Microsoft-Windows-Firewall

Event ID 6400: An attempt to programmatically disable the Windows Defender Firewall using a call to INetFwProfile.

#
Channel
System
Opcode
Info

Description

An attempt to programmatically disable the Windows Defender Firewall using a call to INetFwProfile.FirewallEnabled(FALSE) interface was rejected because this API is not supported on Windows Vista. This has most likely occurred due to an application which is incompatible with Windows Vista. Please contact the application's vendor to make sure you have a Windows Vista compatible application version. Error Code: E_NOTIMPL Caller Process Name: CallerProcessName Process Id: ProcessId Publisher: Publisher

Message #

An attempt to programmatically disable the Windows Defender Firewall using a call to INetFwProfile.FirewallEnabled(FALSE) interface was rejected because this API is not supported on Windows Vista. This has most likely occurred due to an application which is incompatible with Windows Vista. Please contact the application's vendor to make sure you have a Windows Vista compatible application version.

Error Code:		E_NOTIMPL
Caller Process Name: %1
Process Id: %2
Publisher: %3

Fields #

NameDescription
CallerProcessName UnicodeString
ProcessId UInt32
Publisher UnicodeString

References #

Provenance

ETW provider GUID e595f735-b42a-494b-afcd-b68666945cd3

Defined in mpssvc.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3328, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4768, captured 2026-06-02 — Manifest XML pack, 2.0 MB