Microsoft-Windows-GroupPolicy
177 events across 2 channels
Event ID 1002: The processing of Group Policy failed because of a system allocation failure.
#Description
The processing of Group Policy failed because of a system allocation failure. Please ensure the computer is not running low on resources (memory, available disk space). Group Policy processing will be attempted at the next refresh cycle.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Event ID 1006: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not authenticate to the Active Directory service on a domain controller. (LDAP Bind function call failed). Look in the details tab for error code and description.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 1006,
"version": 0,
"level": 2,
"task": 0,
"opcode": 1,
"keywords": 9223372036854775808,
"time_created": "2026-02-18T05:29:01.333607+00:00",
"event_record_id": 1666,
"correlation": {
"ActivityID": "29E96F9C-8911-49C3-99BC-065B1FD48E8E"
},
"execution": {
"process_id": 3396,
"thread_id": 2868
},
"channel": "System",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"SupportInfo1": 1,
"SupportInfo2": 6168,
"ProcessingMode": 0,
"ProcessingTimeInMilliseconds": 156,
"ErrorCode": 82,
"ErrorDescription": "Local Error",
"DCName": ""
},
"message": ""
}
Event ID 1007: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not determine the site associated for this computer, which is required for Group Policy processing.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Event ID 1030: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows attempted to retrieve new Group Policy settings for this user or computer. Look in the details tab for error code and description. Windows will automatically retry this operation at the next refresh cycle. Computers joined to the domain must have proper name resolution and network connectivity to a domain controller for discovery of new Group Policy objects and settings. An event will be logged when Group Policy is successful.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 1030,
"version": 0,
"level": 2,
"task": 0,
"opcode": 1,
"keywords": 9223372036854775808,
"time_created": "2026-02-12T18:17:33.749779+00:00",
"event_record_id": 1267,
"correlation": {
"ActivityID": "B725C8D9-F151-4EBC-ADFE-2827DEDA46D8"
},
"execution": {
"process_id": 4092,
"thread_id": 12968
},
"channel": "System",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
}
},
"event_data": {
"SupportInfo1": 1,
"SupportInfo2": 3018,
"ProcessingMode": 0,
"ProcessingTimeInMilliseconds": 31,
"ErrorCode": 8341,
"ErrorDescription": "A directory service error has occurred. ",
"DCName": "\\\\LAB-DC01.ludus.domain"
},
"message": ""
}
Event ID 1052: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not determine the role of this computer. Role information (Workgroup, Member Server, or Domain Controller) is required to process Group Policy.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString |
Event ID 1053: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not resolve the user name. This could be caused by one of more of the following.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString |
Event ID 1054: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not obtain the name of a domain controller. This could be caused by a name resolution failure. Verify your Domain Name System (DNS) is configured and working correctly.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"event_id": 1054,
"level": 2,
"task": 0,
"opcode": 1,
"time_created": "2026-04-28T02:27:58.4398646+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "System"
},
"event_data": {
"ErrorDescription": "The specified domain either does not exist or could not be contacted. ",
"ProcessingTimeInMilliseconds": "23063",
"SupportInfo1": "1",
"ErrorCode": "1355",
"SupportInfo2": "3051",
"ProcessingMode": "0"
}
}
Event ID 1055: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 1055,
"version": 0,
"level": 2,
"task": 0,
"opcode": 1,
"keywords": -9223372036854775808,
"time_created": "2026-04-16T03:50:58.0913473+00:00",
"event_record_id": 5355,
"correlation": {
"ActivityID": "{A59FF81D-34E6-4364-A733-8CF28EBB6D64}"
},
"execution": {
"process_id": 11488,
"thread_id": 13396
},
"channel": "System",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"SupportInfo1": "1",
"SupportInfo2": "2616",
"ProcessingMode": "0",
"ProcessingTimeInMilliseconds": "1844",
"ErrorCode": "1398",
"ErrorDescription": "There is a time and/or date difference between the client and server. "
},
"message": "The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: \r\na) Name Resolution failure on the current domain controller. \r\nb) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller)."
}
Event ID 1058: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows attempted to read the file FilePath from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following: a) Name Resolution/Network Connectivity to the current domain controller. b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller). c) The Distributed File System (DFS) client has been disabled.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString | |
GPOCNName UnicodeString | |
FilePath UnicodeString |
Event ID 1065: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not evaluate the Windows Management Instrumentation (WMI) filter for the Group Policy object GPOCNName. This could be caused by RSOP being disabled or Windows Management Instrumentation (WMI) service being disabled, stopped, or other WMI errors. Make sure the WMI service is started and the startup type is set to automatic. New Group Policy objects or settings will not process until this event has been resolved.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString | |
GPOCNName UnicodeString |
Event ID 1068: The processing of Group Policy was interrupted.
#Description
The processing of Group Policy was interrupted. Windows prematurely ended the discovery and enforcement of Group Policy settings because the computer was requested to shutdown or the user logged off. Group Policy processing will be attempted next refresh cycle, on the next computer reboot, or the next user logon.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
DCName UnicodeString |
Event ID 1079: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not obtain the list of Group Policy objects applicable for this computer or user. View the event details for more information.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Event ID 1080: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not search the Active Directory organization unit hierarchy. View the event details for more information.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Event ID 1085: Windows failed to apply the ExtensionName settings.
#Description
Windows failed to apply the ExtensionName settings. ExtensionName settings might have its own log file. Please click on the "More information" link.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString | |
ExtensionName UnicodeString | |
ExtensionId UnicodeString |
References #
Event ID 1088: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows attempted to query the list of Group Policy objects and exceeded the maximum limit (999).
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Event ID 1089: Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or u...
#Description
Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or user. This could be caused by RSOP being disabled or Windows Management Instrumentation (WMI) service being disabled, stopped, or other WMI errors. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Event ID 1090: Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or u...
#Description
Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or user. This could be caused by Windows Management Instrumentation (WMI) service being disabled, stopped, or other WMI errors. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
DCName UnicodeString |
Event ID 1091: Windows could not record the Resultant Set of Policy (RSoP) information for the Group Policy extension <.
#Description
Windows could not record the Resultant Set of Policy (RSoP) information for the Group Policy extension <ExtensionName>. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString | |
ExtensionName UnicodeString | |
ExtensionId UnicodeString |
Event ID 1095: Windows encountered an error while recording Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied ...
#Description
Windows encountered an error while recording Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or user. Group Policy settings successfully applied to the computer or user; however, management tools may not report accurately.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Event ID 1096: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not apply the registry-based policy settings for the Group Policy object GPOCNName. Group Policy settings will not be resolved until this event is resolved. View the event details for more information on the file name and path that caused the failure.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString | |
GPOCNName UnicodeString | |
FilePath UnicodeString |
Event ID 1097: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not determine the computer account to enforce Group Policy settings. This may be transient. Group Policy settings, including computer configuration, will not be enforced for this computer.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Event ID 1101: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not locate the directory object DSObjectName. Group Policy settings will not be enforced until this event is resolved. View the event details for more information on this error.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString | |
DSObjectName UnicodeString |
Event ID 1104: Windows was unable to read the Windows Management Instrumentation (WMI) filter information associated with the Group Policy object GPOCNName.
#Description
Windows was unable to read the Windows Management Instrumentation (WMI) filter information associated with the Group Policy object GPOCNName.This may be caused by a deleted WMI Filter defined in the domain that is still in use by Group Policy objects. Group Policy settings for this Group Policy object will not be enforced. Other Group Policy objects may still apply. Windows will attempt to retrieve this information at the next policy cycle. This specific problem may be resolved by identifying all GPOs that reference the WMI filter and removing the references. Contact an administrator if this event recurs for several hours.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString | |
GPOCNName UnicodeString |
Event ID 1109: The user account is in a different forest than the computer account.
#Description
The user account is in a different forest than the computer account. The processing of Group Policy from another forest is not allowed. Group Policy will be processed using Loopback Replace mode. The scope of the user policy settings will be determined by the location of the computer object in Active Directory. The settings will be acquired from the User Configuration of these policies.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
DCName UnicodeString |
Event ID 1110: The processing of Group Policy failed.
#Description
The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest. Ensure the user domain name matches the name of a trusted domain that resides in the same forest as the computer account.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString |
Event ID 1112: The Group Policy Client Side Extension ExtensionName was unable to apply one or more settings because the changes must be processed before system startup or u...
#Description
The Group Policy Client Side Extension ExtensionName was unable to apply one or more settings because the changes must be processed before system startup or user logon. The system will wait for Group Policy processing to finish completely before the next startup or logon for this user, and this may result in slow startup and boot performance.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString | |
ExtensionName UnicodeString | |
ExtensionId UnicodeString |
Event ID 1125: The processing of Group Policy failed because of an internal system error.
#Description
The processing of Group Policy failed because of an internal system error. Please see the Group Policy operational log for the specific error message. An attempt will be made to process Group Policy again at the next refresh cycle.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString |
References #
Event ID 1126: Windows was unable to determine whether new Group Policy settings defined by a network administrator should be enforced for this user or computer b...
#Description
Windows was unable to determine whether new Group Policy settings defined by a network administrator should be enforced for this user or computer because this computer's clock is not synchronized with the clock of one of the domain controllers for the domain. Because of this issue, this computer system may not be in compliance with the network administrator’s requirements, and users of this system may not be able to use some functionality on the network. Windows will periodically attempt to retry this operation, and it is possible that either this system or the domain controller will correct the time settings without intervention by an administrator, so the problem will be corrected. If this issue persists for more than an hour, checking the local system's clock settings to ensure they are accurate and are synchronized with the clocks on the network's domain controllers is one way to resolve this problem. A network administrator may be required to resolve the issue if correcting the local time settings does not address the problem.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 1126,
"version": 0,
"level": 2,
"task": 0,
"opcode": 1,
"keywords": 9223372036854775808,
"time_created": "2026-02-15T19:48:55.427011+00:00",
"event_record_id": 1406,
"correlation": {
"ActivityID": "D02B1188-929A-4E97-B63D-48B93E963B5B"
},
"execution": {
"process_id": 6076,
"thread_id": 10716
},
"channel": "System",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"SupportInfo1": 5,
"SupportInfo2": 347,
"ProcessingMode": 0,
"ProcessingTimeInMilliseconds": 47,
"ErrorCode": 2148074276,
"ErrorDescription": "The clocks on the client and server machines are skewed. ",
"DCName": "\\\\LAB-DC01.ludus.domain"
},
"message": ""
}
Event ID 1127: The processing of Group Policy failed due to an internal error.
#Description
The processing of Group Policy failed due to an internal error. Please look into the Group Policy operational log for the specific error message. An attempt will be made to process Group Policy again at the next refresh cycle.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
DCName UnicodeString |
Event ID 1128: The Group Policy Client Side Extension ExtensionName may have caused the Group Policy Service to terminate unexpectedly.
#Description
The Group Policy Client Side Extension ExtensionName may have caused the Group Policy Service to terminate unexpectedly. To prevent further failures in the Group Policy Service, this extension has been temporarily disabled until after the next system restart. Group Policy settings managed by this extension may no longer be enforced until the system is restarted. The vendor of this extension should be contacted if this issue recurs.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ExtensionName UnicodeString | |
ExtensionId UnicodeString |
Event ID 1129: The processing of Group Policy failed because of lack of network connectivity to a domain controller.
#Description
The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 1129,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-16T11:45:42.9987787+00:00",
"event_record_id": 1391,
"correlation": {
"ActivityID": "{1A907B63-A93F-4756-9C4B-CDD8832FF748}"
},
"execution": {
"process_id": 1616,
"thread_id": 6188
},
"channel": "System",
"computer": "telemetry-W11-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
}
},
"event_data": {
"SupportInfo1": "1",
"SupportInfo2": "2266",
"ProcessingMode": "2",
"ProcessingTimeInMilliseconds": "16",
"ErrorCode": "1222",
"ErrorDescription": "The network is not present or not started. "
},
"message": "The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine gets connected to the domain controller and Group Policy has successfully processed. If you do not see a success message for several hours, then contact your administrator."
}
References #
Event ID 1130: SupportInfo2 failed.
#Description
ScriptType failed. GPO Name : GPODisplayName GPO File System Path : GPOFileSystemPath Script Name: GPOScriptCommandString
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ErrorCode UInt32 | |
ErrorDescription UnicodeString | |
ScriptType UInt32 | |
GPODisplayName UnicodeString | |
GPOFileSystemPath UnicodeString | |
GPOScriptCommandString UnicodeString |
Event ID 1500: The Group Policy settings for the computer were processed successfully.
#Description
The Group Policy settings for the computer were processed successfully. There were no changes detected since the last successful processing of Group Policy.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
DCName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 1500,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T14:33:21.4898521+00:00",
"event_record_id": 4565,
"correlation": {
"ActivityID": "{4CB8FB96-1506-4D59-85DF-9B915C7A0B40}"
},
"execution": {
"process_id": 1736,
"thread_id": 6400
},
"channel": "System",
"computer": "telemetry-DC-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"SupportInfo1": "1",
"SupportInfo2": "4214",
"ProcessingMode": "0",
"ProcessingTimeInMilliseconds": "156",
"DCName": "\\\\telemetry-DC-d.cell-d.ludus.domain"
},
"message": "The Group Policy settings for the computer were processed successfully. There were no changes detected since the last successful processing of Group Policy."
}
Event ID 1501: The Group Policy settings for the user were processed successfully.
#Description
The Group Policy settings for the user were processed successfully. There were no changes detected since the last successful processing of Group Policy.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
DCName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 1501,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": -9223372036854775808,
"time_created": "2026-05-28T11:12:52.8111344+00:00",
"event_record_id": 1856,
"correlation": {
"ActivityID": "{8301D29C-202F-48E8-BD0C-278810E5742D}"
},
"execution": {
"process_id": 1376,
"thread_id": 948
},
"channel": "System",
"computer": "telemetry-DC-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"SupportInfo1": "1",
"SupportInfo2": "4214",
"ProcessingMode": "1",
"ProcessingTimeInMilliseconds": "1672",
"DCName": "\\\\telemetry-DC-d.cell-d.ludus.domain"
},
"message": "The Group Policy settings for the user were processed successfully. There were no changes detected since the last successful processing of Group Policy."
}
Event ID 1502: The Group Policy settings for the computer were processed successfully.
#Description
The Group Policy settings for the computer were processed successfully. New settings from NumberOfGroupPolicyObjects Group Policy objects were detected and applied.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
DCName UnicodeString | |
NumberOfGroupPolicyObjects UInt32 | Number of Group Policy objects that were processed |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 1502,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T06:21:48.6031327+00:00",
"event_record_id": 6403,
"correlation": {
"ActivityID": "{77469AD0-7D18-41C0-B45D-4A830B44DB6F}"
},
"execution": {
"process_id": 1872,
"thread_id": 5536
},
"channel": "System",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"SupportInfo1": "1",
"SupportInfo2": "4195",
"ProcessingMode": "0",
"ProcessingTimeInMilliseconds": "954",
"DCName": "\\\\telemetry-DC-a.cell-a.ludus.domain",
"NumberOfGroupPolicyObjects": "2"
},
"message": "The Group Policy settings for the computer were processed successfully. New settings from 2 Group Policy objects were detected and applied."
}
References #
Event ID 1503: The Group Policy settings for the user were processed successfully.
#Description
The Group Policy settings for the user were processed successfully. New settings from NumberOfGroupPolicyObjects Group Policy objects were detected and applied.
Message #
Fields #
| Name | Description |
|---|---|
SupportInfo1 UInt32 | |
SupportInfo2 UInt32 | |
ProcessingMode UInt32 | |
ProcessingTimeInMilliseconds UInt32 | |
DCName UnicodeString | |
NumberOfGroupPolicyObjects UInt32 | Number of Group Policy objects that were processed |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 1503,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:34:38.149825+00:00",
"event_record_id": 1319,
"correlation": {
"ActivityID": "DCA9073D-A053-4D86-A71A-A22443FB751F"
},
"execution": {
"process_id": 1352,
"thread_id": 1684
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
}
},
"event_data": {
"SupportInfo1": 1,
"SupportInfo2": 4195,
"ProcessingMode": 0,
"ProcessingTimeInMilliseconds": 671,
"DCName": "\\\\WIN-FPV0DSIC9O6.lab.local",
"NumberOfGroupPolicyObjects": 1
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
- Windows Forensic Artifacts https://github.com/Psmths/windows-forensic-artifacts/blob/main/group-policy/evtx-1503-user-gpo-success.md
Event ID 4000: Starting computer boot policy processing for PrincipalSamName.
#Description
Starting computer boot policy processing for PrincipalSamName.
Message #
Fields #
| Name | Description |
|---|---|
PolicyActivityId GUID | Activity id. |
PrincipalSamName UnicodeString | SAM name of the computer account for which GPO processing was started |
IsMachine UInt32 | |
IsDomainJoined Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean | |
IsServiceRestart Boolean | |
ReasonForSyncProcessing UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4000,
"version": 1,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:23:58.0801723+00:00",
"event_record_id": 31550,
"correlation": {
"ActivityID": "{A841B46F-F932-4765-A57F-C992AEC87CA4}"
},
"execution": {
"process_id": 1980,
"thread_id": 2792
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyActivityId": "{a841b46f-f932-4765-a57f-c992aec87ca4}",
"PrincipalSamName": "cell-c\\TELEMETRY-DC-C$",
"IsMachine": "1",
"IsDomainJoined": "true",
"IsBackgroundProcessing": "false",
"IsAsyncProcessing": "false",
"IsServiceRestart": "false",
"ReasonForSyncProcessing": "5"
},
"message": "Starting computer boot policy processing for cell-c\\TELEMETRY-DC-C$. \r\nActivity id: {a841b46f-f932-4765-a57f-c992aec87ca4}"
}
References #
Event ID 4001: Starting user logon Policy processing for PrincipalSamName.
#Description
Starting user logon Policy processing for PrincipalSamName.
Message #
Fields #
| Name | Description |
|---|---|
PolicyActivityId GUID | Activity id. |
PrincipalSamName UnicodeString | SAM name of the user account for which GPO processing was started |
IsMachine UInt32 | |
IsDomainJoined Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean | |
IsServiceRestart Boolean | |
ReasonForSyncProcessing UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4001,
"version": 1,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:23:59.5469576+00:00",
"event_record_id": 31589,
"correlation": {
"ActivityID": "{DC96B6CB-CED9-4463-8C28-581ADFFD8E96}"
},
"execution": {
"process_id": 1980,
"thread_id": 2780
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyActivityId": "{dc96b6cb-ced9-4463-8c28-581adffd8e96}",
"PrincipalSamName": "cell-c\\domainadmin",
"IsMachine": "0",
"IsDomainJoined": "true",
"IsBackgroundProcessing": "false",
"IsAsyncProcessing": "false",
"IsServiceRestart": "false",
"ReasonForSyncProcessing": "5"
},
"message": "Starting user logon Policy processing for cell-c\\domainadmin. \r\nActivity id: {dc96b6cb-ced9-4463-8c28-581adffd8e96}"
}
References #
Event ID 4002: Starting policy processing due to network state change for computer PolicyActivityId.
#Description
Starting policy processing due to network state change for computer PolicyActivityId.
Message #
Fields #
| Name | Description |
|---|---|
PolicyActivityId GUID | |
PrincipalSamName UnicodeString | |
IsMachine UInt32 | |
IsDomainJoined Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean | |
IsServiceRestart Boolean | |
ReasonForSyncProcessing UInt32 |
Event ID 4003: Starting policy processing due to network state change for user PolicyActivityId.
#Description
Starting policy processing due to network state change for user PolicyActivityId.
Message #
Fields #
| Name | Description |
|---|---|
PolicyActivityId GUID | |
PrincipalSamName UnicodeString | |
IsMachine UInt32 | |
IsDomainJoined Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean | |
IsServiceRestart Boolean | |
ReasonForSyncProcessing UInt32 |
Event ID 4004: Starting manual processing of policy for computer PrincipalSamName.
#Description
Starting manual processing of policy for computer PrincipalSamName.
Message #
Fields #
| Name | Description |
|---|---|
PolicyActivityId GUID | Activity id. |
PrincipalSamName UnicodeString | SAM name of the computer account for which GPO processing was started |
IsMachine UInt32 | |
IsDomainJoined Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean | |
IsServiceRestart Boolean | |
ReasonForSyncProcessing UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4004,
"version": 1,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-05-29T06:52:27.2496306+00:00",
"event_record_id": 29388,
"correlation": {
"ActivityID": "{84ECAB31-F9E8-4B4F-A2FD-465D7AC5C011}"
},
"execution": {
"process_id": 1864,
"thread_id": 5828
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyActivityId": "{84ecab31-f9e8-4b4f-a2fd-465d7ac5c011}",
"PrincipalSamName": "cell-c\\TELEMETRY-DC-C$",
"IsMachine": "1",
"IsDomainJoined": "true",
"IsBackgroundProcessing": "true",
"IsAsyncProcessing": "false",
"IsServiceRestart": "false",
"ReasonForSyncProcessing": "0"
},
"message": "Starting manual processing of policy for computer cell-c\\TELEMETRY-DC-C$. \r\nActivity id: {84ecab31-f9e8-4b4f-a2fd-465d7ac5c011}"
}
References #
Event ID 4005: Starting manual processing of policy for user PrincipalSamName.
#Description
Starting manual processing of policy for user PrincipalSamName.
Message #
Fields #
| Name | Description |
|---|---|
PolicyActivityId GUID | Activity id. |
PrincipalSamName UnicodeString | SAM name of the user account for which GPO processing was started |
IsMachine UInt32 | |
IsDomainJoined Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean | |
IsServiceRestart Boolean | |
ReasonForSyncProcessing UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4005,
"version": 1,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:56:40.7919982+00:00",
"event_record_id": 18255,
"correlation": {
"ActivityID": "{805A095A-2906-4A2D-AFAE-826D5D69CA6F}"
},
"execution": {
"process_id": 1904,
"thread_id": 552
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyActivityId": "{805a095a-2906-4a2d-afae-826d5d69ca6f}",
"PrincipalSamName": "cell-a\\domainadmin",
"IsMachine": "0",
"IsDomainJoined": "true",
"IsBackgroundProcessing": "true",
"IsAsyncProcessing": "false",
"IsServiceRestart": "false",
"ReasonForSyncProcessing": "0"
},
"message": "Starting manual processing of policy for user cell-a\\domainadmin. \r\nActivity id: {805a095a-2906-4a2d-afae-826d5d69ca6f}"
}
References #
Event ID 4006: Starting periodic policy processing for computer PrincipalSamName.
#Description
Starting periodic policy processing for computer PrincipalSamName.
Message #
Fields #
| Name | Description |
|---|---|
PolicyActivityId GUID | Activity id. |
PrincipalSamName UnicodeString | |
IsMachine UInt32 | |
IsDomainJoined Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean | |
IsServiceRestart Boolean | |
ReasonForSyncProcessing UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4006,
"version": 1,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.1640288+00:00",
"event_record_id": 34982,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyActivityId": "{dbcfe2fb-1977-4351-9d05-5bf8388c112e}",
"PrincipalSamName": "cell-c\\TELEMETRY-DC-C$",
"IsMachine": "1",
"IsDomainJoined": "true",
"IsBackgroundProcessing": "true",
"IsAsyncProcessing": "false",
"IsServiceRestart": "false",
"ReasonForSyncProcessing": "0"
},
"message": "Starting periodic policy processing for computer cell-c\\TELEMETRY-DC-C$. \r\nActivity id: {dbcfe2fb-1977-4351-9d05-5bf8388c112e}"
}
Event ID 4007: Starting periodic policy processing for user PrincipalSamName.
#Description
Starting periodic policy processing for user PrincipalSamName.
Message #
Fields #
| Name | Description |
|---|---|
PolicyActivityId GUID | |
PrincipalSamName UnicodeString | |
IsMachine UInt32 | |
IsDomainJoined Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean | |
IsServiceRestart Boolean | |
ReasonForSyncProcessing UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 4007,
"version": 1,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-03-14T01:40:41.526525+00:00",
"event_record_id": 179683,
"correlation": {
"ActivityID": "261F3C8C-5577-42F1-99D9-89D7A88E5B00"
},
"execution": {
"process_id": 1112,
"thread_id": 6604
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyActivityId": "261F3C8C-5577-42F1-99D9-89D7A88E5B00",
"PrincipalSamName": "ludus\\domainadmin",
"IsMachine": 0,
"IsDomainJoined": true,
"IsBackgroundProcessing": true,
"IsAsyncProcessing": false,
"IsServiceRestart": false,
"ReasonForSyncProcessing": 0
},
"message": ""
}
Event ID 4016: Starting CSEExtensionName Extension Processing.
#Description
Starting CSEExtensionName Extension Processing.
Message #
Fields #
| Name | Description |
|---|---|
CSEExtensionId GUID | |
CSEExtensionName UnicodeString | |
IsExtensionAsyncProcessing Boolean | |
IsGPOListChanged Boolean | |
GPOListStatusString UnicodeString | |
DescriptionString UnicodeString | |
ApplicableGPOList UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4016,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T13:39:15.5855300+00:00",
"event_record_id": 34796,
"correlation": {
"ActivityID": "{C2EE9D80-D0BC-4B89-9A29-4D244941B824}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"CSEExtensionId": "{827d319e-6eac-11d2-a4ea-00c04f79f83a}",
"CSEExtensionName": "Security",
"IsExtensionAsyncProcessing": "true",
"IsGPOListChanged": "true",
"GPOListStatusString": "%%4102",
"DescriptionString": "Default Domain Policy\nDefault Domain Controllers Policy\n",
"ApplicableGPOList": "<GPO ID=\"{31B2F340-016D-11D2-945F-00C04FB984F9}\"><Name>Default Domain Policy</Name></GPO><GPO ID=\"{6AC1786C-016F-11D2-945F-00C04fB984F9}\"><Name>Default Domain Controllers Policy</Name></GPO>"
},
"message": "Starting Security Extension Processing. \r\n\r\nList of applicable Group Policy objects: (Changes were detected.)\r\n\r\nDefault Domain Policy\nDefault Domain Controllers Policy\n"
}
Event ID 4017: OperationDescription Parameter.
#Description
OperationDescription Parameter
Message #
Fields #
| Name | Description |
|---|---|
OperationDescription UnicodeString | |
Parameter UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4017,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.3157615+00:00",
"event_record_id": 35002,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"OperationDescription": "%%4131",
"Parameter": "\\\\cell-c.ludus.domain\\sysvol\\cell-c.ludus.domain\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\gpt.ini"
},
"message": "Making system calls to access specified file. \r\n\\\\cell-c.ludus.domain\\sysvol\\cell-c.ludus.domain\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\gpt.ini"
}
Event ID 4018: Starting ScriptType for PrincipalSamName.
#Event ID 4019: Running script name ScriptName.
#Event ID 4115: Group Policy Service started.
#Description
Group Policy Service started.
Message #
Fields #
| Name | Description |
|---|---|
IsServiceRestart Boolean | |
IsMachineBoot Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4115,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:22:56.1841189+00:00",
"event_record_id": 31538,
"correlation": {},
"execution": {
"process_id": 1980,
"thread_id": 1052
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"IsServiceRestart": "false",
"IsMachineBoot": "true"
},
"message": "Group Policy Service started."
}
Event ID 4116: Started the Group Policy service initialization phase.
#Description
Started the Group Policy service initialization phase.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4116,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:22:56.1799164+00:00",
"event_record_id": 31537,
"correlation": {},
"execution": {
"process_id": 1980,
"thread_id": 1052
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "Started the Group Policy service initialization phase."
}
Event ID 4117: Group Policy Session started.
#Description
Group Policy Session started.
Message #
Fields #
| Name | Description |
|---|---|
IsMachine Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4117,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:23:59.5460185+00:00",
"event_record_id": 31587,
"correlation": {},
"execution": {
"process_id": 1980,
"thread_id": 2780
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"IsMachine": "false",
"IsBackgroundProcessing": "false",
"IsAsyncProcessing": "false"
},
"message": "Group Policy Session started."
}
Event ID 4126: Group Policy receiving applicable GPOs from the domain controller.
#Description
Group Policy receiving applicable GPOs from the domain controller.
Message #
Fields #
| Name | Description |
|---|---|
IsMachine Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4126,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.2842276+00:00",
"event_record_id": 34997,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"IsMachine": "true"
},
"message": "Group Policy receiving applicable GPOs from the domain controller."
}
Event ID 4216: Starting to save policies to the local datastore.
#Description
Starting to save policies to the local datastore.
Message #
Fields #
| Name | Description |
|---|---|
IsMachine Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 4216,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-09T00:48:47.640241+00:00",
"event_record_id": 5485,
"correlation": {
"ActivityID": "9197D599-AFC9-4584-AEA0-64AEB7628F03"
},
"execution": {
"process_id": 2268,
"thread_id": 8268
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
}
},
"event_data": {
"IsMachine": false
},
"message": ""
}
Event ID 4217: Starting to load policies from the local datastore.
#Event ID 4218: Starting the first WMI query for the policy.
#Event ID 4257: Starting to download policies.
#Description
Starting to download policies.
Message #
Fields #
| Name | Description |
|---|---|
IsMachine Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4257,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.2860369+00:00",
"event_record_id": 34998,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"IsMachine": "true",
"IsBackgroundProcessing": "true",
"IsAsyncProcessing": "true"
},
"message": "Starting to download policies."
}
Event ID 4326: Group Policy is trying to discover the Domain Controller information.
#Description
Group Policy is trying to discover the Domain Controller information.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 4326,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.1648966+00:00",
"event_record_id": 34988,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "Group Policy is trying to discover the Domain Controller information."
}
Event ID 5016: Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds milliseconds.
#Description
Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
CSEElaspedTimeInMilliSeconds UInt32 | |
ErrorCode UInt32 | |
CSEExtensionName UnicodeString | |
CSEExtensionId GUID |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5016,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T13:39:16.3255249+00:00",
"event_record_id": 34797,
"correlation": {
"ActivityID": "{C2EE9D80-D0BC-4B89-9A29-4D244941B824}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"CSEElaspedTimeInMilliSeconds": "735",
"ErrorCode": "0",
"CSEExtensionName": "Security",
"CSEExtensionId": "{827d319e-6eac-11d2-a4ea-00c04f79f83a}"
},
"message": "Completed Security Extension Processing in 735 milliseconds."
}
Event ID 5017: OperationDescription Parameter The call completed in OperationElaspedTimeInMilliSeconds milliseconds.
#Description
OperationDescription Parameter The call completed in OperationElaspedTimeInMilliSeconds milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
OperationElaspedTimeInMilliSeconds UInt32 | |
ErrorCode UInt32 | |
OperationDescription UnicodeString | |
Parameter UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5017,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.3186721+00:00",
"event_record_id": 35003,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"OperationElaspedTimeInMilliSeconds": "0",
"ErrorCode": "0",
"OperationDescription": "%%4132",
"Parameter": "\\\\cell-c.ludus.domain\\sysvol\\cell-c.ludus.domain\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\gpt.ini"
},
"message": "The system calls to access specified file completed. \r\n\\\\cell-c.ludus.domain\\sysvol\\cell-c.ludus.domain\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\gpt.ini\r\nThe call completed in 0 milliseconds."
}
Event ID 5018: Completed ScriptType for PrincipalSamName in ScriptElaspedTimeInSeconds seconds.
#Event ID 5019: Completed ScriptName in ScriptElaspedTimeInSeconds seconds.
#Event ID 5115: Group Policy Service stopped.
#Description
Group Policy Service stopped.
Message #
Fields #
| Name | Description |
|---|---|
IsServiceRestart Boolean | |
IsMachineBoot Boolean | |
GpsvcTimeElapsedInMilliseconds UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5115,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:22:33.9370914+00:00",
"event_record_id": 31536,
"correlation": {},
"execution": {
"process_id": 1784,
"thread_id": 1104
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"IsServiceRestart": "false",
"IsMachineBoot": "true",
"GpsvcTimeElapsedInMilliseconds": "6010359"
},
"message": "Group Policy Service stopped."
}
Event ID 5116: Successfully completed the Group Policy Service initialization phase.
#Description
Successfully completed the Group Policy Service initialization phase.
Message #
Fields #
| Name | Description |
|---|---|
GpsvcInitTimeElapsedInMilliseconds UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5116,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:22:56.1891837+00:00",
"event_record_id": 31539,
"correlation": {},
"execution": {
"process_id": 1980,
"thread_id": 2064
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"GpsvcInitTimeElapsedInMilliseconds": "16"
},
"message": "Successfully completed the Group Policy Service initialization phase."
}
Event ID 5117: Group policy session completed successfully.
#Description
Group policy session completed successfully.
Message #
Fields #
| Name | Description |
|---|---|
IsMachine Boolean | |
SessionTimeElapsedInMilliseconds UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5117,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:23:59.6975593+00:00",
"event_record_id": 31616,
"correlation": {
"ActivityID": "{DC96B6CB-CED9-4463-8C28-581ADFFD8E96}"
},
"execution": {
"process_id": 1980,
"thread_id": 2780
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"IsMachine": "false",
"SessionTimeElapsedInMilliseconds": "156"
},
"message": "Group policy session completed successfully."
}
Event ID 5126: Group Policy successfully got applicable GPOs from the domain controller.
#Description
Group Policy successfully got applicable GPOs from the domain controller.
Message #
Fields #
| Name | Description |
|---|---|
IsMachine Boolean | |
IsBackgroundProcessing Boolean | |
IsAsyncProcessing Boolean | |
NumberOfGPOsDownloaded UInt32 | |
NumberOfGPOsApplicable UInt32 | |
GPODownloadTimeElapsedInMilliseconds UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5126,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.3190717+00:00",
"event_record_id": 35005,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"IsMachine": "true",
"IsBackgroundProcessing": "true",
"IsAsyncProcessing": "false",
"NumberOfGPOsDownloaded": "2",
"NumberOfGPOsApplicable": "0",
"GPODownloadTimeElapsedInMilliseconds": "31"
},
"message": "Group Policy successfully got applicable GPOs from the domain controller."
}
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5126
Event ID 5216: Successfully saved policies to the local datastore.
#Description
Successfully saved policies to the local datastore.
Message #
Fields #
| Name | Description |
|---|---|
IsMachine Boolean | |
SaveToCacheTimeElapsedInMilliseconds UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 5216,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-09T00:48:47.649684+00:00",
"event_record_id": 5486,
"correlation": {
"ActivityID": "9197D599-AFC9-4584-AEA0-64AEB7628F03"
},
"execution": {
"process_id": 2268,
"thread_id": 8268
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
}
},
"event_data": {
"IsMachine": false,
"SaveToCacheTimeElapsedInMilliseconds": 16
},
"message": ""
}
Event ID 5217: Successfully loaded policies from the local datastore.
#Event ID 5218: Successfully completed the first WMI query.
#Event ID 5257: Successfully completed downloading policies.
#Description
Successfully completed downloading policies.
Message #
Fields #
| Name | Description |
|---|---|
IsMachine Boolean | |
PolicyDownloadTimeElapsedInMilliseconds UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5257,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.3187075+00:00",
"event_record_id": 35004,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"IsMachine": "true",
"PolicyDownloadTimeElapsedInMilliseconds": "31"
},
"message": "Successfully completed downloading policies."
}
Event ID 5308: Domain Controller details.
#Description
Domain Controller details.
Message #
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | [Domain Controller details] Domain Controller Name. |
DCIPAddress UnicodeString | [Domain Controller details] Domain Controller IP Address. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5308,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.2783668+00:00",
"event_record_id": 34992,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DCName": "telemetry-DC-c.cell-c.ludus.domain",
"DCIPAddress": "10.1.40.11"
},
"message": "Domain Controller details: \r\n\tDomain Controller Name : telemetry-DC-c.cell-c.ludus.domain\r\n\tDomain Controller IP Address : 10.1.40.11"
}
Event ID 5309: Computer details.
#Description
Computer details.
Message #
Fields #
| Name | Description |
|---|---|
MachineRole UInt32 | [Computer details] Computer role. |
NetworkName UnicodeString | [Computer details] Network name. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5309,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.2788342+00:00",
"event_record_id": 34994,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"MachineRole": "3",
"NetworkName": "<none>"
},
"message": "Computer details: \r\n\tComputer role : 3\r\n\tNetwork name : <none>"
}
Event ID 5310: Account details.
#Description
Account details.
Message #
Fields #
| Name | Description |
|---|---|
PrincipalCNName UnicodeString | [Account details] Account Name. |
PrincipalDomainName UnicodeString | [Account details] Account Domain Name. |
DCName UnicodeString | [Account details] DC Name. |
DCDomainName UnicodeString | [Account details] DC Domain Name. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5310,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.2788360+00:00",
"event_record_id": 34995,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PrincipalCNName": "CN=TELEMETRY-DC-C,OU=Domain Controllers,DC=cell-c,DC=ludus,DC=domain",
"PrincipalDomainName": "cell-c.ludus.domain",
"DCName": "\\\\telemetry-DC-c.cell-c.ludus.domain",
"DCDomainName": "cell-c.ludus.domain"
},
"message": "Account details: \r\n\tAccount Name : CN=TELEMETRY-DC-C,OU=Domain Controllers,DC=cell-c,DC=ludus,DC=domain\r\n\tAccount Domain Name : cell-c.ludus.domain\r\n\tDC Name : \\\\telemetry-DC-c.cell-c.ludus.domain\r\n\tDC Domain Name : cell-c.ludus.domain"
}
Event ID 5311: The loopback policy processing mode is PolicyProcessingMode.
#Description
The loopback policy processing mode is PolicyProcessingMode.
Message #
Fields #
| Name | Description |
|---|---|
PolicyProcessingMode UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5311,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.2842257+00:00",
"event_record_id": 34996,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyProcessingMode": "0"
},
"message": "The loopback policy processing mode is \"No loopback mode\"."
}
Event ID 5312: List of applicable Group Policy objects.
#Description
List of applicable Group Policy objects.
Message #
Fields #
| Name | Description |
|---|---|
DescriptionString UnicodeString | List of applicable Group Policy objects |
GPOInfoList UnicodeString | XML string containing information about the applicable Group Policy objects |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5312,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.3194250+00:00",
"event_record_id": 35006,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DescriptionString": "Default Domain Policy\nDefault Domain Controllers Policy\n",
"GPOInfoList": "<GPO ID=\"{31B2F340-016D-11D2-945F-00C04FB984F9}\"><Name>Default Domain Policy</Name><Version>262148</Version><SOM>LDAP://DC=cell-c,DC=ludus,DC=domain</SOM><FSPath>\\\\cell-c.ludus.domain\\sysvol\\cell-c.ludus.domain\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\Machine</FSPath><Extensions>[{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{53D6AB1B-2488-11D1-A28C-00C04FB94F17}][{827D319E-6EAC-11D2-A4EA-00C04F79F83A}{803E14A0-B4FB-11D0-A0D0-00A0C90F574B}][{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}{53D6AB1B-2488-11D1-A28C-00C04FB94F17}]</Extensions></GPO><GPO ID=\"{6AC1786C-016F-11D2-945F-00C04fB984F9}\"><Name>Default Domain Controllers Policy</Name><Version>196611</Version><SOM>LDAP://OU=Domain Controllers,DC=cell-c,DC=ludus,DC=domain</SOM><FSPath>\\\\cell-c.ludus.domain\\sysvol\\cell-c.ludus.domain\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\Machine</FSPath><Extensions>[{827D319E-6EAC-11D2-A4EA-00C04F79F83A}{803E14A0-B4FB-11D0-A0D0-00A0C90F574B}]</Extensions></GPO>"
},
"message": "List of applicable Group Policy objects: \r\n\r\nDefault Domain Policy\nDefault Domain Controllers Policy\n"
}
References #
- Windows Forensic Artifacts https://github.com/Psmths/windows-forensic-artifacts/blob/main/group-policy/evtx-5312-list-of-gpo.md
Event ID 5313: The following Group Policy objects were not applicable because they were filtered out.
#Description
The following Group Policy objects were not applicable because they were filtered out.
Message #
Fields #
| Name | Description |
|---|---|
DescriptionString UnicodeString | The following Group Policy objects were not applicable because they were filtered out |
GPOInfoList UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5313,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.3194566+00:00",
"event_record_id": 35007,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DescriptionString": "Local Group Policy\n\tNot Applied (Empty)\n",
"GPOInfoList": "<GPO ID=\"Local Group Policy\"><Name>Local Group Policy</Name><Version>0</Version><SOM>Local</SOM><FSPath>C:\\Windows\\System32\\GroupPolicy\\Machine</FSPath><Reason>NOTAPPLIED-EMPTY</Reason></GPO>"
},
"message": "The following Group Policy objects were not applicable because they were filtered out : \r\n\r\nLocal Group Policy\n\tNot Applied (Empty)\n"
}
Event ID 5314: A LinkDescription link was detected.
#Description
A LinkDescription link was detected. The Estimated bandwidth is BandwidthInkbps kbps. The slow link threshold is ThresholdInkbps kbps.
Message #
Fields #
| Name | Description |
|---|---|
BandwidthInkbps UInt32 | |
IsSlowLink Boolean | |
ThresholdInkbps UInt32 | |
PolicyApplicationMode UInt32 | |
ErrorCode UInt32 | |
LinkDescription UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"event_id": 5314,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-05-27T16:17:04.9396956+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-GroupPolicy"
},
"event_data": {
"PolicyApplicationMode": "0",
"ErrorCode": "0",
"ThresholdInkbps": "500",
"LinkDescription": "%%4113",
"IsSlowLink": "false",
"BandwidthInkbps": "1410065"
}
}
Event ID 5315: Next policy processing for PrincipalSamName will be attempted in NextPolicyApplicationTime NextPolicyApplicationTimeUnit.
#Description
Next policy processing for PrincipalSamName will be attempted in NextPolicyApplicationTime NextPolicyApplicationTimeUnit.
Message #
Fields #
| Name | Description |
|---|---|
PrincipalSamName UnicodeString | |
NextPolicyApplicationTime UInt32 | |
NextPolicyApplicationTimeUnit UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5315,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.3334593+00:00",
"event_record_id": 35012,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PrincipalSamName": "cell-c\\TELEMETRY-DC-C$",
"NextPolicyApplicationTime": "5",
"NextPolicyApplicationTimeUnit": "%%4100"
},
"message": "Next policy processing for cell-c\\TELEMETRY-DC-C$ will be attempted in 5 minutes."
}
Event ID 5320: InfoDescription.
#Description
InfoDescription
Message #
Fields #
| Name | Description |
|---|---|
InfoDescription UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5320,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.3235606+00:00",
"event_record_id": 35010,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"InfoDescription": "%%4165"
},
"message": "Finished checking for non-system extensions."
}
Event ID 5321: InfoDescription Parameter: OperationParameter1.
#Description
InfoDescription Parameter: OperationParameter1.
Message #
Fields #
| Name | Description |
|---|---|
InfoDescription UnicodeString | |
OperationParameter1 UnicodeString | 1 Parameter. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5321,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:22:56.2755729+00:00",
"event_record_id": 31543,
"correlation": {},
"execution": {
"process_id": 1980,
"thread_id": 2064
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"InfoDescription": "%%4167",
"OperationParameter1": "ea290edc-1514-4f09-bb35-db08da390e9d"
},
"message": "A previous instance of the Group Policy Client Service was detected. Parameter: ea290edc-1514-4f09-bb35-db08da390e9d"
}
Event ID 5322: Group Policy waited for TimeWaitedAtStartup milliseconds for the network subsystem at computer boot.
#Description
Group Policy waited for TimeWaitedAtStartup milliseconds for the network subsystem at computer boot.
Message #
Fields #
| Name | Description |
|---|---|
IsPolicyConfigured Boolean | |
MaxTimeToWait UInt32 | |
TimeWaitedAtStartup UInt32 | |
PrevAvgWaitTimeout UInt32 | |
NewAvgWaitTimeout UInt32 | |
DidWaitTimeout Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5322,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:23:58.0799894+00:00",
"event_record_id": 31549,
"correlation": {},
"execution": {
"process_id": 1980,
"thread_id": 2792
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"IsPolicyConfigured": "false",
"MaxTimeToWait": "120000",
"TimeWaitedAtStartup": "61562",
"PrevAvgWaitTimeout": "60000",
"NewAvgWaitTimeout": "60000",
"DidWaitTimeout": "true"
},
"message": "Group Policy waited for 61562 milliseconds for the network subsystem at computer boot."
}
Event ID 5324: Group Policy received the notification NotificationType from Winlogon for session SessionId.
#Description
Group Policy received the notification NotificationType from Winlogon for session SessionId.
Message #
Fields #
| Name | Description |
|---|---|
NotificationType UInt32 | |
SessionId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5324,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:24:00.1241944+00:00",
"event_record_id": 31619,
"correlation": {},
"execution": {
"process_id": 1980,
"thread_id": 2064
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NotificationType": "3",
"SessionId": "1"
},
"message": "Group Policy received the notification StartShell from Winlogon for session 1."
}
Event ID 5325: Group Policy received NotificationType notification from Service Control Manager.
#Description
Group Policy received NotificationType notification from Service Control Manager.
Message #
Fields #
| Name | Description |
|---|---|
NotificationType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5325,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:22:33.9368217+00:00",
"event_record_id": 31535,
"correlation": {},
"execution": {
"process_id": 1784,
"thread_id": 1788
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NotificationType": "0"
},
"message": "Group Policy received Preshutdown notification from Service Control Manager."
}
Event ID 5326: Group Policy successfully discovered the Domain Controller in DCDiscoveryTimeInMilliSeconds milliseconds.
#Description
Group Policy successfully discovered the Domain Controller in DCDiscoveryTimeInMilliSeconds milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
DCDiscoveryTimeInMilliSeconds UInt32 | |
ErrorCode UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5326,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.2783694+00:00",
"event_record_id": 34993,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DCDiscoveryTimeInMilliSeconds": "110",
"ErrorCode": "0"
},
"message": "Group Policy successfully discovered the Domain Controller in 110 milliseconds."
}
Event ID 5327: Estimated network bandwidth on one of the connections: NetworkBandwidthInKbps kbps.
#Description
Estimated network bandwidth on one of the connections: NetworkBandwidthInKbps kbps.
Message #
Fields #
| Name | Description |
|---|---|
NetworkBandwidthInKbps UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"event_id": 5327,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-05-27T16:17:04.9371831+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-GroupPolicy"
},
"event_data": {
"NetworkBandwidthInKbps": "1250000000"
}
}
Event ID 5331: Service configuration update to standalone was attempted due to the presence of Group Policy client extension UpdateCauseExtensionName that is not part of the operating ...
#Description
Service configuration update to standalone was attempted due to the presence of Group Policy client extension UpdateCauseExtensionName that is not part of the operating system and completed with status ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
UpdateCauseExtensionName UnicodeString | |
UpdateCauseExtensionId UnicodeString | |
ErrorCode UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"event_id": 5331,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-04-18T00:27:32.8630314+00:00",
"computer": "WIN11-25H2-X64",
"channel": "Microsoft-Windows-GroupPolicy"
},
"event_data": {
"ErrorCode": "0",
"UpdateCauseExtensionId": "{9F02E2F5-5A41-4D1A-B473-4617E84BC957}",
"UpdateCauseExtensionName": "Windows Protected Print Policy"
}
}
Event ID 5332: Group Policy waited for TimeWaitedAtStartup milliseconds for the Direct Access CorpNet connectivity at computer boot.
#Event ID 5340: The Group Policy processing mode is PolicyApplicationMode.
#Description
The Group Policy processing mode is PolicyApplicationMode.
Message #
Fields #
| Name | Description |
|---|---|
PolicyApplicationMode UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5340,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.1643929+00:00",
"event_record_id": 34983,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyApplicationMode": "0"
},
"message": "The Group Policy processing mode is Background."
}
Event ID 5351: Group policy session returned to winlogon.
#Description
Group policy session returned to winlogon.
Message #
Fields #
| Name | Description |
|---|---|
IsMachine Boolean | |
WinlogonReturnTimeElapsedInMilliseconds UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 5351,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:23:59.6975731+00:00",
"event_record_id": 31618,
"correlation": {},
"execution": {
"process_id": 1980,
"thread_id": 2064
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"IsMachine": "false",
"WinlogonReturnTimeElapsedInMilliseconds": "156"
},
"message": "Group policy session returned to winlogon."
}
Event ID 6016: Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds milliseconds.
#Event ID 6033: Skipped CSEExtensionName Extension based on Group Policy client-side processing rules.
#Event ID 6034: Group Policy changed from synchronous foreground to asynchronous foreground based on slow link detection.
#Description
Group Policy changed from synchronous foreground to asynchronous foreground based on slow link detection.
Message #
Event ID 6035: CSEExtensionName Extension deferred processing until next synchronous foreground.
#Event ID 6314: Group Policy bandwidth estimation failed.
#Description
Group Policy bandwidth estimation failed. Group Policy processing will continue. Assuming LinkDescription link.
Message #
Fields #
| Name | Description |
|---|---|
BandwidthInkbps UInt32 | |
IsSlowLink Boolean | |
ThresholdInkbps UInt32 | |
PolicyApplicationMode UInt32 | |
ErrorCode UInt32 | |
LinkDescription UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 6314,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.3054336+00:00",
"event_record_id": 34999,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"BandwidthInkbps": "0",
"IsSlowLink": "false",
"ThresholdInkbps": "500",
"PolicyApplicationMode": "0",
"ErrorCode": "1",
"LinkDescription": "%%4113"
},
"message": "Group Policy bandwidth estimation failed. Group Policy processing will continue. Assuming fast link."
}
Event ID 6320: Warning: Warning Warning code WarningDescription.
#Event ID 6321: Warning: Warning Parameter: WarningDescription : Warning code Parameter.
#Event ID 6323: Group Policy dependency (DisplayName) did not start.
#Event ID 6330: An unfinished invocation of the Group Policy Client Side Extension InfoDescription from a previous instance of the Group Policy Service was detected.
#Description
An unfinished invocation of the Group Policy Client Side Extension InfoDescription from a previous instance of the Group Policy Service was detected. This may indicate that the extension caused the Group Policy Client Service to terminate unexpectedly.
Message #
Fields #
| Name | Description |
|---|---|
InfoDescription UnicodeString | |
OperationParameter1 UnicodeString |
Event ID 6331: Invalid Error Message.
#Event ID 6337: Group Policy network connection is via Direct Access.
#Description
Group Policy network connection is via Direct Access.
Message #
Event ID 6338: Group Policy Winlogon status reporting has completed.
#Description
Group Policy Winlogon status reporting has completed.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 6338,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:23:59.6975701+00:00",
"event_record_id": 31617,
"correlation": {},
"execution": {
"process_id": 1980,
"thread_id": 2064
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "Group Policy Winlogon status reporting has completed."
}
Event ID 6339: Group Policy Winlogon Start Shell handling completed.
#Description
Group Policy Winlogon Start Shell handling completed.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 6339,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:24:00.1243494+00:00",
"event_record_id": 31620,
"correlation": {},
"execution": {
"process_id": 1980,
"thread_id": 2064
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "Group Policy Winlogon Start Shell handling completed."
}
Event ID 6341: A Group Policy setting was used to override the fast/slow link detection.
#Description
A Group Policy setting was used to override the fast/slow link detection.
Message #
Event ID 6342: The network connection is using a WWAN device for connectivity.
#Description
The network connection is using a WWAN device for connectivity.
Message #
Event ID 6344: Group Policy detected a slow link during sync mode processing.
#Event ID 6345: The connection to DC timed out during the Group Policy sync mode process.
#Event ID 6346: Group Policy switched the sync mode process to async mode.
#Event ID 7000: Computer boot policy processing failed for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Event ID 7001: User logon policy processing failed for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Event ID 7002: Policy processing due to network state change failed for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Event ID 7003: Policy processing due to network state change failed for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Event ID 7004: Manual processing of policy failed for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Event ID 7005: Manual processing of policy failed for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Event ID 7006: Periodic policy processing failed for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Event ID 7007: Periodic policy processing failed for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Event ID 7016: Completed CSEExtensionName Extension Processing in CSEElaspedTimeInMilliSeconds milliseconds.
#Event ID 7017: OperationDescription Parameter The call failed after OperationElaspedTimeInMilliSeconds milliseconds.
#Description
OperationDescription Parameter The call failed after OperationElaspedTimeInMilliSeconds milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
OperationElaspedTimeInMilliSeconds UInt32 | |
ErrorCode UInt32 | |
OperationDescription UnicodeString | |
Parameter UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 7017,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2022-04-07T16:59:24.588821+00:00",
"event_record_id": 562,
"correlation": {
"ActivityID": "178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6"
},
"execution": {
"process_id": 1352,
"thread_id": 4040
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"OperationElaspedTimeInMilliSeconds": 2000,
"ErrorCode": 58,
"OperationDescription": "%%4120",
"Parameter": "WIN-FPV0DSIC9O6.lab.local"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 7018: Script for PrincipalSamName failed in ScriptElaspedTimeInSeconds seconds.
#Event ID 7117: Group policy session completed with error.
#Event ID 7126: Group Policy could not get applicable GPOs from the domain controller.
#Event ID 7216: Saved policies to the local datastore with error.
#Event ID 7217: Loaded policies from the local datastore with error.
#Event ID 7257: Downloaded policies with error.
#Event ID 7320: Error: ErrorDescription Error code ErrorCode.
#Description
Error: ErrorDescription Error code ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
ErrorDescription UnicodeString | Error. |
ErrorCode UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 7320,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2022-04-07T16:59:24.590503+00:00",
"event_record_id": 564,
"correlation": {
"ActivityID": "178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6"
},
"execution": {
"process_id": 1352,
"thread_id": 4040
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ErrorDescription": "%%4125",
"ErrorCode": 50
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 7321: Error: Error Parameter: ErrorDescription : Error code Parameter.
#Event ID 7326: Group Policy failed to discover the Domain Controller details in DCDiscoveryTimeInMilliSeconds milliseconds.
#Description
Group Policy failed to discover the Domain Controller details in DCDiscoveryTimeInMilliSeconds milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
DCDiscoveryTimeInMilliSeconds UInt32 | |
ErrorCode UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 7326,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2022-04-07T16:59:24.588837+00:00",
"event_record_id": 563,
"correlation": {
"ActivityID": "178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6"
},
"execution": {
"process_id": 1352,
"thread_id": 4040
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DCDiscoveryTimeInMilliSeconds": 4000,
"ErrorCode": 58
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 7331: Service configuration update to standalone was attempted due to the presence of Group Policy client extension UpdateCauseExtensionName that is not part of the operating ...
#Description
Service configuration update to standalone was attempted due to the presence of Group Policy client extension UpdateCauseExtensionName that is not part of the operating system and completed with status ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
UpdateCauseExtensionName UnicodeString | |
UpdateCauseExtensionId UnicodeString | |
ErrorCode UInt32 |
Event ID 8000: Completed computer boot policy processing for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Description
Completed computer boot policy processing for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
Message #
Fields #
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds UInt32 | |
ErrorCode UInt32 | |
PrincipalSamName UnicodeString | |
IsMachine UInt32 | |
IsConnectivityFailure Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 8000,
"version": 1,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:23:58.2937079+00:00",
"event_record_id": 31579,
"correlation": {
"ActivityID": "{A841B46F-F932-4765-A57F-C992AEC87CA4}"
},
"execution": {
"process_id": 1980,
"thread_id": 2792
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyElaspedTimeInSeconds": "0",
"ErrorCode": "0",
"PrincipalSamName": "cell-c\\TELEMETRY-DC-C$",
"IsMachine": "1",
"IsConnectivityFailure": "false"
},
"message": "Completed computer boot policy processing for cell-c\\TELEMETRY-DC-C$ in 0 seconds."
}
Event ID 8001: Completed user logon policy processing for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Description
Completed user logon policy processing for PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
Message #
Fields #
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds UInt32 | |
ErrorCode UInt32 | |
PrincipalSamName UnicodeString | |
IsMachine UInt32 | |
IsConnectivityFailure Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 8001,
"version": 1,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T05:23:59.6973726+00:00",
"event_record_id": 31614,
"correlation": {
"ActivityID": "{DC96B6CB-CED9-4463-8C28-581ADFFD8E96}"
},
"execution": {
"process_id": 1980,
"thread_id": 2780
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyElaspedTimeInSeconds": "0",
"ErrorCode": "0",
"PrincipalSamName": "cell-c\\domainadmin",
"IsMachine": "0",
"IsConnectivityFailure": "false"
},
"message": "Completed user logon policy processing for cell-c\\domainadmin in 0 seconds."
}
Event ID 8002: Completed policy processing due to network state change for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Event ID 8003: Completed policy processing due to network state change for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Event ID 8004: Completed manual processing of policy for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Description
Completed manual processing of policy for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
Message #
Fields #
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds UInt32 | |
ErrorCode UInt32 | |
PrincipalSamName UnicodeString | |
IsMachine UInt32 | |
IsConnectivityFailure Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 8004,
"version": 1,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-05-29T06:52:28.2740150+00:00",
"event_record_id": 29421,
"correlation": {
"ActivityID": "{84ECAB31-F9E8-4B4F-A2FD-465D7AC5C011}"
},
"execution": {
"process_id": 1864,
"thread_id": 5828
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyElaspedTimeInSeconds": "1",
"ErrorCode": "0",
"PrincipalSamName": "cell-c\\TELEMETRY-DC-C$",
"IsMachine": "1",
"IsConnectivityFailure": "false"
},
"message": "Completed manual processing of policy for computer cell-c\\TELEMETRY-DC-C$ in 1 seconds."
}
Event ID 8005: Completed manual processing of policy for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Description
Completed manual processing of policy for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
Message #
Fields #
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds UInt32 | |
ErrorCode UInt32 | |
PrincipalSamName UnicodeString | |
IsMachine UInt32 | |
IsConnectivityFailure Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 8005,
"version": 1,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:56:41.0294444+00:00",
"event_record_id": 18280,
"correlation": {
"ActivityID": "{805A095A-2906-4A2D-AFAE-826D5D69CA6F}"
},
"execution": {
"process_id": 1904,
"thread_id": 552
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyElaspedTimeInSeconds": "0",
"ErrorCode": "0",
"PrincipalSamName": "cell-a\\domainadmin",
"IsMachine": "0",
"IsConnectivityFailure": "false"
},
"message": "Completed manual processing of policy for user cell-a\\domainadmin in 0 seconds."
}
Event ID 8006: Completed periodic policy processing for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Description
Completed periodic policy processing for computer PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
Message #
Fields #
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds UInt32 | |
ErrorCode UInt32 | |
PrincipalSamName UnicodeString | |
IsMachine UInt32 | |
IsConnectivityFailure Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"event_source_name": "",
"event_id": 8006,
"version": 1,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T14:09:17.3269334+00:00",
"event_record_id": 35011,
"correlation": {
"ActivityID": "{DBCFE2FB-1977-4351-9D05-5BF8388C112E}"
},
"execution": {
"process_id": 1980,
"thread_id": 1816
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyElaspedTimeInSeconds": "0",
"ErrorCode": "0",
"PrincipalSamName": "cell-c\\TELEMETRY-DC-C$",
"IsMachine": "1",
"IsConnectivityFailure": "false"
},
"message": "Completed periodic policy processing for computer cell-c\\TELEMETRY-DC-C$ in 0 seconds."
}
Event ID 8007: Completed periodic policy processing for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
#Description
Completed periodic policy processing for user PrincipalSamName in PolicyElaspedTimeInSeconds seconds.
Message #
Fields #
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds UInt32 | |
ErrorCode UInt32 | |
PrincipalSamName UnicodeString | |
IsMachine UInt32 | |
IsConnectivityFailure Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"guid": "AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9",
"event_source_name": "",
"event_id": 8007,
"version": 1,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-03-14T01:40:41.669270+00:00",
"event_record_id": 179708,
"correlation": {
"ActivityID": "261F3C8C-5577-42F1-99D9-89D7A88E5B00"
},
"execution": {
"process_id": 1112,
"thread_id": 6604
},
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PolicyElaspedTimeInSeconds": 0,
"ErrorCode": 0,
"PrincipalSamName": "ludus\\domainadmin",
"IsMachine": 0,
"IsConnectivityFailure": false
},
"message": ""
}
Event ID 8016: CSEExtensionName Extension (CSEExtensionId) requests a sync mode process.
#Event ID 9001: This machine is configured to retrieve Group Policy files from a file share in an insecure way.
#Description
This machine is configured to retrieve Group Policy files from a file share in an insecure way.
Message #
Fields #
| Name | Description |
|---|---|
UncPath UnicodeString | |
MutualAuthenticationEnforced Boolean | |
IntegrityEnforced Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-GroupPolicy",
"event_id": 9001,
"level": 3,
"task": 0,
"opcode": 0,
"time_created": "2026-04-18T03:03:33.8017414+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-GroupPolicy"
},
"event_data": {
"MutualAuthenticationEnforced": "false",
"IntegrityEnforced": "false",
"UncPath": "\\\\ludus.domain\\NETLOGON"
}
}
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID aea1b4fa-97d1-45f2-a64c-4d69fffd92c9
Defined in gpsvc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02