Microsoft-Windows-FeatureConfiguration

11 events across 2 channels

Event ID 1001: Failed to synchronize with the Group Policy service.

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Operational
Task
FeatureConfigurationEvents

Description

Failed to synchronize with the Group Policy service. Aborting feature configuration processing.

Message #

Failed to synchronize with the Group Policy service. Aborting feature configuration processing.

Error: %1

Fields #

NameDescription
ErrorCode Int32

Event ID 1002: Ignoring unsupported feature state policy override registry value.

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Operational
Task
FeatureConfigurationEvents

Description

Ignoring unsupported feature state policy override registry value. Expected REG_DWORD values with integer names.

Message #

Ignoring unsupported feature state policy override registry value. Expected REG_DWORD values with integer names.

Key Name: %1
Value Name: %2
Value Type: %3
Error: %4

Fields #

NameDescription
RegKeyName UnicodeString
ValueName UnicodeString
ValueType UInt32
ErrorCode Int32

Event ID 1004: Failed to backup applied feature overrides.

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Operational
Task
FeatureConfigurationEvents

Description

Failed to backup applied feature overrides.

Message #

Failed to backup applied feature overrides.

Feature configurations may not be reset to their default state if the policy is removed.

Error: %1

Fields #

NameDescription
ErrorCode Int32

Event ID 1005: Setting feature state by enterprise policies.

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Operational
Level
Informational
Task
FeatureConfigurationEvents
Opcode
OpCodeforsettingfeaturestate

Description

Setting feature state by enterprise policies.

Message #

Setting feature state by enterprise policies. 

Feature id:%1 
State:%2

Fields #

NameDescription
FeatureId UInt32
FeatureState UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-FeatureConfiguration",
    "guid": "{C2F36562-A1E4-4BC3-A6F6-01A7ADB643E8}",
    "event_source_name": "",
    "event_id": 1005,
    "version": 0,
    "level": 4,
    "task": 1001,
    "opcode": 11,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-25T21:58:39.6956368+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 12160,
      "thread_id": 2400
    },
    "channel": "Microsoft-Windows-FeatureConfiguration/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "FeatureId": "835989134",
    "FeatureState": "2"
  },
  "message": "Setting feature state by enterprise policies. \r\n\r\nFeature id:835989134 \r\nState:Enabled"
}

Event ID 1006: Resetting feature FeatureId to its default state.

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Operational
Task
FeatureConfigurationEvents
Opcode
OpCodeforre_settingfeaturestate

Description

Resetting feature FeatureId to its default state.

Message #

Resetting feature %1 to its default state.

Fields #

NameDescription
FeatureId UInt32

Event ID 1007: task_0

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Operational

Fields #

NameDescription
FeatureId UInt32
Kind UInt32

Event ID 1008: task_01008

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Operational
Also via
realtime ETW trace
Level
Informational

Fields #

NameDescription
FeatureId UInt32
Kind UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-FeatureConfiguration",
    "guid": "{C2F36562-A1E4-4BC3-A6F6-01A7ADB643E8}",
    "event_source_name": "",
    "event_id": 1008,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000002",
    "time_created": "2026-06-02T05:50:19.169+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-8CC7-85720FEEDC01}"
    },
    "execution": {
      "process_id": 10616,
      "thread_id": 8596
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FeatureId": 51593804,
    "Kind": 6
  },
  "message": ""
}

Event ID 1009: task_01009

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Operational
Also via
realtime ETW trace
Level
Informational

Fields #

NameDescription
FeatureId UInt32
Kind UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-FeatureConfiguration",
    "guid": "{C2F36562-A1E4-4BC3-A6F6-01A7ADB643E8}",
    "event_source_name": "",
    "event_id": 1009,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000004",
    "time_created": "2026-06-02T05:50:16.685+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 5972,
      "thread_id": 8924
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FeatureId": 43687372,
    "Kind": 2
  },
  "message": ""
}

Event ID 1010: task_01010

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Operational
Also via
realtime ETW trace
Level
Informational

Fields #

NameDescription
FeatureId UInt32
Kind UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-FeatureConfiguration",
    "guid": "{C2F36562-A1E4-4BC3-A6F6-01A7ADB643E8}",
    "event_source_name": "",
    "event_id": 1010,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000008",
    "time_created": "2026-06-02T05:50:19.173+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0001-E37A-8F720FEEDC01}"
    },
    "execution": {
      "process_id": 10616,
      "thread_id": 11124
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FeatureId": 5195825,
    "Kind": 2
  },
  "message": ""
}

Event ID 5001: Feature configuration started

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Analytic
Task
FeatureConfigurationEvents
Opcode
Start

Description

Feature configuration started.

Message #

Feature configuration started

Event ID 5002: Feature configuration completed

#
Provider
Microsoft-Windows-FeatureConfiguration
Channel
Analytic
Task
FeatureConfigurationEvents
Opcode
Stop

Description

Feature configuration completed.

Message #

Feature configuration completed

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {C2F36562-A1E4-4BC3-A6F6-01A7ADB643E8}

Defined in fcon.dll, which carries the event manifest.

Observed on:

  • Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.4484, captured 2026-06-02
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4484, captured 2026-06-02

Downloads