Microsoft-Windows-FeatureConfiguration
11 events across 2 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1001 | Failed to synchronize with the Group Policy service. | Operational | N |
| 1002 | Ignoring unsupported feature state policy override registry value. | Operational | N |
| 1004 | Failed to backup applied feature overrides. | Operational | N |
| 1005 | Setting feature state by enterprise policies. | Operational | Y |
| 1006 | Resetting feature FeatureId to its default state. | Operational | N |
| 1007 | task_0 | Operational | N |
| 1008 | task_01008 | Operational | Y |
| 1009 | task_01009 | Operational | Y |
| 1010 | task_01010 | Operational | Y |
| 5001 | Feature configuration started | Analytic | N |
| 5002 | Feature configuration completed | Analytic | N |
Event ID 1001: Failed to synchronize with the Group Policy service.
#Event ID 1002: Ignoring unsupported feature state policy override registry value.
#Event ID 1004: Failed to backup applied feature overrides.
#Event ID 1005: Setting feature state by enterprise policies.
#Description
Setting feature state by enterprise policies.
Message #
Fields #
| Name | Description |
|---|---|
FeatureId UInt32 | |
FeatureState UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-FeatureConfiguration",
"guid": "{C2F36562-A1E4-4BC3-A6F6-01A7ADB643E8}",
"event_source_name": "",
"event_id": 1005,
"version": 0,
"level": 4,
"task": 1001,
"opcode": 11,
"keywords": 4611686018427387904,
"time_created": "2026-03-25T21:58:39.6956368+00:00",
"event_record_id": 7,
"correlation": {},
"execution": {
"process_id": 12160,
"thread_id": 2400
},
"channel": "Microsoft-Windows-FeatureConfiguration/Operational",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"FeatureId": "835989134",
"FeatureState": "2"
},
"message": "Setting feature state by enterprise policies. \r\n\r\nFeature id:835989134 \r\nState:Enabled"
}
Event ID 1006: Resetting feature FeatureId to its default state.
#Event ID 1008: task_01008
#Fields #
| Name | Description |
|---|---|
FeatureId UInt32 | |
Kind UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-FeatureConfiguration",
"guid": "{C2F36562-A1E4-4BC3-A6F6-01A7ADB643E8}",
"event_source_name": "",
"event_id": 1008,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000000002",
"time_created": "2026-06-02T05:50:19.169+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0002-8CC7-85720FEEDC01}"
},
"execution": {
"process_id": 10616,
"thread_id": 8596
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"FeatureId": 51593804,
"Kind": 6
},
"message": ""
}
Event ID 1009: task_01009
#Fields #
| Name | Description |
|---|---|
FeatureId UInt32 | |
Kind UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-FeatureConfiguration",
"guid": "{C2F36562-A1E4-4BC3-A6F6-01A7ADB643E8}",
"event_source_name": "",
"event_id": 1009,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000000004",
"time_created": "2026-06-02T05:50:16.685+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 5972,
"thread_id": 8924
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"FeatureId": 43687372,
"Kind": 2
},
"message": ""
}
Event ID 1010: task_01010
#Fields #
| Name | Description |
|---|---|
FeatureId UInt32 | |
Kind UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-FeatureConfiguration",
"guid": "{C2F36562-A1E4-4BC3-A6F6-01A7ADB643E8}",
"event_source_name": "",
"event_id": 1010,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": "0x0000000000000008",
"time_created": "2026-06-02T05:50:19.173+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{72529F65-EE0F-0001-E37A-8F720FEEDC01}"
},
"execution": {
"process_id": 10616,
"thread_id": 11124
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"FeatureId": 5195825,
"Kind": 2
},
"message": ""
}
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {C2F36562-A1E4-4BC3-A6F6-01A7ADB643E8}
Defined in fcon.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.4484, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4484, captured 2026-06-02