Microsoft-Windows-EFS
172 events across 3 channels
Event ID 1: An API call failed at FileNumber.
#Event ID 2: An API call failed at Data.
#Event ID 3: An API call failed at Data.
#Event ID 4: FileNumber.
#Event ID 256: EFS key promoted from current key.
#Description
EFS key promoted from current key. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.
Message #
Fields #
| Name | Description |
|---|---|
CertValidated UInt32 | |
cbHash UInt32 | |
pbHash AnsiString | |
ContainerName UnicodeString | |
ProviderName UnicodeString | |
DisplayInformation UnicodeString | |
dwCapabilities AnsiString | |
bIsCurrentKey AnsiString | |
eKeyType AnsiString |
Event ID 257: EFS key demoted from current key.
#Description
EFS key demoted from current key. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.
Message #
Fields #
| Name | Description |
|---|---|
CertValidated UInt32 | |
cbHash UInt32 | |
pbHash AnsiString | |
ContainerName UnicodeString | |
ProviderName UnicodeString | |
DisplayInformation UnicodeString | |
dwCapabilities AnsiString | |
bIsCurrentKey AnsiString | |
eKeyType AnsiString |
Event ID 258: EFS key flushed from cache.
#Description
EFS key flushed from cache. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.
Message #
Fields #
| Name | Description |
|---|---|
CertValidated UInt32 | |
cbHash UInt32 | |
pbHash AnsiString | |
ContainerName UnicodeString | |
ProviderName UnicodeString | |
DisplayInformation UnicodeString | |
dwCapabilities AnsiString | |
bIsCurrentKey AnsiString | |
eKeyType AnsiString |
Event ID 259: FileNumber.
#Event ID 260: FileNumber.
#Event ID 261: FileNumber.
#Event ID 262: FileNumber.
#Event ID 263: FileNumber.
#Event ID 264: FileNumber.
#Event ID 265: FileNumber.
#Event ID 272: FileNumber.
#Event ID 273: FileNumber.
#Event ID 274: FileNumber.
#Event ID 275: FileNumber.
#Event ID 276: FileNumber.
#Event ID 277: FileNumber.
#Event ID 278: FileNumber.
#Event ID 279: FileNumber.
#Event ID 280: FileNumber.
#Event ID 281: FileNumber.
#Event ID 288: FileNumber.
#Event ID 289: FileNumber.
#Event ID 290: FileNumber.
#Event ID 512: FileNumber.
#Event ID 513: FileNumber.
#Event ID 514: FileNumber.
#Event ID 515: FileNumber.
#Event ID 516: FileNumber.
#Event ID 517: EFS key added to user cache.
#Description
EFS key added to user cache. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.
Message #
Fields #
| Name | Description |
|---|---|
CertValidated UInt32 | |
cbHash UInt32 | |
pbHash AnsiString | |
ContainerName UnicodeString | |
ProviderName UnicodeString | |
DisplayInformation UnicodeString | |
dwCapabilities AnsiString | |
bIsCurrentKey AnsiString | |
eKeyType AnsiString |
Event ID 518: FileNumber.
#Event ID 519: FileNumber.
#Event ID 520: FileNumber.
#Event ID 521: FileNumber.
#Event ID 768: FileNumber.
#Event ID 769: FileNumber.
#Event ID 770: FileNumber.
#Event ID 771: FileNumber.
#Event ID 772: FileNumber.
#Event ID 773: FileNumber.
#Event ID 774: FileNumber.
#Event ID 775: FileNumber.
#Event ID 776: FileNumber.
#Event ID 777: FileNumber.
#Event ID 784: FileNumber.
#Event ID 785: FileNumber.
#Event ID 786: FileNumber.
#Event ID 787: FileNumber.
#Event ID 788: FileNumber.
#Event ID 789: FileNumber.
#Event ID 790: FileNumber.
#Event ID 791: FileNumber.
#Event ID 792: FileNumber.
#Event ID 793: FileNumber.
#Event ID 800: FileNumber.
#Event ID 801: FileNumber.
#Event ID 802: FileNumber.
#Event ID 803: FileNumber.
#Event ID 804: FileNumber.
#Event ID 805: FileNumber.
#Event ID 1024: FileNumber.
#Event ID 1040: FileNumber.
#Event ID 1041: FileNumber.
#Event ID 1042: FileNumber.
#Event ID 1280: Actual.
#Event ID 1281: Actual.
#Event ID 1282: FileNumber.
#Event ID 1283: FileNumber.
#Event ID 1284: FileNumber.
#Event ID 1536: PIN prompt dialog has closed
#Event ID 1537: Prompt the user to select a smartcard-based EFS cert
#Event ID 1538: Smartcard-based EFS cert successfully selected by the user
#Event ID 1539: Prompt the user for PIN
#Event ID 1540: PIN successfully acquired from the user
#Event ID 1541: Perfect match found in cache.
#Event ID 1542: Masterkey history already loaded
#Event ID 1543: Current key loaded from cache
#Event ID 1544: Current key loaded from registry
#Event ID 1545: FileNumber.
#Event ID 4096: FileNumber.
#Event ID 4097: FileNumber.
#Event ID 4098: FileNumber.
#Event ID 4099: FileNumber.
#Event ID 4100: FileNumber.
#Event ID 4101: FileNumber.
#Event ID 4102: FileNumber.
#Event ID 4353: FileNumber.
#Event ID 4354: FileNumber.
#Event ID 4355: FileNumber.
#Event ID 4356: FileNumber.
#Event ID 4357: FileNumber.
#Event ID 4358: FileNumber.
#Event ID 4359: FileNumber.
#Event ID 4360: FileNumber.
#Event ID 4361: FileNumber.
#Event ID 4368: FileNumber.
#Event ID 4369: FileNumber.
#Description
FileNumber.LineNumber: EFS recovery service cannot open the backup file Param1 by name. The interrupted encryption/decryption operation (on file Param2) may be recovered. The backup file will not be deleted. User should delete the backup file if the recovery operation is done successfully.
Message #
Fields #
| Name | Description |
|---|---|
FileNumber UInt32 | |
LineNumber UInt32 | |
Param1 UnicodeString | |
Param2 UnicodeString |
Event ID 4370: FileNumber.
#Event ID 4371: FileNumber.
#Description
FileNumber.LineNumber: EFS recovery service cannot get the backup file name. The interrupted encryption/decryption operation (on file Param1) may be recovered. The temporary backup file Param2 is not deleted. User should delete the backup file if the recovery operation is done successfully.
Message #
Fields #
| Name | Description |
|---|---|
FileNumber UInt32 | |
LineNumber UInt32 | |
Param1 UnicodeString | |
Param2 UnicodeString |
Event ID 4372: FileNumber.
#Event ID 4373: FileNumber.
#Event ID 4374: FileNumber.
#Event ID 4375: FileNumber.
#Event ID 4376: EFS Service failed to start.
#Event ID 4377: FileNumber.
#Event ID 4378: FileNumber.
#Event ID 4379: EFS service was unable to populate SID information.
#Event ID 4380: EFS service was unable to determine the computer name.
#Event ID 4381: EFS service was unable to initialize cache lock.
#Event ID 4382: EFS service was unable to initialize the BCrypt Algorithm Provider.
#Event ID 4383: EFS service was unable to query Software Licensing for the cache size.
#Event ID 4384: EFS service was unable to open handle to the MS_DEF_PROV provider.
#Event ID 4385: EFS service was unable to setup notifications from LSA.
#Event ID 4386: EFS service was unable to initialize the recovery policy resource.
#Event ID 4387: EFS service was unable process the recovery policy.
#Event ID 4388: EFS service was unable to notify NTFS of its state.
#Event ID 4389: EFS service was unable to setup group policy change notifications.
#Event ID 4390: EFS service was unable to process active user sessions.
#Event ID 4391: Encrypting File System server ready to accept calls.
#Event ID 4392: FileNumber.
#Event ID 4393: FileNumber.
#Event ID 4400: FileNumber.
#Event ID 4401: FileNumber.
#Event ID 4402: FileNumber.
#Event ID 4403: FileNumber.
#Event ID 4404: FileNumber.
#Event ID 4405: FileNumber.
#Event ID 4406: Code.
#Event ID 4407: FileNumber.
#Event ID 4408: FileNumber.
#Event ID 4409: FileNumber.
#Event ID 4410: FileNumber.
#Event ID 4411: Code.
#Event ID 4412: Code.
#Event ID 4413: Code.
#Event ID 4414: FileNumber.
#Event ID 4415: FileNumber.
#Event ID 4416: Code.
#Event ID 4417: Code.
#Event ID 4418: FileNumber.
#Event ID 4419: Thread ThreadId: File, Line LineNumber, HRESULT HRESULT, Message: 'Message'.
#Event ID 4420: A client attempted to call an EFS service API without privacy level authentication.
#Event ID 4421: A client that called an EFS service API without privacy level authentication was allowed.
#Description
A client that called an EFS service API without privacy level authentication was allowed. See https://go.microsoft.com/fwlink/?linkid=2181030.
Message #
Event ID 4422: Failed to unprotect device user credential key using Windows Hello for user: Param1.
#Event ID 4423: Personal Data Encryption and Windows Hello status updated: 1) Windows Hello availability: Param1; 2) Windows Hello logon capability: Param2; 3) Windows Hel...
#Description
Personal Data Encryption and Windows Hello status updated: 1) Windows Hello availability: Param1; 2) Windows Hello logon capability: Param2; 3) Windows Hello hardware capability: Param3; 4) Remote Desktop remote connections disabled: Param4; 5) Windows automatic restart sign-on disabled: Param5.
Message #
Fields #
| Name | Description |
|---|---|
FileNumber UInt32 | |
LineNumber UInt32 | |
Param1 UInt32 | |
Param2 UInt32 | |
Param3 UInt32 | |
Param4 UInt32 | |
Param5 UInt32 |
Event ID 4424: Personal Data Encryption enabled for user Param1.
#Event ID 4425: Personal Data Encryption disabled for user Param1.
#Event ID 4432: User Param1 attempted to access user Param2's data protected with Personal Data Encryption and was denied.
#Event ID 4433: Personal Data Encryption conversion started.
#Event ID 4434: Personal Data Encryption conversion completed.
#Event ID 4435: Personal Data Encryption conversion did not complete.
#Description
Personal Data Encryption conversion did not complete.
Message #
Fields #
| Name | Description |
|---|---|
FileNumber UInt32 | |
LineNumber UInt32 | |
Param1 UnicodeString | |
Param2 UnicodeString | |
Param3 UnicodeString | |
Param4 UnicodeString | |
Param5 UInt32 | |
Param6 UInt64 | |
Param7 UInt64 | |
Param8 UInt64 | |
Param9 UInt64 | |
Param10 UInt64 | |
Param11 UInt64 | |
Param12 UInt64 |
Event ID 4436: Personal Data Encryption conversion failed to convert one or more files or folders.
#Event ID 4437: Personal Data Encryption policy for Desktop folder is set to Param2 for user Param1.
#Event ID 4438: Personal Data Encryption policy for Documents folder is set to Param2 for user Param1.
#Event ID 4439: Personal Data Encryption policy for Pictures folder is set to Param2 for user Param1.
#Event ID 4440: Personal Data Encryption policy for Desktop folder is deleted for user Param1.
#Event ID 4441: Personal Data Encryption policy for Documents folder is deleted for user Param1.
#Event ID 4448: Personal Data Encryption policy for Pictures folder is deleted for user Param1.
#Event ID 4449: Personal Data Encryption policy for Desktop folder is mapped to path "Param1" for user Param2.
#Event ID 4450: Personal Data Encryption policy for Documents folder is mapped to path "Param1" for user Param2.
#Event ID 4451: Personal Data Encryption policy for Pictures folder is mapped to path "Param1" for user Param2.
#Event ID 4452: Personal Data Encryption: paths to protect folders is empty for user Param1.
#Event ID 4453: Windows Information Protection has been disabled.
#Event ID 4454: Windows Information Protection could not be disabled.
#Event ID 4455: Personal Data Encryption conversion did not complete the last time it was run.
#Event ID 4456: Personal Data Encryption is not available for the current device.
#Event ID 4457: Personal Data Encryption is not available for the current device.
#Event ID 7000: Machine role cannot be determined.
#Event ID 7002: Default group policy object cannot be created.
#Description
Default group policy object cannot be created. Reason.
Message #
Fields #
| Name | Description |
|---|---|
Reason UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-EFS",
"guid": "{3663A992-84BE-40EA-BBA9-90C7ED544222}",
"event_source_name": "",
"event_id": 7002,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-05-28T03:43:46.9077024+00:00",
"event_record_id": 230,
"correlation": {},
"execution": {
"process_id": 4940,
"thread_id": 5316
},
"channel": "Application",
"computer": "telemetry-DC-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1000"
}
},
"event_data": {
"Reason": "Error 80070005 to open GPO Domain EFS Recovery Policy in domain LDAP://DC=cell-d,DC=ludus,DC=domain."
},
"message": "Default group policy object cannot be created. Error 80070005 to open GPO Domain EFS Recovery Policy in domain LDAP://DC=cell-d,DC=ludus,DC=domain."
}
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 3663a992-84be-40ea-bba9-90c7ed544222
Defined in efscore.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02