Microsoft-Windows-EapMethods-Ttls
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 100 | TTLS authentication failed because the client doesn't understand a mandatory … | Operational | N | N |
| 101 | TTLS authentication failed because a bad authentication protocol packet was … | Operational | N | N |
| 200 | Server certificate received | Operational | N | N |
| 201 | Validation completed | Operational | N | N |
| 202 | Message receieved from server | Operational | N | N |
| 203 | Client sends response | Operational | N | N |
| 204 | Server Certificate Thumbprint: CAThumbprint. | Operational | N | N |
Event ID 100: TTLS authentication failed because the client doesn't understand a mandatory step that the server wants to perform.
#Event ID 101: TTLS authentication failed because a bad authentication protocol packet was received, possibly due to an implementation error.
#Event ID 200: Server certificate received
#Event ID 201: Validation completed
#Event ID 202: Message receieved from server
#Event ID 203: Client sends response
#Provenance
ETW provider GUID d710d46c-235d-4798-ac20-9f83e1dcd557
Defined in TtlsAuth.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB