Microsoft-Windows-EnrollmentPolicyWebService
21 events across 1 channel
Event ID 1: The Certificate Enrollment Policy Web Service has started.
#Description
The Certificate Enrollment Policy Web Service has started.
Message #
Event ID 2: A service end point with URI URL has been configured for this service.
#Description
A service end point with URI URL has been configured for this service. The client authentication scheme is Authentication. Use the Group Policy Management Console or the Certificates snap-in to configure clients with this Certificate Enrollment Policy Web Service information.
Message #
Fields #
| Name | Description |
|---|---|
URL UnicodeString | |
Authentication UnicodeString |
Event ID 3: A service end point with URI URL has been configured for this service.
#Description
A service end point with URI URL has been configured for this service. The configuration of the client authentication scheme or the binding is not recommended. To fix the issue, open the web.config file and verify the binding and security settings. The only supported binding type for this service is wsHttpBinding. The security mode should be either Transport or TransportWithMessageCredential. When the security mode is Transport, the ClientCredentialType should be either Windows or Certificate. When the security mode is TransportWithMessageCredential, the ClientCredentialType should be UserName.
Message #
Fields #
| Name | Description |
|---|---|
URL UnicodeString |
Event ID 4: The Certificate Enrollment Policy Web Service failed to initialize.
#Description
The Certificate Enrollment Policy Web Service failed to initialize. Confirm that the Certificate Enrollment Policy Web Service is properly installed. Try to restart Internet Information Services (IIS) by using iisreset.exe. If the problem persists, enable tracing in the web.config file, restart IIS, attempt to obtain policy information from any client, and then contact Microsoft Customer Service and Support with the trace file information. Error
Message #
Fields #
| Name | Description |
|---|---|
Error Int32 |
Event ID 5: The Certificate Enrollment Policy Web Service has been stopped.
#Description
The Certificate Enrollment Policy Web Service has been stopped.
Message #
Event ID 6: The Active Directory certificate enrollment policy provider has been initialized to target the "DC" domain controller.
#Event ID 7: The Active Directory certificate enrollment policy provider has been initialized to target the default domain controller for the current domain.
#Description
The Active Directory certificate enrollment policy provider has been initialized to target the default domain controller for the current domain.
Message #
Event ID 8: The Active Directory certificate enrollment policy provider failed to initialize.
#Description
The Active Directory certificate enrollment policy provider failed to initialize. Try to restart Internet Information Services (IIS) by using iisreset.exe. If the problem persists, enable tracing in the web.config file, restart IIS, attempt to obtain policy information from any client, and then contact Microsoft Customer Service and Support with the trace file information. Error
Message #
Fields #
| Name | Description |
|---|---|
Error Int32 |
Event ID 9: The Active Directory certificate enrollment policy provider failed to obtain policy information from Active Directory Domain Services (AD DS).
#Description
The Active Directory certificate enrollment policy provider failed to obtain policy information from Active Directory Domain Services (AD DS). The provider will attempt to read the information again in RetryIntervalMs milliseconds. If the problem persists, enable tracing in the web.config file, enable logging by using "certutil -setreg debug 0xffffffe3", restart IIS by using iisreset.exe, attempt to obtain policy information from any client, and then contact Microsoft Customer Service and Support with the information in the trace files and certenroll.log file. Error
Message #
Fields #
| Name | Description |
|---|---|
RetryIntervalMs Int32 | |
Error Int32 |
Event ID 10: There is no enterprise certification authority (CA) configured with the Certificate Enrollment Web Service in the current forest.
#Description
There is no enterprise certification authority (CA) configured with the Certificate Enrollment Web Service in the current forest. Confirm that at least one enterprise CA is available in the forest and that at least one server running the Certificate Enrollment Web Service is configured to work with this CA.
Message #
Event ID 11: No certificate templates in the forest are configured to be sent as part of the policy response.
#Description
No certificate templates in the forest are configured to be sent as part of the policy response. Confirm that the server hosting the Certificate Enrollment Policy Web Service has Read permission to the required templates in this forest and that at least one server hosting the Certificate Enrollment Web Service is configured to work with the certification authorities (CAs) configured to issue the required templates.
Message #
Event ID 12: The certification authority (CA) "CA" cannot be sent as part of the policy response.
#Event ID 13: The certificate template "Template" cannot be sent as part of the policy response.
#Description
The certificate template "Template" cannot be sent as part of the policy response. Use the Certificate Templates snap-in to confirm that this is a valid certificate template. Also confirm that at least one running certification authority (CA) has this template enabled and that at least one Certificate Enrollment Web Service is configured to use this CA. Error
Message #
Fields #
| Name | Description |
|---|---|
Template UnicodeString | |
Error Int32 |
Event ID 14: The certification authority (CA) "CA" associated with the template "Template" cannot be sent as part of the policy response.
#Description
The certification authority (CA) "CA" associated with the template "Template" cannot be sent as part of the policy response. Confirm that the CA is running and that at least one Certificate Enrollment Web Service is configured to use this CA. Error
Message #
Fields #
| Name | Description |
|---|---|
CA UnicodeString | |
Template UnicodeString | |
Error Int32 |
Event ID 15: The URI URL used by the Certificate Enrollment Web Service for certification authority (CA) "CA" is invalid.
#Event ID 16: A certificate template Template has been loaded.
#Event ID 17: A certification authority CA has been loaded.
#Event ID 18: For a list of the OIDs which are loaded please refer to the "Details" pane.
#Event ID 19: The Certificate Enrollment Policy Web Service cannot operate because Windows authentication is not compatible with key based renewal.
#Description
The Certificate Enrollment Policy Web Service cannot operate because Windows authentication is not compatible with key based renewal. To resolve this issue, remove the Certificate Enrollment Policy Web Service. Reconfigure the Setup options to disable key based renewal, or select either user name and password authentication or client certificate authentication, and then run Setup again.
Message #
Event ID 20: A service end point with URI URL has been configured for this service.
#Description
A service end point with URI URL has been configured for this service. The client authentication scheme is Authentication. Only policies that contain certificate templates that are enabled for key based renewal will be returned to the client. Use the Group Policy Management Console or the Certificates snap-in to configure clients with this Certificate Enrollment Policy Web Service information.
Message #
Fields #
| Name | Description |
|---|---|
URL UnicodeString | |
Authentication UnicodeString |
Event ID 21: A service end point with URI URL has been configured for this service.
#Description
A service end point with URI URL has been configured for this service. The client authentication scheme is Authentication. Only policies that contain certificate templates that are enabled for key based renewal will be returned to the client. Client certificates without subject information in the Active Directory database can be used to retrieve certificate templates. Use the Group Policy Management Console or the Certificates snap-in to configure clients with this Certificate Enrollment Policy Web Service information.
Message #
Fields #
| Name | Description |
|---|---|
URL UnicodeString | |
Authentication UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID f64ed6ba-bd9b-4ce1-90fb-7b8765928134
Defined in certadm.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4767, captured 2026-06-02