Microsoft-Windows-EFS

EventTitleChannelSampleRule
1An API call failed at FileNumber.DebugNN
2An API call failed at Data.DebugNN
3An API call failed at Data.DebugNN
4FileNumber.DebugNN
256EFS key promoted from current key.DebugNN
257EFS key demoted from current key.DebugNN
258EFS key flushed from cache.DebugNN
259FileNumber.DebugNN
260FileNumber.DebugNN
261FileNumber.DebugNN
262FileNumber.DebugNN
263FileNumber.DebugNN
264FileNumber.DebugNN
265FileNumber.DebugNN
272FileNumber.DebugNN
273FileNumber.DebugNN
274FileNumber.DebugNN
275FileNumber.DebugNN
276FileNumber.DebugNN
277FileNumber.DebugNN
278FileNumber.DebugNN
279FileNumber.DebugNN
280FileNumber.DebugNN
281FileNumber.DebugNN
288FileNumber.DebugNN
289FileNumber.DebugNN
290FileNumber.DebugNN
512FileNumber.DebugNN
513FileNumber.DebugNN
514FileNumber.DebugNN
515FileNumber.DebugNN
516FileNumber.DebugNN
517EFS key added to user cache.DebugNN
518FileNumber.DebugNN
519FileNumber.DebugNN
520FileNumber.DebugNN
521FileNumber.DebugNN
768FileNumber.DebugNN
769FileNumber.DebugNN
770FileNumber.DebugNN
771FileNumber.DebugNN
772FileNumber.DebugNN
773FileNumber.DebugNN
774FileNumber.DebugNN
775FileNumber.DebugNN
776FileNumber.DebugNN
777FileNumber.DebugNN
784FileNumber.DebugNN
785FileNumber.DebugNN
786FileNumber.DebugNN
787FileNumber.DebugNN
788FileNumber.DebugNN
789FileNumber.DebugNN
790FileNumber.DebugNN
791FileNumber.DebugNN
792FileNumber.DebugNN
793FileNumber.DebugNN
800FileNumber.DebugNN
801FileNumber.DebugNN
802FileNumber.DebugNN
803FileNumber.DebugNN
804FileNumber.DebugNN
805FileNumber.DebugNN
1024FileNumber.DebugNN
1040FileNumber.DebugNN
1041FileNumber.DebugNN
1042FileNumber.DebugNN
1280Actual.DebugNN
1281Actual.DebugNN
1282FileNumber.DebugNN
1283FileNumber.DebugNN
1284FileNumber.DebugNN
1536PIN prompt dialog has closedDebugNN
1537Prompt the user to select a smartcard-based EFS certDebugNN
1538Smartcard-based EFS cert successfully selected by the userDebugNN
1539Prompt the user for PINDebugNN
1540PIN successfully acquired from the userDebugNN
1541Perfect match found in cache.DebugNN
1542Masterkey history already loadedDebugNN
1543Current key loaded from cacheDebugNN
1544Current key loaded from registryDebugNN
1545FileNumber.DebugNN
4096FileNumber.DebugNN
4097FileNumber.DebugNN
4098FileNumber.DebugNN
4099FileNumber.DebugNN
4100FileNumber.DebugNN
4101FileNumber.DebugNN
4102FileNumber.DebugNN
4353FileNumber.DebugNN
4354FileNumber.DebugNN
4355FileNumber.DebugNN
4356FileNumber.DebugNN
4357FileNumber.DebugNN
4358FileNumber.DebugNN
4359FileNumber.DebugNN
4360FileNumber.DebugNN
4361FileNumber.DebugNN
4368FileNumber.DebugNN
4369FileNumber.DebugNN
4370FileNumber.DebugNN
4371FileNumber.DebugNN
4372FileNumber.DebugNN
4373FileNumber.DebugNN
4374FileNumber.DebugNN
4375FileNumber.DebugNN
4376EFS Service failed to start.ApplicationNN
4377FileNumber.DebugNN
4378FileNumber.DebugNN
4379EFS service was unable to populate SID information.ApplicationNN
4380EFS service was unable to determine the computer name.ApplicationNN
4381EFS service was unable to initialize cache lock.ApplicationNN
4382EFS service was unable to initialize the BCrypt Algorithm Provider.ApplicationNN
4383EFS service was unable to query Software Licensing for the cache size.ApplicationNN
4384EFS service was unable to open handle to the MS_DEF_PROV provider.ApplicationNN
4385EFS service was unable to setup notifications from LSA.ApplicationNN
4386EFS service was unable to initialize the recovery policy resource.ApplicationNN
4387EFS service was unable process the recovery policy.ApplicationNN
4388EFS service was unable to notify NTFS of its state.ApplicationNN
4389EFS service was unable to setup group policy change notifications.ApplicationNN
4390EFS service was unable to process active user sessions.ApplicationNN
4391Encrypting File System server ready to accept calls.DebugNN
4392FileNumber.ApplicationNN
4393FileNumber.ApplicationNN
4400FileNumber.ApplicationNN
4401FileNumber.ApplicationNN
4402FileNumber.ApplicationNN
4403FileNumber.ApplicationNN
4404FileNumber.ApplicationNN
4405FileNumber.DebugNN
4406Code.DebugNN
4407FileNumber.DebugNN
4408FileNumber.DebugNN
4409FileNumber.DebugNN
4410FileNumber.DebugNN
4411Code.DebugNN
4412Code.DebugNN
4413Code.DebugNN
4414FileNumber.DebugNN
4415FileNumber.DebugNN
4416Code.DebugNN
4417Code.DebugNN
4418FileNumber.ApplicationNN
4419Thread ThreadId: File, Line LineNumber, HRESULT HRESULT, Message: 'Message'.DebugNN
4420A client attempted to call an EFS service API without privacy level …ApplicationNN
4421A client that called an EFS service API without privacy level authentication was …ApplicationNN
4422Failed to unprotect device user credential key using Windows Hello for user: …OperationalNN
4423Personal Data Encryption and Windows Hello status updated: 1) Windows Hello …OperationalNN
4424Personal Data Encryption enabled for user Param1.OperationalNN
4425Personal Data Encryption disabled for user Param1.OperationalNN
4432User Param1 attempted to access user Param2's data protected with Personal Data …OperationalNN
4433Personal Data Encryption conversion started.OperationalNN
4434Personal Data Encryption conversion completed.OperationalNN
4435Personal Data Encryption conversion did not complete.OperationalNN
4436Personal Data Encryption conversion failed to convert one or more files or …OperationalNN
4437Personal Data Encryption policy for Desktop folder is set to Param2 for user …OperationalNN
4438Personal Data Encryption policy for Documents folder is set to Param2 for user …OperationalNN
4439Personal Data Encryption policy for Pictures folder is set to Param2 for user …OperationalNN
4440Personal Data Encryption policy for Desktop folder is deleted for user Param1.OperationalNN
4441Personal Data Encryption policy for Documents folder is deleted for user Param1.OperationalNN
4448Personal Data Encryption policy for Pictures folder is deleted for user Param1.OperationalNN
4449Personal Data Encryption policy for Desktop folder is mapped to path "Param1" …OperationalNN
4450Personal Data Encryption policy for Documents folder is mapped to path "Param1" …OperationalNN
4451Personal Data Encryption policy for Pictures folder is mapped to path "Param1" …OperationalNN
4452Personal Data Encryption: paths to protect folders is empty for user Param1.OperationalNN
4453Windows Information Protection has been disabled.OperationalNN
4454Windows Information Protection could not be disabled.OperationalNN
4455Personal Data Encryption conversion did not complete the last time it was run.OperationalNN
4456Personal Data Encryption is not available for the current device.OperationalNN
4457Personal Data Encryption is not available for the current device.OperationalNN
7000Machine role cannot be determined.ApplicationNN
7002Default group policy object cannot be created.ApplicationYN

Event ID 1: An API call failed at FileNumber.

#
Channel
Debug

Description

An API call failed at FileNumber.LineNumber. Error code: Param.

Message #

An API call failed at %1.%2.  Error code: %3

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param UInt32

Event ID 2: An API call failed at Data.

#
Channel
Debug

Description

An API call failed at Data.FileNumber. Error code: LineNumber, Data: Param1.

Message #

An API call failed at %1.%2.  Error code: %3, Data: %4

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UInt32
Param2 UInt32

Event ID 3: An API call failed at Data.

#
Channel
Debug

Description

An API call failed at Data.FileNumber. Error code: LineNumber, Data: Param1, Param2.

Message #

An API call failed at %1.%2.  Error code: %3, Data: %4, %5

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UInt32
Param2 UInt32
Param3 UInt32

Event ID 4: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Failed to allocate Param bytes.

Message #

%1.%2: Failed to allocate %3 bytes.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param UInt32

Event ID 256: EFS key promoted from current key.

#
Channel
Debug

Description

EFS key promoted from current key. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.

Message #

EFS key promoted from current key.  CertValidated: %1, cbHash: %2, pbHash: %3, ContainerName: %4, ProviderName: %5, DisplayInformation: %6, dwCapabilities: %7, bIsCurrentKey: %8, eKeyType: %9

Fields #

NameDescription
CertValidated UInt32
cbHash UInt32
pbHash AnsiString
ContainerName UnicodeString
ProviderName UnicodeString
DisplayInformation UnicodeString
dwCapabilities AnsiString
bIsCurrentKey AnsiString
eKeyType AnsiString

Event ID 257: EFS key demoted from current key.

#
Channel
Debug

Description

EFS key demoted from current key. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.

Message #

EFS key demoted from current key.  CertValidated: %1, cbHash: %2, pbHash: %3, ContainerName: %4, ProviderName: %5, DisplayInformation: %6, dwCapabilities: %7, bIsCurrentKey: %8, eKeyType: %9

Fields #

NameDescription
CertValidated UInt32
cbHash UInt32
pbHash AnsiString
ContainerName UnicodeString
ProviderName UnicodeString
DisplayInformation UnicodeString
dwCapabilities AnsiString
bIsCurrentKey AnsiString
eKeyType AnsiString

Event ID 258: EFS key flushed from cache.

#
Channel
Debug

Description

EFS key flushed from cache. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.

Message #

EFS key flushed from cache.  CertValidated: %1, cbHash: %2, pbHash: %3, ContainerName: %4, ProviderName: %5, DisplayInformation: %6, dwCapabilities: %7, bIsCurrentKey: %8, eKeyType: %9

Fields #

NameDescription
CertValidated UInt32
cbHash UInt32
pbHash AnsiString
ContainerName UnicodeString
ProviderName UnicodeString
DisplayInformation UnicodeString
dwCapabilities AnsiString
bIsCurrentKey AnsiString
eKeyType AnsiString

Event ID 259: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: The specified key is not valid for EFS.

Message #

%1.%2: The specified key is not valid for EFS

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 260: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Attempt to create a new EFS key.

Message #

%1.%2: Attempt to create a new EFS key

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 261: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: A new EFS key was successfully created.

Message #

%1.%2: A new EFS key was successfully created

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 262: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Begin searching the MY store for a valid EFS key.

Message #

%1.%2: Begin searching the MY store for a valid EFS key

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 263: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Begin searching the MY store for a valid EFS key.

Message #

%1.%2: Begin searching the MY store for a valid EFS key

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 264: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Deleting currentkey from registry.

Message #

%1.%2: Deleting currentkey from registry

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 265: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: The EFS cert is self-signed, but self-signed certs are disabled by policy.

Message #

%1.%2: The EFS cert is self-signed, but self-signed certs are disabled by policy

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 272: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: RSA is required by policy, but the key does not support RSA encryption.

Message #

%1.%2: RSA is required by policy, but the key does not support RSA encryption

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 273: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: MASTERKEY is required by policy, but the key does not support MASTERKEY encryption.

Message #

%1.%2: MASTERKEY is required by policy, but the key does not support MASTERKEY encryption

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 274: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: SMARTCARDS are required by policy, but the key is not SMARTCARD-based.

Message #

%1.%2: SMARTCARDS are required by policy, but the key is not SMARTCARD-based

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 275: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: key is expired.

Message #

%1.%2: key is expired

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 276: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: key is valid.

Message #

%1.%2: key is valid

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 277: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: try and locate the matching key based on cert hash.

Message #

%1.%2: try and locate the matching key based on cert hash

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 278: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: key successfully loaded from registry.

Message #

%1.%2: key successfully loaded from registry

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 279: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: try and locate the matching key in cache.

Message #

%1.%2: try and locate the matching key in cache

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 280: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: trying to load the masterkey history.

Message #

%1.%2: trying to load the masterkey history

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 281: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: masterkey history loaded.

Message #

%1.%2: masterkey history loaded

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 288: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: failed to encrypt: SIS or HSM file.

Message #

%1.%2: failed to encrypt: SIS or HSM file

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 289: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Suite B is disabled by policy, but the key is a Suite B key.

Message #

%1.%2: Suite B is disabled by policy, but the key is a Suite B key

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 290: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Suite B is required by policy, but the key is not a Suite B key.

Message #

%1.%2: Suite B is required by policy, but the key is not a Suite B key

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 512: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: releasing user cache object. Refcount: Param.

Message #

%1.%2: releasing user cache object.  Refcount: %3

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param UInt32

Event ID 513: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: trying to stop cache polling thread.

Message #

%1.%2: trying to stop cache polling thread

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 514: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: no decryption status in cache.

Message #

%1.%2: no decryption status in cache

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 515: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: found matching decryption status in cache.

Message #

%1.%2: found matching decryption status in cache

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 516: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: attempting to add key to user cache.

Message #

%1.%2: attempting to add key to user cache

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 517: EFS key added to user cache.

#
Channel
Debug

Description

EFS key added to user cache. CertValidated: CertValidated, cbHash: cbHash, pbHash: pbHash, ContainerName: ContainerName, ProviderName: ProviderName, DisplayInformation: DisplayInformation, dwCapabilities: dwCapabilities, bIsCurrentKey: bIsCurrentKey, eKeyType: eKeyType.

Message #

EFS key added to user cache.  CertValidated: %1, cbHash: %2, pbHash: %3, ContainerName: %4, ProviderName: %5, DisplayInformation: %6, dwCapabilities: %7, bIsCurrentKey: %8, eKeyType: %9

Fields #

NameDescription
CertValidated UInt32
cbHash UInt32
pbHash AnsiString
ContainerName UnicodeString
ProviderName UnicodeString
DisplayInformation UnicodeString
dwCapabilities AnsiString
bIsCurrentKey AnsiString
eKeyType AnsiString

Event ID 518: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: ensuring user has cache node.

Message #

%1.%2: ensuring user has cache node

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 519: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: found cache node in user info.

Message #

%1.%2: found cache node in user info

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 520: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: found cache node in global cache.

Message #

%1.%2: found cache node in global cache

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 521: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: creating new cache node for user.

Message #

%1.%2: creating new cache node for user

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 768: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Policy settings specified flush on card removal. Starting the polling thread...

Message #

%1.%2: Policy settings specified flush on card removal.  Starting the polling thread...

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 769: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Policy settings specified NO flush on timeout. Stopping the polling thread...

Message #

%1.%2: Policy settings specified NO flush on timeout.  Stopping the polling thread...

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 770: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Policy settings specified flush on timeout. Starting the polling thread...

Message #

%1.%2: Policy settings specified flush on timeout.  Starting the polling thread...

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 771: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Policy settings specified new cache flush interval: Param. Stop polling (will restart if there are active user caches).

Message #

%1.%2: Policy settings specified new cache flush interval: %3.  Stop polling (will restart if there are active user caches)

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param UInt32

Event ID 772: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Polling thread stopped.

Message #

%1.%2: Polling thread stopped

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 773: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Flush cache specified by policy, and we have active user caches. Start polling.

Message #

%1.%2: Flush cache specified by policy, and we have active user caches.  Start polling.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 774: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Polling thread started.

Message #

%1.%2: Polling thread started

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 775: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: User logon detected. Beginning SSO processing.

Message #

%1.%2: User logon detected.  Beginning SSO processing.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 776: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: User logon detected, but is not smartcard-based. No SSO processing required.

Message #

%1.%2: User logon detected, but is not smartcard-based.  No SSO processing required.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 777: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Smartcard notification detected. Beginning SSO processing.

Message #

%1.%2: Smartcard notification detected.  Beginning SSO processing.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 784: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Smartcard notification detected, but the logon cert is already cached. No processing required.

Message #

%1.%2: Smartcard notification detected, but the logon cert is already cached.  No processing required.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 785: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Current key matches the logon cert. Setting up the PIN cache.

Message #

%1.%2: Current key matches the logon cert.  Setting up the PIN cache.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 786: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: User does not yet have a current key. If smartcard is required by policy, the logon cert and PIN will be cached.

Message #

%1.%2: User does not yet have a current key.  If smartcard is required by policy, the logon cert and PIN will be cached.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 787: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Logon notification detected on DC. Beginning DRA install.

Message #

%1.%2: Logon notification detected on DC.  Beginning DRA install.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 788: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: user does not already have a cache: generating one now.

Message #

%1.%2: user does not already have a cache: generating one now

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 789: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: generating pre-cache for PIN and logon cert.

Message #

%1.%2: generating pre-cache for PIN and logon cert

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 790: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: tried to install logon cert, but it's not available (not a smartcard logon, or the smartcard was removed).

Message #

%1.%2: tried to install logon cert, but it's not available (not a smartcard logon, or the smartcard was removed)

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 791: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: logon cert successfully installed.

Message #

%1.%2: logon cert successfully installed

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 792: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: trying to install logon cert.

Message #

%1.%2: trying to install logon cert

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 793: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: User lock detected. Beginning SSO processing.

Message #

%1.%2: User lock detected.  Beginning SSO processing.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 800: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: User logoff detected. Beginning SSO processing.

Message #

%1.%2: User logoff detected.  Beginning SSO processing.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 801: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Flushing the user cache.

Message #

%1.%2: Flushing the user cache

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 802: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: User has locked workstation, but policy says not to flush cache.

Message #

%1.%2: User has locked workstation, but policy says not to flush cache

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 803: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Checking for expired cache entries.

Message #

%1.%2: Checking for expired cache entries

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 804: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Expired certificate in recovery policy.

Message #

%1.%2: Expired certificate in recovery policy

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 805: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Certificate in recovery policy is not yet valid.

Message #

%1.%2: Certificate in recovery policy is not yet valid

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1024: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: SL policy successfully updated.

Message #

%1.%2: SL policy successfully updated

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1040: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS is disabled by SL policy.

Message #

%1.%2: EFS is disabled by SL policy

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1041: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS is not yet initialized.

Message #

%1.%2: EFS is not yet initialized

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1042: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS is disabled.

Message #

%1.%2: EFS is disabled

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1280: Actual.

#
Channel
Debug

Description

Actual.FileNumber: the data received by the API was too large. Expected: LineNumber, Actual: Param1.

Message #

%1.%2: the data received by the API was too large.  Expected: %3, Actual: %4

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UInt32
Param2 UInt32

Event ID 1281: Actual.

#
Channel
Debug

Description

Actual.FileNumber: the data received by the API was too small. Expected: LineNumber, Actual: Param1.

Message #

%1.%2: the data received by the API was too small.  Expected: %3, Actual: %4

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UInt32
Param2 UInt32

Event ID 1282: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: POSSIBLE EFS ATTACK DETECTED: DomainName, UserName, AttackId.

Message #

%1.%2: POSSIBLE EFS ATTACK DETECTED: %3, %4, %5

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
DomainName UnicodeString
UserName UnicodeString
AttackId UInt32

Event ID 1283: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: attempting to validate EFS stream.

Message #

%1.%2: attempting to validate EFS stream

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1284: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS stream validated.

Message #

%1.%2: EFS stream validated

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1536: PIN prompt dialog has closed

#
Channel
Debug

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1537: Prompt the user to select a smartcard-based EFS cert

#
Channel
Debug

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1538: Smartcard-based EFS cert successfully selected by the user

#
Channel
Debug

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1539: Prompt the user for PIN

#
Channel
Debug

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1540: PIN successfully acquired from the user

#
Channel
Debug

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1541: Perfect match found in cache.

#
Channel
Debug

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1542: Masterkey history already loaded

#
Channel
Debug

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1543: Current key loaded from cache

#
Channel
Debug

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1544: Current key loaded from registry

#
Channel
Debug

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 1545: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Masterkey history: failed size consistency check. Param1, Param2, Param3.

Message #

%1.%2: Masterkey history: failed size consistency check.  %3, %4, %5

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UInt32
Param2 UInt32
Param3 UInt32

Event ID 4096: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Encrypted keys not equal.

Message #

%1.%2: Encrypted keys not equal

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4097: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: doing a REKEY, but the DDF entry already exists.

Message #

%1.%2: doing a REKEY, but the DDF entry already exists

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4098: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: replace operation added a DDF (unexpected).

Message #

%1.%2: replace operation added a DDF (unexpected)

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4099: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: user is modifying a DDF entry not matching the PoP entry. Require WRITE_ATTRIBUTES.

Message #

%1.%2: user is modifying a DDF entry not matching the PoP entry.  Require WRITE_ATTRIBUTES

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4100: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: user is modifying a DDF matching the PoP entry, or the DRF. Don't require WRITE_ATTRIBUTES.

Message #

%1.%2: user is modifying a DDF matching the PoP entry, or the DRF.  Don't require WRITE_ATTRIBUTES

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4101: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: UNEXPECTED condition: no ENCRYPTED_KEY for SC failure.

Message #

%1.%2: UNEXPECTED condition: no ENCRYPTED_KEY for SC failure

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4102: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Plug-n-Play service not ready. EFS server will not try to detect interrupted encryption/decryption operation(s).

Message #

%1.%2: Plug-n-Play service not ready. EFS server will not try to detect interrupted encryption/decryption operation(s).

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4353: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Cannot open log file. Encryption/decryption operation(s) cannot be recovered.

Message #

%1.%2: Cannot open log file. Encryption/decryption operation(s) cannot be recovered.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4354: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Cannot read log file. Encryption/decryption operation(s) cannot be recovered.

Message #

%1.%2: Cannot read log file. Encryption/decryption operation(s) cannot be recovered.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4355: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: A corrupted or different format log file has been found. No action was taken.

Message #

%1.%2: A corrupted or different format log file has been found. No action was taken.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4356: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: The log file cannot be opened as non-cached IO. No action was taken.

Message #

%1.%2: The log file cannot be opened as non-cached IO. No action was taken.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4357: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Interrupted encryption/decryption operation(s) found on a volume. Recovery procedure started.

Message #

%1.%2: Interrupted encryption/decryption operation(s) found on a volume. Recovery procedure started.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4358: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS recovery service cannot open the file Param1. The interrupted encryption/decryption operation cannot be recovered.

Message #

%1.%2: EFS recovery service cannot open the file %3. The interrupted encryption/decryption operation cannot be recovered.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4359: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS service recovered Param1 successfully.

Message #

%1.%2: EFS service recovered %3 successfully.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4360: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS service could not open all the streams on file Param1 The file was not recovered.

Message #

%1.%2: EFS service could not open all the streams on file %3  The file was not recovered.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4361: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Param1 could not be recovered Completely. EFS driver may be missing.

Message #

%1.%2: %3 could not be recovered Completely.  EFS driver may be missing.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4368: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: IO Error occurred during stream recovery. Param1 was not recovered.

Message #

%1.%2: IO Error occurred during stream recovery.  %3 was not recovered.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4369: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS recovery service cannot open the backup file Param1 by name. The interrupted encryption/decryption operation (on file Param2) may be recovered. The backup file will not be deleted. User should delete the backup file if the recovery operation is done successfully.

Message #

%1.%2: EFS recovery service cannot open the backup file %3 by name. The interrupted encryption/decryption operation (on file %4) may be recovered.  The backup file will not be deleted. User should delete the backup file if the recovery operation is done successfully.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString

Event ID 4370: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Param1 was opened by File ID successfully the first time but not the second time. No recovery operation was tried on file Param2. This is an internal error.

Message #

%1.%2: %3 was opened by File ID successfully the first time but not the second time. No recovery operation was tried on file %4. This is an internal error.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString

Event ID 4371: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS recovery service cannot get the backup file name. The interrupted encryption/decryption operation (on file Param1) may be recovered. The temporary backup file Param2 is not deleted. User should delete the backup file if the recovery operation is done successfully.

Message #

%1.%2: EFS recovery service cannot get the backup file name. The interrupted encryption/decryption operation (on file %3) may be recovered.  The temporary backup file %4 is not deleted.  User should delete the backup file if the recovery operation is done successfully.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString

Event ID 4372: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Param1 could not be opened. Param2 was not recovered.

Message #

%1.%2: %3 could not be opened. %4 was not recovered.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString

Event ID 4373: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Stream Information could not be got from Param1. Param2 was not recovered.

Message #

%1.%2: Stream Information could not be got from %3. %4 was not recovered.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString

Event ID 4374: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS service could not open all the streams on file Param1. Param2 was not recovered.

Message #

%1.%2: EFS service could not open all the streams on file %3.  %4 was not recovered.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString

Event ID 4375: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: EFS Service received logon notification.

Message #

%1.%2: EFS Service received logon notification.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4376: EFS Service failed to start.

#
Channel
Application

Description

EFS Service failed to start. Error code: ErrorCode.

Message #

EFS Service failed to start. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4377: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: User cache entry purged. Reference count: Param.

Message #

%1.%2: User cache entry purged. Reference count: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param UInt32

Event ID 4378: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: All user cache entries purged. Reference count: Param.

Message #

%1.%2: All user cache entries purged. Reference count: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param UInt32

Event ID 4379: EFS service was unable to populate SID information.

#
Channel
Application

Description

EFS service was unable to populate SID information. Error code: ErrorCode.

Message #

EFS service was unable to populate SID information. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4380: EFS service was unable to determine the computer name.

#
Channel
Application

Description

EFS service was unable to determine the computer name. Error code: ErrorCode.

Message #

EFS service was unable to determine the computer name. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4381: EFS service was unable to initialize cache lock.

#
Channel
Application

Description

EFS service was unable to initialize cache lock. Error code: ErrorCode.

Message #

EFS service was unable to initialize cache lock. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4382: EFS service was unable to initialize the BCrypt Algorithm Provider.

#
Channel
Application

Description

EFS service was unable to initialize the BCrypt Algorithm Provider. Error code: ErrorCode.

Message #

EFS service was unable to initialize the BCrypt Algorithm Provider. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4383: EFS service was unable to query Software Licensing for the cache size.

#
Channel
Application

Description

EFS service was unable to query Software Licensing for the cache size. Error code: ErrorCode.

Message #

EFS service was unable to query Software Licensing for the cache size. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4384: EFS service was unable to open handle to the MS_DEF_PROV provider.

#
Channel
Application

Description

EFS service was unable to open handle to the MS_DEF_PROV provider. Error code: ErrorCode.

Message #

EFS service was unable to open handle to the MS_DEF_PROV provider. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4385: EFS service was unable to setup notifications from LSA.

#
Channel
Application

Description

EFS service was unable to setup notifications from LSA. Error code: ErrorCode.

Message #

EFS service was unable to setup notifications from LSA. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4386: EFS service was unable to initialize the recovery policy resource.

#
Channel
Application

Description

EFS service was unable to initialize the recovery policy resource. Error code: ErrorCode.

Message #

EFS service was unable to initialize the recovery policy resource. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4387: EFS service was unable process the recovery policy.

#
Channel
Application

Description

EFS service was unable process the recovery policy. Error code: ErrorCode.

Message #

EFS service was unable process the recovery policy. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4388: EFS service was unable to notify NTFS of its state.

#
Channel
Application

Description

EFS service was unable to notify NTFS of its state. Error code: ErrorCode.

Message #

EFS service was unable to notify NTFS of its state. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4389: EFS service was unable to setup group policy change notifications.

#
Channel
Application

Description

EFS service was unable to setup group policy change notifications. Error code: ErrorCode.

Message #

EFS service was unable to setup group policy change notifications. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4390: EFS service was unable to process active user sessions.

#
Channel
Application

Description

EFS service was unable to process active user sessions. Error code: ErrorCode.

Message #

EFS service was unable to process active user sessions. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4391: Encrypting File System server ready to accept calls.

#
Channel
Debug

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4392: FileNumber.

#
Channel
Application

Description

FileNumber.LineNumber: EFS service failed to subscribe for updates to an MDM policy. Index: ErrorCode.

Message #

%1.%2: EFS service failed to subscribe for updates to an MDM policy. Index: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4393: FileNumber.

#
Channel
Application

Description

FileNumber.LineNumber: Failed to initialize one or more synchronization objects. Error code: ErrorCode.

Message #

%1.%2: Failed to initialize one or more synchronization objects. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4400: FileNumber.

#
Channel
Application

Description

FileNumber.LineNumber: EFS service failed to process MDM policy updates. Error code: ErrorCode.

Message #

%1.%2: EFS service failed to process MDM policy updates. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4401: FileNumber.

#
Channel
Application

Description

FileNumber.LineNumber: EFS service failed to provision a user for Windows Information Protection. Error code: ErrorCode.

Message #

%1.%2: EFS service failed to provision a user for Windows Information Protection. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4402: FileNumber.

#
Channel
Application

Description

FileNumber.LineNumber: EFS service failed to provision a user for DPL. Error code: ErrorCode.

Message #

%1.%2: EFS service failed to provision a user for DPL. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4403: FileNumber.

#
Channel
Application

Description

FileNumber.LineNumber: EFS service failed to initialize file encryption queues. Error code: ErrorCode.

Message #

%1.%2: EFS service failed to initialize file encryption queues. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4404: FileNumber.

#
Channel
Application

Description

FileNumber.LineNumber: Recovery policy data is in an invalid format. Error code: ErrorCode.

Message #

%1.%2: Recovery policy data is in an invalid format. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4405: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Start: Param1.

Message #

%1.%2: Start: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4406: Code.

#
Channel
Debug

Description

Code.FileNumber: Complete: LineNumber. Code: Param1.

Message #

%1.%2: Complete: %3. Code: %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 HexInt32

Event ID 4407: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Error Code: Param1.

Message #

%1.%2: Error Code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 HexInt32

Event ID 4408: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Status Code: Param1.

Message #

%1.%2: Status Code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 HexInt32

Event ID 4409: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Enter: Param1.

Message #

%1.%2: Enter: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4410: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Leave: Param1.

Message #

%1.%2: Leave: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4411: Code.

#
Channel
Debug

Description

Code.FileNumber: Leave: LineNumber. Code: Param1.

Message #

%1.%2: Leave: %3. Code: %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 HexInt32

Event ID 4412: Code.

#
Channel
Debug

Description

Code.FileNumber: Error: LineNumber. Code: Param1.

Message #

%1.%2: Error: %3. Code: %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 HexInt32

Event ID 4413: Code.

#
Channel
Debug

Description

Code.FileNumber: Warning: LineNumber. Code: Param1.

Message #

%1.%2: Warning: %3. Code: %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 HexInt32

Event ID 4414: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Param1. Code: Param2.

Message #

%1.%2: %3. Code: %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 HexInt32

Event ID 4415: FileNumber.

#
Channel
Debug

Description

FileNumber.LineNumber: Param1. Value: Param2.

Message #

%1.%2: %3. Value: %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UInt32

Event ID 4416: Code.

#
Channel
Debug

Description

Code.FileNumber: Complete: LineNumber. Code: Param1.

Message #

%1.%2: Complete: %3. Code: %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 HexInt32

Event ID 4417: Code.

#
Channel
Debug

Description

Code.FileNumber: Leave: LineNumber. Code: Param1.

Message #

%1.%2: Leave: %3. Code: %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 HexInt32

Event ID 4418: FileNumber.

#
Channel
Application

Description

FileNumber.LineNumber: EFS service failed to provision RMS for Windows Information Protection. Error code: ErrorCode.

Message #

%1.%2: EFS service failed to provision RMS for Windows Information Protection. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4419: Thread ThreadId: File, Line LineNumber, HRESULT HRESULT, Message: 'Message'.

#
Channel
Debug

Message #

Thread %1: %2, Line %3, HRESULT %4, Message: '%5'

Fields #

NameDescription
ThreadId HexInt32
File AnsiString
LineNumber UInt32
HRESULT HexInt32
Message UnicodeString

Event ID 4420: A client attempted to call an EFS service API without privacy level authentication.

#
Channel
Application

Description

A client attempted to call an EFS service API without privacy level authentication. Error code: ErrorCode. See https://go.microsoft.com/fwlink/?linkid=2181030.

Message #

A client attempted to call an EFS service API without privacy level authentication. Error code: %3. See https://go.microsoft.com/fwlink/?linkid=2181030.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4421: A client that called an EFS service API without privacy level authentication was allowed.

#
Channel
Application

Description

A client that called an EFS service API without privacy level authentication was allowed. See https://go.microsoft.com/fwlink/?linkid=2181030.

Message #

A client that called an EFS service API without privacy level authentication was allowed. See https://go.microsoft.com/fwlink/?linkid=2181030.

Event ID 4422: Failed to unprotect device user credential key using Windows Hello for user: Param1.

#
Channel
Operational

Description

Failed to unprotect device user credential key using Windows Hello for user: Param1. Error code: Param2.

Message #

Failed to unprotect device user credential key using Windows Hello for user: %3. Error code: %4

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UInt32

Event ID 4423: Personal Data Encryption and Windows Hello status updated: 1) Windows Hello availability: Param1; 2) Windows Hello logon capability: Param2; 3) Windows Hel...

#
Channel
Operational

Description

Personal Data Encryption and Windows Hello status updated: 1) Windows Hello availability: Param1; 2) Windows Hello logon capability: Param2; 3) Windows Hello hardware capability: Param3; 4) Remote Desktop remote connections disabled: Param4; 5) Windows automatic restart sign-on disabled: Param5.

Message #

Personal Data Encryption and Windows Hello status updated: 1) Windows Hello availability: %3; 2) Windows Hello logon capability: %4; 3) Windows Hello hardware capability: %5; 4) Remote Desktop remote connections disabled: %6; 5) Windows automatic restart sign-on disabled: %7.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UInt32
Param2 UInt32
Param3 UInt32
Param4 UInt32
Param5 UInt32

Event ID 4424: Personal Data Encryption enabled for user Param1.

#
Channel
Operational

Message #

Personal Data Encryption enabled for user %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4425: Personal Data Encryption disabled for user Param1.

#
Channel
Operational

Description

Personal Data Encryption disabled for user Param1. 1) Policy value: Param2; and 2) Is opted out: Param3.

Message #

Personal Data Encryption disabled for user %3. 1) Policy value: %4; and 2) Is opted out: %5.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UInt32
Param3 UInt32

Event ID 4432: User Param1 attempted to access user Param2's data protected with Personal Data Encryption and was denied.

#
Channel
Operational

Message #

User %3 attempted to access user %4's data protected with Personal Data Encryption and was denied.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString

Event ID 4433: Personal Data Encryption conversion started.

#
Channel
Operational

Message #

Personal Data Encryption conversion started.
Mode: "%3",
paths in policy: "%4",
paths protected: "%5",
paths attempted: "%6",
status: %7.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString
Param4 UnicodeString
Param5 UInt32

Event ID 4434: Personal Data Encryption conversion completed.

#
Channel
Operational

Message #

Personal Data Encryption conversion completed.
Mode: "%3",
paths in policy: "%4",
paths protected: "%5",
paths attempted: "%6",
status: %7,
number of items converted: %8 (total bytes converted: %9),
number of system items : %10,
number of read-only files : %11,
number of items looked at : %12.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString
Param4 UnicodeString
Param5 UInt32
Param6 UInt64
Param7 UInt64
Param8 UInt64
Param9 UInt64
Param10 UInt64

Event ID 4435: Personal Data Encryption conversion did not complete.

#
Channel
Operational

Message #

Personal Data Encryption conversion did not complete.
Mode: "%3",
paths in policy: "%4",
paths protected: "%5",
paths attempted: "%6",
status: %7,
number of items converted: %8 (total bytes converted: %9),
number of system items: %10,
number of read-only files : %11,
number of items looked at : %12,
number of unknown failures: %13,
number of items not protectable: %14.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString
Param4 UnicodeString
Param5 UInt32
Param6 UInt64
Param7 UInt64
Param8 UInt64
Param9 UInt64
Param10 UInt64
Param11 UInt64
Param12 UInt64

Event ID 4436: Personal Data Encryption conversion failed to convert one or more files or folders.

#
Channel
Operational

Description

Personal Data Encryption conversion failed to convert one or more files or folders. First encountered failure on file or folder "Param1" was Param2.

Message #

Personal Data Encryption conversion failed to convert one or more files or folders. First encountered failure on file or folder "%3" was %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UInt32

Event ID 4437: Personal Data Encryption policy for Desktop folder is set to Param2 for user Param1.

#
Channel
Operational

Message #

Personal Data Encryption policy for Desktop folder is set to %4 for user %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UInt32

Event ID 4438: Personal Data Encryption policy for Documents folder is set to Param2 for user Param1.

#
Channel
Operational

Message #

Personal Data Encryption policy for Documents folder is set to %4 for user %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UInt32

Event ID 4439: Personal Data Encryption policy for Pictures folder is set to Param2 for user Param1.

#
Channel
Operational

Message #

Personal Data Encryption policy for Pictures folder is set to %4 for user %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UInt32

Event ID 4440: Personal Data Encryption policy for Desktop folder is deleted for user Param1.

#
Channel
Operational

Message #

Personal Data Encryption policy for Desktop folder is deleted for user %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4441: Personal Data Encryption policy for Documents folder is deleted for user Param1.

#
Channel
Operational

Message #

Personal Data Encryption policy for Documents folder is deleted for user %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4448: Personal Data Encryption policy for Pictures folder is deleted for user Param1.

#
Channel
Operational

Message #

Personal Data Encryption policy for Pictures folder is deleted for user %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4449: Personal Data Encryption policy for Desktop folder is mapped to path "Param1" for user Param2.

#
Channel
Operational

Message #

Personal Data Encryption policy for Desktop folder is mapped to path "%3" for user %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString

Event ID 4450: Personal Data Encryption policy for Documents folder is mapped to path "Param1" for user Param2.

#
Channel
Operational

Message #

Personal Data Encryption policy for Documents folder is mapped to path "%3" for user %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString

Event ID 4451: Personal Data Encryption policy for Pictures folder is mapped to path "Param1" for user Param2.

#
Channel
Operational

Message #

Personal Data Encryption policy for Pictures folder is mapped to path "%3" for user %4.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString
Param2 UnicodeString

Event ID 4452: Personal Data Encryption: paths to protect folders is empty for user Param1.

#
Channel
Operational

Message #

Personal Data Encryption: paths to protect folders is empty for user %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param1 UnicodeString

Event ID 4453: Windows Information Protection has been disabled.

#
Channel
Operational

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4454: Windows Information Protection could not be disabled.

#
Channel
Operational

Description

Windows Information Protection could not be disabled. Error code: ErrorCode.

Message #

Windows Information Protection could not be disabled. Error code: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
ErrorCode HexInt32

Event ID 4455: Personal Data Encryption conversion did not complete the last time it was run.

#
Channel
Operational

Description

Personal Data Encryption conversion did not complete the last time it was run. Last run mode: Param.

Message #

Personal Data Encryption conversion did not complete the last time it was run. Last run mode: %3.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32
Param UInt32

Event ID 4456: Personal Data Encryption is not available for the current device.

#
Channel
Operational

Description

Personal Data Encryption is not available for the current device. Only Azure AD joined devices are supported.

Message #

Personal Data Encryption is not available for the current device. Only Azure AD joined devices are supported.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 4457: Personal Data Encryption is not available for the current device.

#
Channel
Operational

Description

Personal Data Encryption is not available for the current device. Supported device types are Azure AD joined and Hybrid Azure AD joined devices.

Message #

Personal Data Encryption is not available for the current device. Supported device types are Azure AD joined and Hybrid Azure AD joined devices.

Fields #

NameDescription
FileNumber UInt32
LineNumber UInt32

Event ID 7000: Machine role cannot be determined.

#
Channel
Application

Description

Machine role cannot be determined. Reason.

Message #

Machine role cannot be determined. %1

Fields #

NameDescription
Reason UnicodeString

Event ID 7002: Default group policy object cannot be created.

#
Channel
Application
Level
Error

Description

Default group policy object cannot be created. Reason.

Message #

Default group policy object cannot be created. %1

Fields #

NameDescription
Reason UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-EFS",
    "guid": "{3663A992-84BE-40EA-BBA9-90C7ED544222}",
    "event_source_name": "",
    "event_id": 7002,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-28T03:43:46.9077024+00:00",
    "event_record_id": 230,
    "correlation": {},
    "execution": {
      "process_id": 4940,
      "thread_id": 5316
    },
    "channel": "Application",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1000"
    }
  },
  "event_data": {
    "Reason": "Error 80070005 to open GPO Domain EFS Recovery Policy in domain LDAP://DC=cell-d,DC=ludus,DC=domain."
  },
  "message": "Default group policy object cannot be created. Error 80070005 to open GPO Domain EFS Recovery Policy in domain LDAP://DC=cell-d,DC=ludus,DC=domain."
}

Provenance

ETW provider GUID 3663a992-84be-40ea-bba9-90c7ed544222

Defined in efscore.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB