Microsoft-Windows-EapMethods-Sim
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 100 | Method Name: User with telephone number Error Cause was successfully … | Operational | N | N |
| 101 | Method Name: Authentication was terminated by the client, reason: Error Cause. | Operational | N | N |
| 102 | Method Name: Authentication was terminated by the server, reason: Error Cause. | Operational | N | N |
| 103 | Method Name: Fast re-authentication was terminated and a full authentication was … | Operational | N | N |
| 104 | Method Name: The client and server were found to be out of sequence during … | Operational | N | N |
| 105 | EAP-AKA': The client detected a mismatch between its version of the network name … | Operational | N | N |
Event ID 100: Method Name: User with telephone number Error Cause was successfully authenticated to the network.
#Event ID 101: Method Name: Authentication was terminated by the client, reason: Error Cause.
#Event ID 102: Method Name: Authentication was terminated by the server, reason: Error Cause.
#Event ID 103: Method Name: Fast re-authentication was terminated and a full authentication was initiated because the client and server were out of sequence.
#Event ID 104: Method Name: The client and server were found to be out of sequence during authentication.
#Event ID 105: EAP-AKA': The client detected a mismatch between its version of the network name and the one received from the server.
#Provenance
ETW provider GUID 3d42a67d-9ce8-4284-b755-2550672b0ce0
Defined in SimAuth.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB