Microsoft-Windows-HostGuardianService-Client

EventTitleChannelSampleRule
100Message.DebugNN
100Event ID 100OperationalNN
101Message.DebugNN
101Event ID 101OperationalNN
102Message.DebugNN
102Event ID 102OperationalNN
103Message.AnalyticNN
103Event ID 103OperationalNN
104Message.AnalyticNN
104Event ID 104OperationalNN
105Message.AnalyticNN
105Event ID 105OperationalNN
106Message.OperationalNN
107Message.OperationalNN
108Message.OperationalNN
109Message.AdminNN
109Event ID 109OperationalNN
110Message.AdminNN
110Event ID 110OperationalNN
111Message.AdminNN
111Event ID 111OperationalNN
112Started operation 'Message'.DebugNN
112Event ID 112OperationalNN
113Operation 'OperationName' ended with result: 'StatusCode'.DebugNN
113Event ID 113OperationalNN
200A new ActivityID has been generated.OperationalNN
1002Remote attestation initiated.OperationalNN
1003Remote attestation completed.OperationalNN
1004ClientAttestationHttpRequestSend: ActivityID HostId.DebugNN
1004Event ID 1004OperationalNN
1005ClientAttestationHttpResponseReceived: Message.DebugNN
1005Event ID 1005OperationalNN
1006ClientAttestationHttpError: Message.AdminNN
1006Event ID 1006OperationalNN
1007The remote attestation request failed because this host is not included in the …AdminNN
1007Event ID 1007OperationalNN
1008The remote attestation request failed because the host did not start with Secure …AdminNN
1008Event ID 1008OperationalNN
1009The remote attestation request failed because this host's Code Integrity policy …AdminNN
1009Event ID 1009OperationalNN
1010The remote attestation request failed because this host is not part of an Active …AdminNN
1010Event ID 1010OperationalNN
1012Determining TPM endorsement key failed.AdminNN
1012Event ID 1012OperationalNN
1013The remote attestation request failed because of a TPM error.AdminNN
1013Event ID 1013OperationalNN
1014Connection to Message failed.AnalyticNN
1014Event ID 1014OperationalNN
1015Switching to Active Directory attestation mode.OperationalNN
1016Connecting to Remote Attestation service at Message.AnalyticNN
1016Event ID 1016OperationalNN
1017Reconnecting to Remote Attestation service at Message.AnalyticNN
1017Event ID 1017OperationalNN
1018Remote attestation succeeded and returned a health certificate with the …OperationalNN
1019The remote attestation request failed because the Remote Attestation Service …AdminNN
1019Event ID 1019OperationalNN
1020The remote attestation request failed.AdminNN
1020Event ID 1020OperationalNN
1021The remote attestation request failed because this host was not booted …AdminNN
1021Event ID 1021OperationalNN
1022The remote attestation request failed because at least one Debug Mode is enabled …AdminNN
1022Event ID 1022OperationalNN
1023Determining TPM endorsement key failed.OperationalNN
1024The remote attestation request failed because this host was not configured …AdminNN
1024Event ID 1024OperationalNN
1025The remote attestation request failed because Isolated User Mode could not be …AdminNN
1025Event ID 1025OperationalNN
1026The remote attestation request failed because the TPM measurements were not …AdminNN
1026Event ID 1026OperationalNN
1027The remote attestation request failed because the Host Guardian Service did not …AdminNN
1027Event ID 1027OperationalNN
1028The remote attestation request failed because the host did not start with …AdminNN
1028Event ID 1028OperationalNN
1029The remote attestation request failed because IOMMU was not required by the …AdminNN
1029Event ID 1029OperationalNN
1030The remote attestation request failed because the host did not start with …AdminNN
1030Event ID 1030OperationalNN
1031The remote attestation request failed because code integrity was not required by …AdminNN
1031Event ID 1031OperationalNN
1032The remote attestation request failed but no reason was given.AdminNN
1032Event ID 1032OperationalNN
1033Switching to TPM attestation mode.OperationalNN
1034The remote attestation request failed because the Host Guardian Service is using …AdminNN
1034Event ID 1034OperationalNN
1035The remote attestation request failed because the Host Guardian Service could …AdminNN
1035Event ID 1035OperationalNN
1036The remote attestation request failed because it could not authenticate to the …AdminNN
1036Event ID 1036OperationalNN
1037The remote attestation request failed because the host started with hibernation …AdminNN
1037Event ID 1037OperationalNN
1038The remote attestation request failed because the host started with dumps …AdminNN
1038Event ID 1038OperationalNN
1039The remote attestation request failed because the host did not start with dump …AdminNN
1039Event ID 1039OperationalNN
1040The remote attestation request failed because the host's dump encryption key …AdminNN
1040Event ID 1040OperationalNN
1041Local attestation initiated.OperationalNN
1042No local health signing certificate was found.OperationalNN
1043Remote attestation failed due to an invalid payload received by the Host …AdminNN
1043Event ID 1043OperationalNN
1044The endorsement key certificate could not be found in the TPM.AdminNN
1044Event ID 1044OperationalNN
1045The issuing intermediate certificate could not be found in the TPM for the …DebugNN
1045Event ID 1045OperationalNN
1046The remote attestation request failed because the host key is not inclued in the …AdminNN
1046Event ID 1046OperationalNN
2000The requested WMI operation failed because access is denied.OperationalNN
2001The required value 'FirstMessage' in registry key 'SecondMessage' was not found.AdminNN
2001Event ID 2001OperationalNN
2002Successfully opened Shielded VM Local Certificates store.OperationalNN
2003No health signing certificate was found.OperationalNN
2004The Host Guardian Service Client is unable to retrieve the encryption key (IDK) …AdminNN
2004Event ID 2004OperationalNN
2005Unable to retrieve the local health certificate: Message.AdminNN
2005Event ID 2005OperationalNN
2006Failed to roll the transport key: Message.AdminNN
2006Event ID 2006OperationalNN
2007No signing certificates were found in the Shielded VM Local Certificates store.AdminNN
2007Event ID 2007OperationalNN
2008No encryption certificates were found in the Shielded VM Local Certificates …AdminNN
2008Event ID 2008OperationalNN
2009Initiating unwrap of key protector.OperationalNN
2010Initiating creation of a new of key protector.OperationalNN
2011Adding a guardian with signing certificate FirstMessage and encryption …OperationalNN
2012Initiating privileged unwrap of key protector.OperationalNN
2013Instantiating Host Guardian Service client in Mode mode.OperationalNN
2014The Host Guardian Service Client failed to unwrap a Key Protector on behalf of a …AdminNN
2014Event ID 2014OperationalNN
2015The Host Guardian Service Client successfully unwrapped a Key Protector on …AdminNN
2015Event ID 2015OperationalNN
2016The signing certificate need set 'DigitalSignature' key usage.AdminNN
2016Event ID 2016OperationalNN
2017The encryption certificate need set 'DataEncipherment' key usage.AdminNN
2017Event ID 2017OperationalNN
2018Failures rolling the transport key as the health certificate is invalid.OperationalNN
2019Raw certificate dump.DebugNN
2019Event ID 2019OperationalNN
2020The Host Guardian Service Client reused a cached health certificate issued in …OperationalNN
2021The Host Guardian Service Client could not contact the Host Guardian Service.OperationalNN
3007The remote attestation request failed because this host is not included in the …OperationalNN
3008The remote attestation request failed because the host did not start with Secure …OperationalNN
3009The remote attestation request failed because this host's Code Integrity policy …OperationalNN
3010The remote attestation request failed because this host is not part of an Active …OperationalNN
3013The remote attestation request failed because of a TPM error.OperationalNN
3019The remote attestation request failed because the Remote Attestation Service …OperationalNN
3020The remote attestation request failed.OperationalNN
3021The remote attestation request failed because this host was not booted …OperationalNN
3022The remote attestation request failed because at least one Debug Mode is enabled …OperationalNN
3024The remote attestation request failed because this host was not configured …OperationalNN
3025The remote attestation request failed because Isolated User Mode could not be …OperationalNN
3026The remote attestation request failed because the TPM measurements were not …OperationalNN
3027The remote attestation request failed because the Host Guardian Service did not …OperationalNN
3028The remote attestation request failed because the host did not start with …OperationalNN
3029The remote attestation request failed because IOMMU was not required by the …OperationalNN
3030The remote attestation request failed because the host did not start with …OperationalNN
3031The remote attestation request failed because code integrity was not required by …OperationalNN
3032The remote attestation request failed but no reason was given.OperationalNN
3034The remote attestation request failed because the Host Guardian Service is using …OperationalNN
3035The remote attestation request failed because the Host Guardian Service could …OperationalNN
3036The remote attestation request failed because it could not authenticate to the …OperationalNN
3037The remote attestation request failed because the host started with hibernation …OperationalNN
3038The remote attestation request failed because the host started with dumps …OperationalNN
3039The remote attestation request failed because the host did not start with dump …OperationalNN
3040The remote attestation request failed because the host's dump encryption key …OperationalNN
3043Remote attestation failed due to an invalid payload received by the Host …OperationalNN
3044The endorsement key certificate could not be found in the TPM.OperationalNN
3046The remote attestation request failed because the host key is not inclued in the …OperationalNN
4001The HGAttest API completed the operation with status code: ResultCode.OperationalNN
4002The URL provided for SHS attestation is invalid.AdminNN
4002Event ID 4002OperationalNN
4003Attestation is not supported in this configuration.AdminNN
4003Event ID 4003OperationalNN
4004Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is …AdminNN
4004Event ID 4004OperationalNN
4005Remote attestation for a CA Intermediate Certificate is currently not supported.AdminNN
4005Event ID 4005OperationalNN
4006This host attempted a remote attestation in ClientOperationMode mode, but the …AdminNN
4006Event ID 4006OperationalNN
5000A host key was set from certificate with thumbprint CertThumbprint.AdminNN
5000Event ID 5000OperationalNN
5001A host key was removed.AdminNN
5001Event ID 5001OperationalNN

Event ID 100: Message.

#
Channel
Debug

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 100

#
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 101: Message.

#
Channel
Debug

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 101

#
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 102: Message.

#
Channel
Debug

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 102

#
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 103: Message.

#
Channel
Analytic

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 103

#
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 104: Message.

#
Channel
Analytic

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 104

#
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 105: Message.

#
Channel
Analytic

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 105

#
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 106: Message.

#
Channel
Operational

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 107: Message.

#
Channel
Operational

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 108: Message.

#
Channel
Operational

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 109: Message.

#
Channel
Admin

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 109

#
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 110: Message.

#
Channel
Admin

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 110

#
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 111: Message.

#
Channel
Admin

Message #

%1

Fields #

NameDescription
Message UnicodeString

Event ID 111

#
Channel
Operational

Fields #

NameDescription
Message UnicodeString

Event ID 112: Started operation 'Message'.

#
Channel
Debug

Message #

Started operation '%1'.

Fields #

NameDescription
Message UnicodeString

Event ID 112

#
Channel
Operational

Description

Started operation 'Message'.

Fields #

NameDescription
Message UnicodeString

Event ID 113: Operation 'OperationName' ended with result: 'StatusCode'.

#
Channel
Debug

Message #

Operation '%1' ended with result: '%2'.

Fields #

NameDescription
OperationName UnicodeString
StatusCode Int32NTSTATUS reference

Event ID 113

#
Channel
Operational

Description

Operation 'OperationName' ended with result: 'StatusCode'.

Fields #

NameDescription
OperationName UnicodeString
StatusCode Int32NTSTATUS reference

Event ID 200: A new ActivityID has been generated.

#
Channel
Operational
Opcode
Send

Fields #

NameDescription
Id GUID

Event ID 1002: Remote attestation initiated.

#
Channel
Operational
Task
Attest

Event ID 1003: Remote attestation completed.

#
Channel
Operational
Task
Attest

Message #

Remote attestation completed.
OperationMode: %1
Status: %2
Substatus: %3

Fields #

NameDescription
OperationMode UInt8
AttestationStatus UInt16
AttestationSubstatus UInt16

Event ID 1004: ClientAttestationHttpRequestSend: ActivityID HostId.

#
Channel
Debug
Task
Http

Message #

ClientAttestationHttpRequestSend: ActivityID %1

Fields #

NameDescription
HostId UnicodeString

Event ID 1004

#
Channel
Operational
Task
Http

Description

ClientAttestationHttpRequestSend: ActivityID.

Fields #

NameDescription
HostId UnicodeString

Event ID 1005: ClientAttestationHttpResponseReceived: Message.

#
Channel
Debug
Task
Http

Message #

ClientAttestationHttpResponseReceived: %1

Fields #

NameDescription
Message UnicodeString

Event ID 1005

#
Channel
Operational
Task
Http

Description

ClientAttestationHttpResponseReceived.

Fields #

NameDescription
Message UnicodeString

Event ID 1006: ClientAttestationHttpError: Message.

#
Channel
Admin
Task
Http

Message #

ClientAttestationHttpError: %1

Fields #

NameDescription
Message UnicodeString

Event ID 1006

#
Channel
Operational
Task
Http

Description

ClientAttestationHttpError.

Fields #

NameDescription
Message UnicodeString

Event ID 1007: The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation se...

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation server. Error: %1. To add this host to the authorized list of host EKs, perform the following steps:
    1. On this host, run the Get-PlatformIdentifier cmdlet to retrieve the host EK in the form of a XML file.
    2. On the Attestation server, run the Add-HgsAttestationTpmHost cmdlet, specifying the file generated in the previous step.
Event IDs 1007 and 3007 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1007

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 1008: The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did ...

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did not match a valid baseline host. Error: %1. To ensure a successful attestation request, verify that the host configuration matches a valid baseline host. If this is a baseline host, you must first perform the following steps:
    1.  On this host, run the Get-HgsAttestationBaselinePolicy cmdlet to generate a policy file.
    2. On the attestation server, run the Add-HgsAttestationTpmPolicy cmdlet, specifying the policy file generated by the Get-HgsAttestationBaselinePolicy cmdlet. This adds the policy as a valid baseline TPM policy.
Event IDs 1008 and 3008 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1008

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 1009: The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation ser...

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation server. Error: %1. To ensure a successful attestation request, verify that this host is configured with a valid Code Integrity policy. For help, refer to http://go.microsoft.com/fwlink/?LinkId=734772
Event IDs 1009 and 3009 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1009

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 1010: The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server. Error: %1. To ensure a successful attestation request, verify that the host is a member of an authorized Active Directory host group. If the Active Directory host group is not authorized by the Attestation server, you must first perform the following steps:
    1. On the attestation server, run the Add-HgsAttestationHostGroup cmdlet to add it as a valid Active Directory host group.
Event IDs 1010 and 3010 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1010

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 1012: Determining TPM endorsement key failed.

#
Channel
Admin
Task
Attest

Description

Determining TPM endorsement key failed. Error: Message.

Message #

Determining TPM endorsement key failed. Error: %1

Fields #

NameDescription
Message UnicodeString

Event ID 1012

#
Channel
Operational
Task
Attest

Description

Determining TPM endorsement key failed. Error.

Fields #

NameDescription
Message UnicodeString

Event ID 1013: The remote attestation request failed because of a TPM error.

#
Channel
Admin
Task
Attest

Description

The remote attestation request failed because of a TPM error. Try clearing and reprovisioning the TPM. Error: Message.

Message #

The remote attestation request failed because of a TPM error. Try clearing and reprovisioning the TPM. Error: %1
Event IDs 1013 and 3013 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1013

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because of a TPM error. Try clearing and reprovisioning the TPM. Error.

Fields #

NameDescription
Message UnicodeString

Event ID 1014: Connection to Message failed.

#
Channel
Analytic
Task
Attest

Description

Connection to Message failed. Reconnecting to another IP.

Message #

Connection to %1 failed. Reconnecting to another IP.

Fields #

NameDescription
Message UnicodeString

Event ID 1014

#
Channel
Operational
Task
Attest

Description

Connection to failed. Reconnecting to another IP.

Fields #

NameDescription
Message UnicodeString

Event ID 1015: Switching to Active Directory attestation mode.

#
Channel
Operational
Task
Attest

Event ID 1016: Connecting to Remote Attestation service at Message.

#
Channel
Analytic
Task
Attest

Message #

Connecting to Remote Attestation service at %1

Fields #

NameDescription
Message UnicodeString

Event ID 1016

#
Channel
Operational
Task
Attest

Description

Connecting to Remote Attestation service at.

Fields #

NameDescription
Message UnicodeString

Event ID 1017: Reconnecting to Remote Attestation service at Message.

#
Channel
Analytic
Task
Attest

Message #

Reconnecting to Remote Attestation service at %1

Fields #

NameDescription
Message UnicodeString

Event ID 1017

#
Channel
Operational
Task
Attest

Description

Reconnecting to Remote Attestation service at.

Fields #

NameDescription
Message UnicodeString

Event ID 1018: Remote attestation succeeded and returned a health certificate with the thumbprint CertThumbprint.

#
Channel
Operational
Task
Attest

Message #

Remote attestation succeeded and returned a health certificate with the thumbprint %1.

Fields #

NameDescription
CertThumbprint UnicodeString

Event ID 1019: The remote attestation request failed because the Remote Attestation Service could not be reached.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because the Remote Attestation Service could not be reached.
Event IDs 1019 and 3019 represent the same event.

Event ID 1019

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the Remote Attestation Service could not be reached.

Event ID 1020: The remote attestation request failed.

#
Channel
Admin
Task
Attest

Description

The remote attestation request failed. Error: Message. For help, see http://go.microsoft.com/fwlink/?LinkId=735076.

Message #

The remote attestation request failed. Error: %1. For help, see http://go.microsoft.com/fwlink/?LinkId=735076
Event IDs 1020 and 3020 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1020

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed. Error: . For help, see http://go.microsoft.com/fwlink/?LinkId=735076.

Fields #

NameDescription
Message UnicodeString

Event ID 1021: The remote attestation request failed because this host was not booted correctly.

#
Channel
Admin
Task
Attest

Description

The remote attestation request failed because this host was not booted correctly. Error: Message. To ensure a successful attestation request, verify that the host's most recent boot was a full boot.

Message #

The remote attestation request failed because this host was not booted correctly. Error: %1. To ensure a successful attestation request, verify that the host's most recent boot was a full boot.
Event IDs 1021 and 3021 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1021

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because this host was not booted correctly. Error: . To ensure a successful attestation request, verify that the host's most recent boot was a full boot.

Fields #

NameDescription
Message UnicodeString

Event ID 1022: The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
Event IDs 1022 and 3022 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1022

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.

Fields #

NameDescription
Message UnicodeString

Event ID 1023: Determining TPM endorsement key failed.

#
Channel
Operational
Task
Attest

Description

Determining TPM endorsement key failed. Switching to Active Directory attestation mode.

Message #

Determining TPM endorsement key failed. Switching to Active Directory attestation mode.

Event ID 1024: The remote attestation request failed because this host was not configured properly.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because this host was not configured properly. Error: %1. To ensure a successful attestation request, verify that the host's configuration contains an attestation service URL that is valid.
Event IDs 1024 and 3024 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1024

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 1025: The remote attestation request failed because Isolated User Mode could not be detected.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because Isolated User Mode could not be detected.  Verify that the Isolated User Mode feature is installed and that Virtualization Based Security has not been disabled manually or by local/domain-level policy.
Event IDs 1025 and 3025 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1025

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 1026: The remote attestation request failed because the TPM measurements were not valid.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because the TPM measurements were not valid.  This can happen when the host utilizes unsupported TPM configurations, the Host Guardian Service client version is not supported by the server, or an attempt to tamper with the TPM Measurements was made.  Some PXE boot environments can also cause this issue; for help, refer to http://go.microsoft.com/fwlink/?LinkId=734770
Event IDs 1026 and 3026 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1026

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 1027: The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Event IDs 1027 and 3027 represent the same event.

Event ID 1027

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.

Event ID 1028: The remote attestation request failed because the host did not start with pagefile encryption enabled.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because the host did not start with pagefile encryption enabled.
Event IDs 1028 and 3028 represent the same event.

Event ID 1028

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the host did not start with pagefile encryption enabled.

Event ID 1029: The remote attestation request failed because IOMMU was not required by the hypervisor.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because IOMMU was not required by the hypervisor. Verify that IOMMU is enabled and that it is explicity required for Virtual Secure Mode to launch. For help, refer to http://go.microsoft.com/fwlink/?LinkId=734842
Event IDs 1029 and 3029 represent the same event.

Event ID 1029

#
Channel
Operational
Task
Attest

Event ID 1030: The remote attestation request failed because the host did not start with BitLocker enabled.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because the host did not start with BitLocker enabled.
Event IDs 1030 and 3030 represent the same event.

Event ID 1030

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the host did not start with BitLocker enabled.

Event ID 1031: The remote attestation request failed because code integrity was not required by the hypervisor.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because code integrity was not required by the hypervisor. Verify that code integrity is enabled and that it is being enforced by the hypervisor. For help, please refer to http://go.microsoft.com/fwlink/?LinkId=734841
Event IDs 1031 and 3031 represent the same event.

Event ID 1031

#
Channel
Operational
Task
Attest

Event ID 1032: The remote attestation request failed but no reason was given.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed but no reason was given. This typically indicates that the Host Guardian Service has not been fully configured with valid attestation policies.  If policies have been registered with the Host Guardian Service already, verify the functionality of the server and try again.
Event IDs 1032 and 3032 represent the same event.

Event ID 1032

#
Channel
Operational
Task
Attest

Event ID 1033: Switching to TPM attestation mode.

#
Channel
Operational
Task
Attest

Event ID 1034: The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.

#
Channel
Admin
Task
Attest

Description

The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.

Message #

The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.
Event IDs 1034 and 3034 represent the same event.

Event ID 1034

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.

Event ID 1035: The remote attestation request failed because the Host Guardian Service could not be contacted.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because the Host Guardian Service could not be contacted.  This happens when the request can reach the server but the service either does not respond or responds with an unknown HTTP error.  Verify that the Host Guardian Service is registered, started, and fully operational.
Error: %1
Event IDs 1035 and 3035 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1035

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 1036: The remote attestation request failed because it could not authenticate to the Host Guardian Service.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because it could not authenticate to the Host Guardian Service.  This can occur when using HTTPS with an invalid or untrusted certificate, or when using Active Directory-based attestation without configuring trust between this host's domain and the Host Guardian Service domain, preventing NTLM and Kerberos authentication from succeeding.
Error: %1
Event IDs 1036 and 3036 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1036

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 1037: The remote attestation request failed because the host started with hibernation enabled.

#
Channel
Admin
Task
Attest

Description

The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147.

Message #

The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147
Event IDs 1037 and 3037 represent the same event.

Event ID 1037

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147.

Event ID 1038: The remote attestation request failed because the host started with dumps enabled.

#
Channel
Admin
Task
Attest

Description

The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148.

Message #

The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148
Event IDs 1038 and 3038 represent the same event.

Event ID 1038

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148.

Event ID 1039: The remote attestation request failed because the host did not start with dump encryption enabled.

#
Channel
Admin
Task
Attest

Description

The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149.

Message #

The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149
Event IDs 1039 and 3039 represent the same event.

Event ID 1039

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149.

Event ID 1040: The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server. Error:%1. If this is a valid host, you must first perform the following steps:
    1. On the host, configure dump encryption with a certificate.
    2. On the Attestation server, run the Add-HgsAttestationDumpPolicy cmdlet, specifying the SHA256 hash of the public key blob configured on the host.
Event IDs 1040 and 3040 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1040

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 1041: Local attestation initiated.

#
Channel
Operational
Task
Attest

Event ID 1042: No local health signing certificate was found.

#
Channel
Operational
Task
Attest

Description

No local health signing certificate was found. Attempting to generate a new certificate.

Message #

No local health signing certificate was found.  Attempting to generate a new certificate.

Event ID 1043: Remote attestation failed due to an invalid payload received by the Host Guardian Service.

#
Channel
Admin
Task
Attest

Description

Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.

Message #

Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.

Event ID 1043

#
Channel
Operational
Task
Attest

Description

Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.

Event ID 1044: The endorsement key certificate could not be found in the TPM.

#
Channel
Admin
Task
Attest

Description

The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error: StatusCode.

Message #

The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error: %1
Event IDs 1044 and 3044 represent the same event.

Fields #

NameDescription
StatusCode Int32NTSTATUS reference

Event ID 1044

#
Channel
Operational
Task
Attest

Description

The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error.

Fields #

NameDescription
StatusCode Int32NTSTATUS reference

Event ID 1045: The issuing intermediate certificate could not be found in the TPM for the endorsement key certificate.

#
Channel
Debug
Task
Attest

Message #

The issuing intermediate certificate could not be found in the TPM for the endorsement key certificate. The intermediate certificate is necessary for nested attestation; otherwise, this event may be ignored. Error: %1

Fields #

NameDescription
StatusCode Int32NTSTATUS reference

Event ID 1045

#
Channel
Operational
Task
Attest

Fields #

NameDescription
StatusCode Int32NTSTATUS reference

Event ID 1046: The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server.

#
Channel
Admin
Task
Attest

Message #

The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server. Error: %1. To add the host key to the authorized list of host keys, perform the following steps:
    1. On this host, run the Get-HgsAttestationHostKey cmdlet to retrieve the necessary key material.
    2. On the Attestation server, run the Add-HgsAttestationHostKey cmdlet, specifying the file generatetd in the previous step.
EventIDs 1046 and 3046 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 1046

#
Channel
Operational
Task
Attest

Fields #

NameDescription
Message UnicodeString

Event ID 2000: The requested WMI operation failed because access is denied.

#
Channel
Operational
Task
Kps

Description

The requested WMI operation failed because access is denied. You must be a member of the local 'Administrators' or 'NT VIRTUAL MACHINE\Virtual Machines' groups.

Message #

The requested WMI operation failed because access is denied. You must be a member of the local 'Administrators' or 'NT VIRTUAL MACHINE\Virtual Machines' groups.

Event ID 2001: The required value 'FirstMessage' in registry key 'SecondMessage' was not found.

#
Channel
Admin
Task
Kps

Message #

The required value '%1' in registry key '%2' was not found.

Fields #

NameDescription
FirstMessage UnicodeString
SecondMessage UnicodeString

Event ID 2001

#
Channel
Operational
Task
Kps

Description

The required value 'FirstMessage' in registry key 'SecondMessage' was not found.

Fields #

NameDescription
FirstMessage UnicodeString
SecondMessage UnicodeString

Event ID 2002: Successfully opened Shielded VM Local Certificates store.

#
Channel
Operational
Task
Kps

Event ID 2003: No health signing certificate was found.

#
Channel
Operational
Task
Kps

Description

No health signing certificate was found. Attempting to generate a new certificate.

Message #

No health signing certificate was found. Attempting to generate a new certificate.

Event ID 2004: The Host Guardian Service Client is unable to retrieve the encryption key (IDK) because Virtualization Based Security is not running on this system.

#
Channel
Admin
Task
Kps

Message #

The Host Guardian Service Client is unable to retrieve the encryption key (IDK) because Virtualization Based Security is not running on this system. To resolve this issue, enable Virtualization Based Security and try again:

%1

Fields #

NameDescription
Message UnicodeString

Event ID 2004

#
Channel
Operational
Task
Kps

Fields #

NameDescription
Message UnicodeString

Event ID 2005: Unable to retrieve the local health certificate: Message.

#
Channel
Admin
Task
Kps

Message #

Unable to retrieve the local health certificate: %1

Fields #

NameDescription
Message UnicodeString

Event ID 2005

#
Channel
Operational
Task
Kps

Description

Unable to retrieve the local health certificate.

Fields #

NameDescription
Message UnicodeString

Event ID 2006: Failed to roll the transport key: Message.

#
Channel
Admin
Task
Kps

Message #

Failed to roll the transport key: %1

Fields #

NameDescription
Message UnicodeString

Event ID 2006

#
Channel
Operational
Task
Kps

Description

Failed to roll the transport key.

Fields #

NameDescription
Message UnicodeString

Event ID 2007: No signing certificates were found in the Shielded VM Local Certificates store.

#
Channel
Admin
Task
Kps

Event ID 2007

#
Channel
Operational
Task
Kps

Description

No signing certificates were found in the Shielded VM Local Certificates store.

Event ID 2008: No encryption certificates were found in the Shielded VM Local Certificates store.

#
Channel
Admin
Task
Kps

Event ID 2008

#
Channel
Operational
Task
Kps

Description

No encryption certificates were found in the Shielded VM Local Certificates store.

Event ID 2009: Initiating unwrap of key protector.

#
Channel
Operational
Task
Kps

Event ID 2010: Initiating creation of a new of key protector.

#
Channel
Operational
Task
Kps

Event ID 2011: Adding a guardian with signing certificate FirstMessage and encryption certificate SecondMessage to a key protector.

#
Channel
Operational
Task
Kps

Message #

Adding a guardian with signing certificate %1 and encryption certificate %2 to a key protector.

Fields #

NameDescription
FirstMessage UnicodeString
SecondMessage UnicodeString

Event ID 2012: Initiating privileged unwrap of key protector.

#
Channel
Operational
Task
Kps

Event ID 2013: Instantiating Host Guardian Service client in Mode mode.

#
Channel
Operational
Task
Kps

Message #

Instantiating Host Guardian Service client in %1 mode.

Fields #

NameDescription
Mode UInt16

Event ID 2014: The Host Guardian Service Client failed to unwrap a Key Protector on behalf of a calling process.

#
Channel
Admin
Task
Kps

Message #

The Host Guardian Service Client failed to unwrap a Key Protector on behalf of a calling process. This event will normally correspond to a failure to startup a shielded virtual machine. Consult the description for further details. This could be related to an attestation issue, a Key Protection Server issue, or a network connectivity issue:

%1

Fields #

NameDescription
Message UnicodeString

Event ID 2014

#
Channel
Operational
Task
Kps

Fields #

NameDescription
Message UnicodeString

Event ID 2015: The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.

#
Channel
Admin
Task
Kps

Event ID 2015

#
Channel
Operational
Task
Kps

Description

The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.

Event ID 2016: The signing certificate need set 'DigitalSignature' key usage.

#
Channel
Admin
Task
Kps

Event ID 2016

#
Channel
Operational
Task
Kps

Description

The signing certificate need set 'DigitalSignature' key usage.

Event ID 2017: The encryption certificate need set 'DataEncipherment' key usage.

#
Channel
Admin
Task
Kps

Event ID 2017

#
Channel
Operational
Task
Kps

Description

The encryption certificate need set 'DataEncipherment' key usage.

Event ID 2018: Failures rolling the transport key as the health certificate is invalid.

#
Channel
Operational
Task
Kps

Description

Failures rolling the transport key as the health certificate is invalid. ErrorCode: ErrorCode, Validation Status: ValidationStatus, Message: Message.

Message #

Failures rolling the transport key as the health certificate is invalid. ErrorCode: %1, Validation Status: %2, Message: %3

Fields #

NameDescription
ErrorCode HexInt32
ValidationStatus UInt32
Message UnicodeString

Event ID 2019: Raw certificate dump.

#
Channel
Debug

Description

Raw certificate dump. Length(bytes)=CertificateDataLength --> CertificateData.

Message #

Raw certificate dump. Length(bytes)=%1 --> %2

Fields #

NameDescription
CertificateDataLength UInt32
CertificateData UInt8

Event ID 2019

#
Channel
Operational

Description

Raw certificate dump. Length(bytes)= -->.

Fields #

NameDescription
CertificateDataLength UInt32
CertificateData UInt8

Event ID 2020: The Host Guardian Service Client reused a cached health certificate issued in OperationMode mode that is valid until CertificateValidTo.

#
Channel
Operational

Message #

The Host Guardian Service Client reused a cached health certificate issued in %1 mode that is valid until %2.

Fields #

NameDescription
OperationMode UInt8
CertificateValidTo UnicodeString

Event ID 2021: The Host Guardian Service Client could not contact the Host Guardian Service.

#
Channel
Operational

Description

The Host Guardian Service Client could not contact the Host Guardian Service. The client will reattempt the operation using the following settings.

Message #

The Host Guardian Service Client could not contact the Host Guardian Service.  The client will reattempt the operation using the following settings:

AttestationServerUrl: %1
KeyProtectionServerUrl: %2

Fields #

NameDescription
FirstMessage UnicodeString
SecondMessage UnicodeString

Event ID 3007: The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation se...

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation server. Error: %1. To add this host to the authorized list of host EKs, perform the following steps:
    1. On this host, run the Get-PlatformIdentifier cmdlet to retrieve the host EK in the form of a XML file.
    2. On the Attestation server, run the Add-HgsAttestationTpmHost cmdlet, specifying the file generated in the previous step.
Event IDs 1007 and 3007 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3008: The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did ...

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did not match a valid baseline host. Error: %1. To ensure a successful attestation request, verify that the host configuration matches a valid baseline host. If this is a baseline host, you must first perform the following steps:
    1.  On this host, run the Get-HgsAttestationBaselinePolicy cmdlet to generate a policy file.
    2. On the attestation server, run the Add-HgsAttestationTpmPolicy cmdlet, specifying the policy file generated by the Get-HgsAttestationBaselinePolicy cmdlet. This adds the policy as a valid baseline TPM policy.
Event IDs 1008 and 3008 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3009: The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation ser...

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation server. Error: %1. To ensure a successful attestation request, verify that this host is configured with a valid Code Integrity policy. For help, refer to http://go.microsoft.com/fwlink/?LinkId=734772
Event IDs 1009 and 3009 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3010: The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server. Error: %1. To ensure a successful attestation request, verify that the host is a member of an authorized Active Directory host group. If the Active Directory host group is not authorized by the Attestation server, you must first perform the following steps:
    1. On the attestation server, run the Add-HgsAttestationHostGroup cmdlet to add it as a valid Active Directory host group.
Event IDs 1010 and 3010 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3013: The remote attestation request failed because of a TPM error.

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because of a TPM error. Try clearing and reprovisioning the TPM. Error: Message.

Message #

The remote attestation request failed because of a TPM error. Try clearing and reprovisioning the TPM. Error: %1
Event IDs 1013 and 3013 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3019: The remote attestation request failed because the Remote Attestation Service could not be reached.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because the Remote Attestation Service could not be reached.
Event IDs 1019 and 3019 represent the same event.

Event ID 3020: The remote attestation request failed.

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed. Error: Message. For help, see http://go.microsoft.com/fwlink/?LinkId=735076.

Message #

The remote attestation request failed. Error: %1. For help, see http://go.microsoft.com/fwlink/?LinkId=735076
Event IDs 1020 and 3020 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3021: The remote attestation request failed because this host was not booted correctly.

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because this host was not booted correctly. Error: Message. To ensure a successful attestation request, verify that the host's most recent boot was a full boot.

Message #

The remote attestation request failed because this host was not booted correctly. Error: %1. To ensure a successful attestation request, verify that the host's most recent boot was a full boot.
Event IDs 1021 and 3021 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3022: The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
Event IDs 1022 and 3022 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3024: The remote attestation request failed because this host was not configured properly.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because this host was not configured properly. Error: %1. To ensure a successful attestation request, verify that the host's configuration contains an attestation service URL that is valid.
Event IDs 1024 and 3024 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3025: The remote attestation request failed because Isolated User Mode could not be detected.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because Isolated User Mode could not be detected.  Verify that the Isolated User Mode feature is installed and that Virtualization Based Security has not been disabled manually or by local/domain-level policy.
Event IDs 1025 and 3025 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3026: The remote attestation request failed because the TPM measurements were not valid.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because the TPM measurements were not valid.  This can happen when the host utilizes unsupported TPM configurations, the Host Guardian Service client version is not supported by the server, or an attempt to tamper with the TPM Measurements was made.  Some PXE boot environments can also cause this issue; for help, refer to http://go.microsoft.com/fwlink/?LinkId=734770
Event IDs 1026 and 3026 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3027: The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Event IDs 1027 and 3027 represent the same event.

Event ID 3028: The remote attestation request failed because the host did not start with pagefile encryption enabled.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because the host did not start with pagefile encryption enabled.
Event IDs 1028 and 3028 represent the same event.

Event ID 3029: The remote attestation request failed because IOMMU was not required by the hypervisor.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because IOMMU was not required by the hypervisor. Verify that IOMMU is enabled and that it is explicity required for Virtual Secure Mode to launch. For help, refer to http://go.microsoft.com/fwlink/?LinkId=734842
Event IDs 1029 and 3029 represent the same event.

Event ID 3030: The remote attestation request failed because the host did not start with BitLocker enabled.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because the host did not start with BitLocker enabled.
Event IDs 1030 and 3030 represent the same event.

Event ID 3031: The remote attestation request failed because code integrity was not required by the hypervisor.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because code integrity was not required by the hypervisor. Verify that code integrity is enabled and that it is being enforced by the hypervisor. For help, please refer to http://go.microsoft.com/fwlink/?LinkId=734841
Event IDs 1031 and 3031 represent the same event.

Event ID 3032: The remote attestation request failed but no reason was given.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed but no reason was given. This typically indicates that the Host Guardian Service has not been fully configured with valid attestation policies.  If policies have been registered with the Host Guardian Service already, verify the functionality of the server and try again.
Event IDs 1032 and 3032 represent the same event.

Event ID 3034: The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.

Message #

The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.
Event IDs 1034 and 3034 represent the same event.

Event ID 3035: The remote attestation request failed because the Host Guardian Service could not be contacted.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because the Host Guardian Service could not be contacted.  This happens when the request can reach the server but the service either does not respond or responds with an unknown HTTP error.  Verify that the Host Guardian Service is registered, started, and fully operational.
Error: %1
Event IDs 1035 and 3035 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3036: The remote attestation request failed because it could not authenticate to the Host Guardian Service.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because it could not authenticate to the Host Guardian Service.  This can occur when using HTTPS with an invalid or untrusted certificate, or when using Active Directory-based attestation without configuring trust between this host's domain and the Host Guardian Service domain, preventing NTLM and Kerberos authentication from succeeding.
Error: %1
Event IDs 1036 and 3036 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3037: The remote attestation request failed because the host started with hibernation enabled.

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147.

Message #

The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147
Event IDs 1037 and 3037 represent the same event.

Event ID 3038: The remote attestation request failed because the host started with dumps enabled.

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148.

Message #

The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148
Event IDs 1038 and 3038 represent the same event.

Event ID 3039: The remote attestation request failed because the host did not start with dump encryption enabled.

#
Channel
Operational
Task
Attest

Description

The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149.

Message #

The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149
Event IDs 1039 and 3039 represent the same event.

Event ID 3040: The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server. Error:%1. If this is a valid host, you must first perform the following steps:
    1. On the host, configure dump encryption with a certificate.
    2. On the Attestation server, run the Add-HgsAttestationDumpPolicy cmdlet, specifying the SHA256 hash of the public key blob configured on the host.
Event IDs 1040 and 3040 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 3043: Remote attestation failed due to an invalid payload received by the Host Guardian Service.

#
Channel
Operational
Task
Attest

Description

Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.

Message #

Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.

Event ID 3044: The endorsement key certificate could not be found in the TPM.

#
Channel
Operational
Task
Attest

Description

The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error: StatusCode.

Message #

The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error: %1
Event IDs 1044 and 3044 represent the same event.

Fields #

NameDescription
StatusCode Int32NTSTATUS reference

Event ID 3046: The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server.

#
Channel
Operational
Task
Attest

Message #

The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server. Error: %1. To add the host key to the authorized list of host keys, perform the following steps:
    1. On this host, run the Get-HgsAttestationHostKey cmdlet to retrieve the necessary key material.
    2. On the Attestation server, run the Add-HgsAttestationHostKey cmdlet, specifying the file generatetd in the previous step.
EventIDs 1046 and 3046 represent the same event.

Fields #

NameDescription
Message UnicodeString

Event ID 4001: The HGAttest API completed the operation with status code: ResultCode.

#
Channel
Operational
Task
Attest

Description

The HGAttest API completed the operation with status code: ResultCode. Operation: Operation.

Message #

The HGAttest API completed the operation with status code: %2. Operation: %1

Fields #

NameDescription
Operation UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ResultCode UInt32

Event ID 4002: The URL provided for SHS attestation is invalid.

#
Channel
Admin
Task
Attest

Description

The URL provided for SHS attestation is invalid. URL: Message.

Message #

The URL provided for SHS attestation is invalid. URL: %1

Fields #

NameDescription
Message UnicodeString

Event ID 4002

#
Channel
Operational
Task
Attest

Description

The URL provided for SHS attestation is invalid. URL.

Fields #

NameDescription
Message UnicodeString

Event ID 4003: Attestation is not supported in this configuration.

#
Channel
Admin
Task
Attest

Event ID 4003

#
Channel
Operational
Task
Attest

Description

Attestation is not supported in this configuration.

Event ID 4004: Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.

#
Channel
Admin
Task
Attest

Event ID 4004

#
Channel
Operational
Task
Attest

Description

Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.

Event ID 4005: Remote attestation for a CA Intermediate Certificate is currently not supported.

#
Channel
Admin
Task
Attest

Event ID 4005

#
Channel
Operational
Task
Attest

Description

Remote attestation for a CA Intermediate Certificate is currently not supported.

Event ID 4006: This host attempted a remote attestation in ClientOperationMode mode, but the targeted HGS server is operating in ServerOperationMode mode.

#
Channel
Admin
Task
Attest

Message #

This host attempted a remote attestation in %1 mode, but the targeted HGS server is operating in %2 mode.

Fields #

NameDescription
ClientOperationMode UInt8
ServerOperationMode UInt8

Event ID 4006

#
Channel
Operational
Task
Attest

Description

This host attempted a remote attestation in mode, but the targeted HGS server is operating in mode.

Fields #

NameDescription
ClientOperationMode UInt8
ServerOperationMode UInt8

Event ID 5000: A host key was set from certificate with thumbprint CertThumbprint.

#
Channel
Admin
Task
Attest

Message #

A host key was set from certificate with thumbprint %1.

Fields #

NameDescription
CertThumbprint UnicodeString

Event ID 5000

#
Channel
Operational
Task
Attest

Description

A host key was set from certificate with thumbprint .

Fields #

NameDescription
CertThumbprint UnicodeString

Event ID 5001: A host key was removed.

#
Channel
Admin
Task
Attest

Description

A host key was removed. It was from certificate with thumbprint CertThumbprint.

Message #

A host key was removed. It was from certificate with thumbprint %1.

Fields #

NameDescription
CertThumbprint UnicodeString

Event ID 5001

#
Channel
Operational
Task
Attest

Description

A host key was removed. It was from certificate with thumbprint .

Fields #

NameDescription
CertThumbprint UnicodeString

Provenance

ETW provider GUID 7dee1fdc-ffa8-4087-912a-95189d6a2d7f

Defined in HostGuardianServiceClientResources.dll, which carries the event manifest.

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB