Descriptor Definitions Language (SDDL) string. The requested action was therefore not performed. Please contact your administrator to get the security descriptor corrected in the Group Policy settings.

Fields #

NameDescription
param1

Event ID 3221235499: The machine wide limit settings do not grant {param1} {param2} permission for COM Server applications to the user {param3}\{param4} SID ({param5}) ...

#
Channel
Operational

Message #

The machine wide limit settings do not grant {param1} {param2} permission for COM Server applications to the user {param3}\{param4} SID ({param5}) from address {param6}. This security permission can be modified using the Component Services administrative tool.

Fields #

NameDescription
param1
param2
param3
param4
param5
param6

Event ID 3221235501: DCOM started the service {param1} with arguments '{param2}' in order to run the server:{param3}.

#
Channel
Operational

Message #

DCOM  started the service {param1} with arguments '{param2}' in order to run the server:{param3}

Fields #

NameDescription
param1
param2
param3

Event ID 3221235507: The COM standard marshaler was unable to fix a mismatch between the IID {ProvidedIid} provided by the server and the IID {RequestedIid} requested b...

#
Channel
Operational

Message #

The COM standard marshaler was unable to fix a mismatch between the IID {ProvidedIid} provided by the server and the IID {RequestedIid} requested by the client; with handler CLSID {HandlerClsid}. The error code was {HRESULT}.

Fields #

NameDescription
ProvidedIid
RequestedIid
HandlerClsid
HRESULT

Provenance

ETW provider GUID 1b562e86-b7aa-4131-badc-b6f3a001407e

Defined in combase.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB