Microsoft-Windows-HostGuardianService-Client
182 events across 4 channels
Event ID 112: Started operation 'Message'.
#Event ID 113: Operation 'OperationName' ended with result: 'StatusCode'.
#Description
Operation 'OperationName' ended with result: 'StatusCode'.
Message #
Fields #
| Name | Description |
|---|---|
OperationName UnicodeString | |
StatusCode Int32 | NTSTATUS reference |
Event ID 113
#Description
Operation 'OperationName' ended with result: 'StatusCode'.
Fields #
| Name | Description |
|---|---|
OperationName UnicodeString | |
StatusCode Int32 | NTSTATUS reference |
Event ID 200: A new ActivityID has been generated.
#Event ID 1003: Remote attestation completed.
#Event ID 1004: ClientAttestationHttpRequestSend: ActivityID HostId.
#Event ID 1004
#Description
ClientAttestationHttpRequestSend: ActivityID.
Fields #
| Name | Description |
|---|---|
HostId UnicodeString |
Event ID 1005: ClientAttestationHttpResponseReceived: Message.
#Event ID 1005
#Description
ClientAttestationHttpResponseReceived.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 1006: ClientAttestationHttpError: Message.
#Event ID 1007: The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation se...
#Event ID 1008: The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did ...
#Event ID 1009: The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation ser...
#Event ID 1010: The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server.
#Event ID 1012: Determining TPM endorsement key failed.
#Event ID 1012
#Description
Determining TPM endorsement key failed. Error.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 1013: The remote attestation request failed because of a TPM error.
#Event ID 1013
#Description
The remote attestation request failed because of a TPM error. Try clearing and reprovisioning the TPM. Error.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 1014: Connection to Message failed.
#Event ID 1014
#Description
Connection to failed. Reconnecting to another IP.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 1015: Switching to Active Directory attestation mode.
#Description
Switching to Active Directory attestation mode.
Message #
Event ID 1016: Connecting to Remote Attestation service at Message.
#Event ID 1016
#Description
Connecting to Remote Attestation service at.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 1017: Reconnecting to Remote Attestation service at Message.
#Event ID 1017
#Description
Reconnecting to Remote Attestation service at.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 1018: Remote attestation succeeded and returned a health certificate with the thumbprint CertThumbprint.
#Event ID 1019: The remote attestation request failed because the Remote Attestation Service could not be reached.
#Description
The remote attestation request failed because the Remote Attestation Service could not be reached.
Message #
Event ID 1019
#Description
The remote attestation request failed because the Remote Attestation Service could not be reached.
Event ID 1020: The remote attestation request failed.
#Event ID 1020
#Description
The remote attestation request failed. Error: . For help, see http://go.microsoft.com/fwlink/?LinkId=735076.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 1021: The remote attestation request failed because this host was not booted correctly.
#Event ID 1021
#Description
The remote attestation request failed because this host was not booted correctly. Error: . To ensure a successful attestation request, verify that the host's most recent boot was a full boot.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 1022: The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
#Event ID 1022
#Description
The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 1023: Determining TPM endorsement key failed.
#Description
Determining TPM endorsement key failed. Switching to Active Directory attestation mode.
Message #
Event ID 1024: The remote attestation request failed because this host was not configured properly.
#Event ID 1025: The remote attestation request failed because Isolated User Mode could not be detected.
#Event ID 1026: The remote attestation request failed because the TPM measurements were not valid.
#Event ID 1027: The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
#Description
The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Message #
Event ID 1027
#Description
The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Event ID 1028: The remote attestation request failed because the host did not start with pagefile encryption enabled.
#Description
The remote attestation request failed because the host did not start with pagefile encryption enabled.
Message #
Event ID 1028
#Description
The remote attestation request failed because the host did not start with pagefile encryption enabled.
Event ID 1029: The remote attestation request failed because IOMMU was not required by the hypervisor.
#Message #
Event ID 1029
#Event ID 1030: The remote attestation request failed because the host did not start with BitLocker enabled.
#Description
The remote attestation request failed because the host did not start with BitLocker enabled.
Message #
Event ID 1030
#Description
The remote attestation request failed because the host did not start with BitLocker enabled.
Event ID 1031: The remote attestation request failed because code integrity was not required by the hypervisor.
#Message #
Event ID 1031
#Event ID 1032
#Event ID 1033: Switching to TPM attestation mode.
#Description
Switching to TPM attestation mode.
Message #
Event ID 1034: The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.
#Description
The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.
Message #
Event ID 1034
#Description
The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.
Event ID 1035: The remote attestation request failed because the Host Guardian Service could not be contacted.
#Event ID 1036: The remote attestation request failed because it could not authenticate to the Host Guardian Service.
#Event ID 1037: The remote attestation request failed because the host started with hibernation enabled.
#Description
The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147.
Message #
Event ID 1037
#Description
The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147.
Event ID 1038: The remote attestation request failed because the host started with dumps enabled.
#Description
The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148.
Message #
Event ID 1038
#Description
The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148.
Event ID 1039: The remote attestation request failed because the host did not start with dump encryption enabled.
#Description
The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149.
Message #
Event ID 1039
#Description
The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149.
Event ID 1040: The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server.
#Event ID 1042: No local health signing certificate was found.
#Description
No local health signing certificate was found. Attempting to generate a new certificate.
Message #
Event ID 1043: Remote attestation failed due to an invalid payload received by the Host Guardian Service.
#Description
Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.
Message #
Event ID 1043
#Description
Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.
Event ID 1044: The endorsement key certificate could not be found in the TPM.
#Description
The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error: StatusCode.
Message #
Fields #
| Name | Description |
|---|---|
StatusCode Int32 | NTSTATUS reference |
Event ID 1044
#Description
The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error.
Fields #
| Name | Description |
|---|---|
StatusCode Int32 | NTSTATUS reference |
Event ID 1045: The issuing intermediate certificate could not be found in the TPM for the endorsement key certificate.
#Message #
Fields #
| Name | Description |
|---|---|
StatusCode Int32 | NTSTATUS reference |
Event ID 1045
#Fields #
| Name | Description |
|---|---|
StatusCode Int32 | NTSTATUS reference |
Event ID 1046: The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server.
#Event ID 2000: The requested WMI operation failed because access is denied.
#Description
The requested WMI operation failed because access is denied. You must be a member of the local 'Administrators' or 'NT VIRTUAL MACHINE\Virtual Machines' groups.
Message #
Event ID 2001: The required value 'FirstMessage' in registry key 'SecondMessage' was not found.
#Event ID 2001
#Description
The required value 'FirstMessage' in registry key 'SecondMessage' was not found.
Fields #
| Name | Description |
|---|---|
FirstMessage UnicodeString | |
SecondMessage UnicodeString |
Event ID 2002: Successfully opened Shielded VM Local Certificates store.
#Description
Successfully opened Shielded VM Local Certificates store.
Message #
Event ID 2003: No health signing certificate was found.
#Description
No health signing certificate was found. Attempting to generate a new certificate.
Message #
Event ID 2004: The Host Guardian Service Client is unable to retrieve the encryption key (IDK) because Virtualization Based Security is not running on this system.
#Event ID 2005: Unable to retrieve the local health certificate: Message.
#Event ID 2005
#Description
Unable to retrieve the local health certificate.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 2006: Failed to roll the transport key: Message.
#Event ID 2006
#Description
Failed to roll the transport key.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 2007: No signing certificates were found in the Shielded VM Local Certificates store.
#Description
No signing certificates were found in the Shielded VM Local Certificates store.
Message #
Event ID 2007
#Description
No signing certificates were found in the Shielded VM Local Certificates store.
Event ID 2008: No encryption certificates were found in the Shielded VM Local Certificates store.
#Description
No encryption certificates were found in the Shielded VM Local Certificates store.
Message #
Event ID 2008
#Description
No encryption certificates were found in the Shielded VM Local Certificates store.
Event ID 2009: Initiating unwrap of key protector.
#Description
Initiating unwrap of key protector.
Message #
Event ID 2010: Initiating creation of a new of key protector.
#Description
Initiating creation of a new of key protector.
Message #
Event ID 2011: Adding a guardian with signing certificate FirstMessage and encryption certificate SecondMessage to a key protector.
#Event ID 2012: Initiating privileged unwrap of key protector.
#Description
Initiating privileged unwrap of key protector.
Message #
Event ID 2013: Instantiating Host Guardian Service client in Mode mode.
#Event ID 2014: The Host Guardian Service Client failed to unwrap a Key Protector on behalf of a calling process.
#Event ID 2015: The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.
#Description
The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.
Message #
Event ID 2015
#Description
The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.
Event ID 2016: The signing certificate need set 'DigitalSignature' key usage.
#Description
The signing certificate need set 'DigitalSignature' key usage.
Message #
Event ID 2016
#Description
The signing certificate need set 'DigitalSignature' key usage.
Event ID 2017: The encryption certificate need set 'DataEncipherment' key usage.
#Description
The encryption certificate need set 'DataEncipherment' key usage.
Message #
Event ID 2017
#Description
The encryption certificate need set 'DataEncipherment' key usage.
Event ID 2018: Failures rolling the transport key as the health certificate is invalid.
#Event ID 2019: Raw certificate dump.
#Event ID 2019
#Description
Raw certificate dump. Length(bytes)= -->.
Fields #
| Name | Description |
|---|---|
CertificateDataLength UInt32 | |
CertificateData UInt8 |
Event ID 2020: The Host Guardian Service Client reused a cached health certificate issued in OperationMode mode that is valid until CertificateValidTo.
#Event ID 2021: The Host Guardian Service Client could not contact the Host Guardian Service.
#Event ID 3007: The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation se...
#Event ID 3008: The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did ...
#Event ID 3009: The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation ser...
#Event ID 3010: The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server.
#Event ID 3013: The remote attestation request failed because of a TPM error.
#Event ID 3019: The remote attestation request failed because the Remote Attestation Service could not be reached.
#Description
The remote attestation request failed because the Remote Attestation Service could not be reached.
Message #
Event ID 3020: The remote attestation request failed.
#Event ID 3021: The remote attestation request failed because this host was not booted correctly.
#Event ID 3022: The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
#Event ID 3024: The remote attestation request failed because this host was not configured properly.
#Event ID 3025: The remote attestation request failed because Isolated User Mode could not be detected.
#Event ID 3026: The remote attestation request failed because the TPM measurements were not valid.
#Event ID 3027: The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
#Description
The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Message #
Event ID 3028: The remote attestation request failed because the host did not start with pagefile encryption enabled.
#Description
The remote attestation request failed because the host did not start with pagefile encryption enabled.
Message #
Event ID 3029: The remote attestation request failed because IOMMU was not required by the hypervisor.
#Message #
Event ID 3030: The remote attestation request failed because the host did not start with BitLocker enabled.
#Description
The remote attestation request failed because the host did not start with BitLocker enabled.
Message #
Event ID 3031: The remote attestation request failed because code integrity was not required by the hypervisor.
#Message #
Event ID 3034: The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.
#Description
The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.0 module.
Message #
Event ID 3035: The remote attestation request failed because the Host Guardian Service could not be contacted.
#Event ID 3036: The remote attestation request failed because it could not authenticate to the Host Guardian Service.
#Event ID 3037: The remote attestation request failed because the host started with hibernation enabled.
#Description
The remote attestation request failed because the host started with hibernation enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824147.
Message #
Event ID 3038: The remote attestation request failed because the host started with dumps enabled.
#Description
The remote attestation request failed because the host started with dumps enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824148.
Message #
Event ID 3039: The remote attestation request failed because the host did not start with dump encryption enabled.
#Description
The remote attestation request failed because the host did not start with dump encryption enabled. For help, refer to http://go.microsoft.com/fwlink/?LinkId=824149.
Message #
Event ID 3040: The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server.
#Event ID 3043: Remote attestation failed due to an invalid payload received by the Host Guardian Service.
#Description
Remote attestation failed due to an invalid payload received by the Host Guardian Service. Event IDs 1043 and 3043 represent the same event.
Message #
Event ID 3044: The endorsement key certificate could not be found in the TPM.
#Description
The endorsement key certificate could not be found in the TPM. The endorsement public key may be used instead. Error: StatusCode.
Message #
Fields #
| Name | Description |
|---|---|
StatusCode Int32 | NTSTATUS reference |
Event ID 3046: The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server.
#Event ID 4001: The HGAttest API completed the operation with status code: ResultCode.
#Description
The HGAttest API completed the operation with status code: ResultCode. Operation: Operation.
Message #
Fields #
| Name | Description |
|---|---|
Operation UInt8 | Known values
|
ResultCode UInt32 |
Event ID 4002: The URL provided for SHS attestation is invalid.
#Event ID 4002
#Description
The URL provided for SHS attestation is invalid. URL.
Fields #
| Name | Description |
|---|---|
Message UnicodeString |
Event ID 4003: Attestation is not supported in this configuration.
#Description
Attestation is not supported in this configuration.
Message #
Event ID 4003
#Description
Attestation is not supported in this configuration.
Event ID 4004: Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.
#Description
Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.
Message #
Event ID 4004
#Description
Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.
Event ID 4005: Remote attestation for a CA Intermediate Certificate is currently not supported.
#Description
Remote attestation for a CA Intermediate Certificate is currently not supported.
Message #
Event ID 4005
#Description
Remote attestation for a CA Intermediate Certificate is currently not supported.
Event ID 4006: This host attempted a remote attestation in ClientOperationMode mode, but the targeted HGS server is operating in ServerOperationMode mode.
#Event ID 4006
#Description
This host attempted a remote attestation in mode, but the targeted HGS server is operating in mode.
Fields #
| Name | Description |
|---|---|
ClientOperationMode UInt8 | |
ServerOperationMode UInt8 |
Event ID 5000: A host key was set from certificate with thumbprint CertThumbprint.
#Event ID 5000
#Description
A host key was set from certificate with thumbprint .
Fields #
| Name | Description |
|---|---|
CertThumbprint UnicodeString |
Event ID 5001: A host key was removed.
#Event ID 5001
#Description
A host key was removed. It was from certificate with thumbprint .
Fields #
| Name | Description |
|---|---|
CertThumbprint UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 7dee1fdc-ffa8-4087-912a-95189d6a2d7f
Defined in HostGuardianServiceClientResources.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02