Microsoft-Windows-LAPS

EventTitleChannelSampleRule
10000The Local Administrator Password feature was successfully loaded and …OperationalYN
10001The Local Administrator Password dll failed to initialize.OperationalNN
10002The Local Administrator Password dll was unloaded.OperationalYN
10003LAPS policy processing is now starting.OperationalYN
10004LAPS policy processing succeeded.OperationalYN
10005LAPS policy processing failed with the error code below.OperationalNN
10006LAPS password encryption is required but the Active Directory domain is not yet …OperationalNN
10007LAPS is not currently configured to manage any account.OperationalNN
10008LAPS policy is currently not supported on domain controllers.OperationalNN
10009LAPS is configured to backup passwords to Active Directory.OperationalNN
10010LAPS is configured to backup passwords to Azure Active Directory.OperationalNN
10011LAPS failed when querying Active Directory for the current computer state.OperationalNN
10012The Active Directory schema has not been updated with the necessary LAPS …OperationalNN
10013LAPS failed to find the currently configured local administrator account.OperationalNN
10014LAPS is updating the managed account password due to an Administrator-initiated …OperationalNN
10015The managed account password needs to be updated due to one or more reasons …OperationalNN
10016The managed account password does not need to be updated at this time.OperationalNN
10017LAPS failed to update Active Directory with the new password.OperationalNN
10018LAPS successfully updated Active Directory with the new password.OperationalNN
10019LAPS failed to update the local admin account with the new password.OperationalNN
10020LAPS successfully updated the local admin account with the new password.OperationalNN
10021The current LAPS policy is configured as follows.OperationalNN
10022The current LAPS policy is configured as follows.OperationalNN
10023The current LAPS policy is configured as follows.OperationalNN
10024LAPS policy is configured as disabled.OperationalYN
10025Azure discovery failed.OperationalNN
10026LAPS was unable to authenticate to Azure using the device identity.OperationalNN
10027LAPS was unable to create an acceptable new password.OperationalNN
10028LAPS failed to update Azure Active Directory with the new password.OperationalNN
10029LAPS successfully updated Azure Active Directory with the new password.OperationalNN
10030LAPS is sending a message to the following endpoint.OperationalNN
10031LAPS blocked an external request that tried to modify the password of the …OperationalNN
10032LAPS was unable to authenticate to Azure using the device identity.OperationalNN
10033The machine is configured with legacy LAPS policy settings but a legacy LAPS …OperationalNN
10034The configured encryption principal is an isolated (ambiguous) name.OperationalNN
10035The configured encryption principal name could not be mapped to a known account.OperationalNN
10036The SID for the configured encryption principal could not be mapped to a known …OperationalNN
10037The DSRM account cannot be managed because password encryption is disabled.OperationalNN
10038LAPS failed to update the DSRM administrator account with the new password.OperationalNN
10039LAPS successfully updated the DSRM administrator account with the new password.OperationalNN
10040LAPS blocked an external request that tried to modify the password of the …OperationalNN
10041LAPS detected a successful authentication for the currently managed account.OperationalNN
10042The post-authentication grace period has expired per policy.OperationalNN
10043LAPS failed to reset the password for the currently managed account.OperationalNN
10044LAPS successfully reset the password for the currently managed account and …OperationalNN
10045LAPS successfully reset the password for the currently managed account.OperationalNN
10046LAPS was scheduled to reset the password for the currently managed account after …OperationalNN
10047A pending post-authentication reset timer has been rescheduled after a reboot.OperationalNN
10048The currently pending post-authentication reset timer has been retried the …OperationalNN
10049LAPS attempted to reboot the machine as a post-authentication action but the …OperationalNN
10050LAPS is updating the managed account password due to an Azure-initiated request.OperationalNN
10051LAPS is updating the managed account password in response to a …OperationalNN
10052LAPS is processing the current policy per normal background scheduling.OperationalNN
10053LAPS is processing the current policy in response to an Administrator request.OperationalNN
10054LAPS is processing the current policy in response to a Group Policy change …OperationalNN
10055LAPS is using the following domain controller.OperationalNN
10056LAPS failed to locate a writable domain controller.OperationalNN
10057LAPS was unable to bind over LDAP to the domain controller.OperationalNN
10058The current policy is configured to backup the password to Azure Active …OperationalNN
10059Azure returned a failure code.OperationalNN
10060The current policy is configured to backup the password to Azure Active …OperationalNN
10061The current policy is configured to backup the password to Azure Active …OperationalNN
10062The current policy is configured to backup the password to Active Directory, but …OperationalNN
10063The current policy is configured to backup the password to Active Directory, but …OperationalNN
10064The current policy is configured to backup the DSRM account password to Active …OperationalNN
10065LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password …OperationalNN
10066LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password …OperationalNN
10067The configured local account is currently disabled.OperationalNN
10068This device has been joined to Azure AD.OperationalNN
10069This device has been unjoined from Azure AD.OperationalNN
10070This device has been joined to Active Directory.OperationalNN
10071This device has been unjoined from Active Directory.OperationalNN
10072Encryption of the new password failed.OperationalNN
10073LAPS is now executing the configured post-authentication actions for the target …OperationalNN
10074LAPS has successfully completed all configured post-authentication actions for …OperationalNN
10075LAPS has completed all configured post-authentication actions for the …OperationalNN
10076A post-authentication action was pending for the account below, but the current …OperationalNN
10077LAPS found Data1 interactive logon sessions using the managed account.OperationalNN
10078LAPS successfully notified the following session that a logoff is pending …OperationalNN
10079LAPS failed to notify the following session that a logoff is pending shortly.OperationalNN
10080LAPS is now pausing for Data1 seconds to give the notified sessions time to …OperationalNN
10081LAPS is now logging off all notified sessions.OperationalNN
10082LAPS successfully logged off the following session.OperationalNN
10083LAPS received an error trying to log off the following session.OperationalNN
10084LAPS found Data1 file share sessions using the managed account.OperationalNN
10085LAPS successfully deleted the following file share session.OperationalNN
10086LAPS failed to disconnect the following file share session.OperationalNN
10087LAPS found Data1 processes using the managed account.OperationalNN
10088LAPS successfully terminated the following process.OperationalNN
10089LAPS failed to terminate the following process.OperationalNN
10090The LAPS managed account was enabled.OperationalNN
10091The LAPS managed account was disabled.OperationalNN
10092The LAPS policy is configured for automatic account management mode, but the …OperationalNN
10093The current automatically LAPS managed account was renamed.OperationalNN
10094LAPS failed to rename the managed account.OperationalNN
10095LAPS failed to enable the managed account.OperationalNN
10096LAPS failed to disable the managed account.OperationalNN
10097LAPS deleted the previously managed account.OperationalNN
10098LAPS failed to delete the previously managed account.OperationalNN
10099LAPS renamed and disabled the previously managed builtin administrator account.OperationalNN
10100LAPS failed to rename and disable the previously managed builtin administrator …OperationalNN
10101LAPS blocked an external request that attempted to modify the current …OperationalNN
10102LAPS blocked an external request that attempted to delete the current …OperationalNN
10103LAPS blocked an external request that attempted to modify the security …OperationalNN
10104LAPS blocked an external request that attempted to remove the current …OperationalNN
10105LAPS failed to update its local registry state.OperationalNN
10106LAPS has successfully completed all sysprep cleanup operations.OperationalNN
10107LAPS failed to complete one or more sysprep cleanup operations.OperationalNN
10108The msLAPSCurrentPasswordVersion attribute has not been added to the Active …OperationalNN
20000One or more Local Administrator Password Solution (LAPS) MDM policy values were …OperationalNN

Event ID 10000: The Local Administrator Password feature was successfully loaded and initialized.

#
Channel
Operational
Level
Informational

Message #

The Local Administrator Password feature was successfully loaded and initialized.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-LAPS",
    "event_id": 10000,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:27.8509942+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-LAPS"
  },
  "event_data": {}
}

Event ID 10001: The Local Administrator Password dll failed to initialize.

#
Channel
Operational

Message #

The Local Administrator Password dll failed to initialize.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10002: The Local Administrator Password dll was unloaded.

#
Channel
Operational
Level
Informational

Message #

The Local Administrator Password dll was unloaded.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-LAPS",
    "event_id": 10002,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T19:31:32.3974609+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-LAPS"
  },
  "event_data": {}
}

Event ID 10003: LAPS policy processing is now starting.

#
Channel
Operational
Level
Informational

Message #

LAPS policy processing is now starting.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-LAPS",
    "event_id": 10003,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T16:17:03.2311243+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-LAPS"
  },
  "event_data": {}
}

Event ID 10004: LAPS policy processing succeeded.

#
Channel
Operational
Level
Informational

Message #

LAPS policy processing succeeded.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-LAPS",
    "event_id": 10004,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T16:17:03.2382766+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-LAPS"
  },
  "event_data": {}
}

Event ID 10005: LAPS policy processing failed with the error code below.

#
Channel
Operational

Message #

LAPS policy processing failed with the error code below.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10006: LAPS password encryption is required but the Active Directory domain is not yet at 2016 domain functional level.

#
Channel
Operational

Description

LAPS password encryption is required but the Active Directory domain is not yet at 2016 domain functional level. The password was not updated and no changes will be made until this is corrected.

Message #

LAPS password encryption is required but the Active Directory domain is not yet at 2016 domain functional level. The password was not updated and no changes will be made until this is corrected.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10007: LAPS is not currently configured to manage any account.

#
Channel
Operational

Message #

LAPS is not currently configured to manage any account.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10008: LAPS policy is currently not supported on domain controllers.

#
Channel
Operational

Message #

LAPS policy is currently not supported on domain controllers.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10009: LAPS is configured to backup passwords to Active Directory.

#
Channel
Operational

Message #

LAPS is configured to backup passwords to Active Directory.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10010: LAPS is configured to backup passwords to Azure Active Directory.

#
Channel
Operational

Message #

LAPS is configured to backup passwords to Azure Active Directory.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10011: LAPS failed when querying Active Directory for the current computer state.

#
Channel
Operational

Message #

LAPS failed when querying Active Directory for the current computer state.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10012: The Active Directory schema has not been updated with the necessary LAPS attributes.

#
Channel
Operational

Message #

The Active Directory schema has not been updated with the necessary LAPS attributes.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10013: LAPS failed to find the currently configured local administrator account.

#
Channel
Operational

Message #

LAPS failed to find the currently configured local administrator account.
 
 Account name: %1
 Error code: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10014: LAPS is updating the managed account password due to an Administrator-initiated request.

#
Channel
Operational

Message #

LAPS is updating the managed account password due to an Administrator-initiated request.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10015: The managed account password needs to be updated due to one or more reasons (Data1).

#
Channel
Operational

Message #

The managed account password needs to be updated due to one or more reasons (%1):
 
 %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32
Data2 UnicodeString

Event ID 10016: The managed account password does not need to be updated at this time.

#
Channel
Operational

Message #

The managed account password does not need to be updated at this time.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10017: LAPS failed to update Active Directory with the new password.

#
Channel
Operational

Description

LAPS failed to update Active Directory with the new password. The current password has not been modified.

Message #

LAPS failed to update Active Directory with the new password. The current password has not been modified.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10018: LAPS successfully updated Active Directory with the new password.

#
Channel
Operational

Message #

LAPS successfully updated Active Directory with the new password.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10019: LAPS failed to update the local admin account with the new password.

#
Channel
Operational

Message #

LAPS failed to update the local admin account with the new password.
 
 Account name: %1
 Account RID: %2
 Error code: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32
Data3 HexInt32

Event ID 10020: LAPS successfully updated the local admin account with the new password.

#
Channel
Operational

Message #

LAPS successfully updated the local admin account with the new password.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10021: The current LAPS policy is configured as follows.

#
Channel
Operational

Message #

The current LAPS policy is configured as follows:
 
 Policy source: %1
 Backup directory: %2
 Local administrator account name: %3
 Password age in days: %4
 Password complexity: %5
 Password length: %6
 Password expiration protection enabled: %7
 Password encryption enabled: %8
 Password encryption target principal: %9
 Password encrypted history size: %10
 Backup DSRM password on domain controllers: %11
 Post authentication grace period (hours): %12
 Post authentication actions: %13
 Automatic account management enabled: %14
 Automatic account management: Target: %15
 Automatic account management: Name or name prefix: %16
 Automatic account management: Account enabled: %17
 Automatic account management: Randomize name: %18
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
PolicySource UnicodeString
BackupDirectory UnicodeString
AdminAccountName UnicodeString
PasswordAgeDays Int32
PasswordComplexity Int32
PasswordLength Int32
PasswordExpirationProtectionEnabled Int32
PasswordEncryptionEnabled Int32
PasswordEncryptionTargetPrincipal UnicodeString
PasswordEncryptionHistorySize Int32
BackupDSRMPassword Int32
PostAuthResetDelay Int32
PostAuthActions HexInt32
AutomaticAccountManagementEnabled Int32
AutomaticAccountManagementTarget UnicodeString
AutomaticAccountManagementNameOrPrefix UnicodeString
AutomaticAccountManagementEnableAccount Int32
AutomaticAccountManagementRandomizeName Int32

Event ID 10022: The current LAPS policy is configured as follows.

#
Channel
Operational

Message #

The current LAPS policy is configured as follows:
 
 Policy source: %1
 Backup directory: %2
 Local administrator account name: %3
 Password age in days: %4
 Password complexity: %5
 Password length: %6
 Post authentication grace period (hours): %7
 Post authentication actions: %8
 Automatic account management enabled: %9
 Automatic account management: Target: %10
 Automatic account management: Name or name prefix: %11
 Automatic account management: Account enabled: %12
 Automatic account management: Randomize name: %13
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
PolicySource UnicodeString
BackupDirectory UnicodeString
AdminAccountName UnicodeString
PasswordAgeDays Int32
PasswordComplexity Int32
PasswordLength Int32
PostAuthResetDelay Int32
PostAuthActions HexInt32
AutomaticAccountManagementEnabled Int32
AutomaticAccountManagementTarget UnicodeString
AutomaticAccountManagementNameOrPrefix UnicodeString
AutomaticAccountManagementEnableAccount Int32
AutomaticAccountManagementRandomizeName Int32

Event ID 10023: The current LAPS policy is configured as follows.

#
Channel
Operational

Message #

The current LAPS policy is configured as follows:
 
 Policy source: %1
 Backup directory: %2
 Local administrator account name: %3
 Password age in days: %4
 Password complexity: %5
 Password length: %6
 Password expiration protection enabled: %7
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
PolicySource UnicodeString
BackupDirectory UnicodeString
AdminAccountName UnicodeString
PasswordAgeDays Int32
PasswordComplexity Int32
PasswordLength Int32
PasswordExpirationProtectionEnabled Int32

Event ID 10024: LAPS policy is configured as disabled.

#
Channel
Operational
Level
Informational

Message #

LAPS policy is configured as disabled.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-LAPS",
    "event_id": 10024,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T16:17:03.2376412+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-LAPS"
  },
  "event_data": {}
}

Event ID 10025: Azure discovery failed.

#
Channel
Operational

Message #

Azure discovery failed.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10026: LAPS was unable to authenticate to Azure using the device identity.

#
Channel
Operational

Message #

LAPS was unable to authenticate to Azure using the device identity.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10027: LAPS was unable to create an acceptable new password.

#
Channel
Operational

Description

LAPS was unable to create an acceptable new password. Please verify that the LAPS password length and complexity policy is compatible with the domain and local password policy settings.

Message #

LAPS was unable to create an acceptable new password. Please verify that the LAPS password length and complexity policy is compatible with the domain and local password policy settings.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10028: LAPS failed to update Azure Active Directory with the new password.

#
Channel
Operational

Message #

LAPS failed to update Azure Active Directory with the new password.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10029: LAPS successfully updated Azure Active Directory with the new password.

#
Channel
Operational

Message #

LAPS successfully updated Azure Active Directory with the new password.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10030: LAPS is sending a message to the following endpoint.

#
Channel
Operational

Message #

LAPS is sending a message to the following endpoint.
 
 %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString

Event ID 10031: LAPS blocked an external request that tried to modify the password of the current managed account.

#
Channel
Operational

Message #

LAPS blocked an external request that tried to modify the password of the current managed account.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10032: LAPS was unable to authenticate to Azure using the device identity.

#
Channel
Operational

Message #

LAPS was unable to authenticate to Azure using the device identity.
 
 Web status: %1(%2)
 Error code: %3
 Hresult: %4
 Error msg: %5
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32
Data2 UnicodeString
Data3 HexInt32
Data4 HexInt32
Data5 UnicodeString

Event ID 10033: The machine is configured with legacy LAPS policy settings but a legacy LAPS product appears to be installed.

#
Channel
Operational

Description

The machine is configured with legacy LAPS policy settings but a legacy LAPS product appears to be installed. The configured account's password will not be managed by Windows until the legacy product is uninstalled. Alternatively you may consider configuring the newer LAPS policy settings. See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

The machine is configured with legacy LAPS policy settings but a legacy LAPS product appears to be installed. The configured account's password will not be managed by Windows until the legacy product is uninstalled. Alternatively you may consider configuring the newer LAPS policy settings.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10034: The configured encryption principal is an isolated (ambiguous) name.

#
Channel
Operational

Description

The configured encryption principal is an isolated (ambiguous) name. This must be corrected before the configured account's password can be managed. Please specify the name in either user@domain.com or domain\user format. Encryption principal name: Data1 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

The configured encryption principal is an isolated (ambiguous) name. This must be corrected before the configured account's password can be managed. Please specify the name in either user@domain.com or domain\user format.
 
 Encryption principal name: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString

Event ID 10035: The configured encryption principal name could not be mapped to a known account.

#
Channel
Operational

Description

The configured encryption principal name could not be mapped to a known account. This must be corrected before the configured account's password can be managed.

Message #

The configured encryption principal name could not be mapped to a known account. This must be corrected before the configured account's password can be managed. 
 
 Encryption principal name: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString

Event ID 10036: The SID for the configured encryption principal could not be mapped to a known account.

#
Channel
Operational

Description

The SID for the configured encryption principal could not be mapped to a known account. This must be corrected before the configured account's password can be managed.

Message #

The SID for the configured encryption principal could not be mapped to a known account. This must be corrected before the configured account's password can be managed. 
 
 Encryption principal SID: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString

Event ID 10037: The DSRM account cannot be managed because password encryption is disabled.

#
Channel
Operational

Description

The DSRM account cannot be managed because password encryption is disabled. Please enable password encryption in the LAPS policy settings in order to enable DSRM account password management.

Message #

The DSRM account cannot be managed because password encryption is disabled. Please enable password encryption in the LAPS policy settings in order to enable DSRM account password management.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10038: LAPS failed to update the DSRM administrator account with the new password.

#
Channel
Operational

Message #

LAPS failed to update the DSRM administrator account with the new password.
 
 DSRM account name: %1
 DSRM account RID: %2
 Error code: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32
Data3 HexInt32

Event ID 10039: LAPS successfully updated the DSRM administrator account with the new password.

#
Channel
Operational

Message #

LAPS successfully updated the DSRM administrator account with the new password.
 
 DSRM account name: %1
 DSRM account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10040: LAPS blocked an external request that tried to modify the password of the currently managed DSRM account.

#
Channel
Operational

Message #

LAPS blocked an external request that tried to modify the password of the currently managed DSRM account.
 
 Account RID: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10041: LAPS detected a successful authentication for the currently managed account.

#
Channel
Operational

Description

LAPS detected a successful authentication for the currently managed account. A background task has been scheduled to execute the configured post-authentication actions after the configured grace period has expired. Account name: Data1 Account RID: Data2 Password reset timer deadline: Data3 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

LAPS detected a successful authentication for the currently managed account. A background task has been scheduled to execute the configured post-authentication actions after the configured grace period has expired.
 
 Account name: %1
 Account RID: %2
 Password reset timer deadline: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32
Data3 FILETIME

Event ID 10042: The post-authentication grace period has expired per policy.

#
Channel
Operational

Description

The post-authentication grace period has expired per policy. The configured post-authentication actions will now be executed.

Message #

The post-authentication grace period has expired per policy. The configured post-authentication actions will now be executed.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10043: LAPS failed to reset the password for the currently managed account.

#
Channel
Operational

Description

LAPS failed to reset the password for the currently managed account. The password is considered expired due to an authentication event. LAPS will continue retrying the password reset operation until it succeeds. Account name: Data1 Account RID: Data2 Password reset retry count: Data3 Error code: Data4 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

LAPS failed to reset the password for the currently managed account. The password is considered expired due to an authentication event. LAPS will continue retrying the password reset operation until it succeeds.
 
 Account name: %1
 Account RID: %2
 Password reset retry count: %3
 Error code: %4
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32
Data3 Int32
Data4 HexInt32

Event ID 10044: LAPS successfully reset the password for the currently managed account and completed all configured post-authentication actions.

#
Channel
Operational

Description

LAPS successfully reset the password for the currently managed account after the expiration of the post-authentication grace period.

Message #

LAPS successfully reset the password for the currently managed account after the expiration of the post-authentication grace period.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10045: LAPS successfully reset the password for the currently managed account.

#
Channel
Operational

Description

LAPS successfully reset the password for the currently managed account. One or more configured post-authentication actions failed. The operations will not be retried.

Message #

LAPS successfully reset the password for the currently managed account. One or more configured post-authentication actions failed. The operations will not be retried.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10046: LAPS was scheduled to reset the password for the currently managed account after expiry of the grace period after a previous authentication event.

#
Channel
Operational

Description

LAPS was scheduled to reset the password for the currently managed account after expiration of the grace period after a previous authentication event. However a password reset has already occurred so it will not be reset again. Remaining post-authentication actions will still be executed. Account name: Data1 Account RID: Data2 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

LAPS was scheduled to reset the password for the currently managed account after expiration of the grace period after a previous authentication event. However a password reset has already occurred so it will not be reset again. Remaining post-authentication actions will still be executed.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10047: A pending post-authentication reset timer has been rescheduled after a reboot.

#
Channel
Operational

Message #

A pending post-authentication reset timer has been rescheduled after a reboot.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10048: The currently pending post-authentication reset timer has been retried the maximum allowed number attempts and will no longer be scheduled.

#
Channel
Operational

Message #

The currently pending post-authentication reset timer has been retried the maximum allowed number attempts and will no longer be scheduled.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10049: LAPS attempted to reboot the machine as a post-authentication action but the operation failed.

#
Channel
Operational

Message #

LAPS attempted to reboot the machine as a post-authentication action but the operation failed.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10050: LAPS is updating the managed account password due to an Azure-initiated request.

#
Channel
Operational

Message #

LAPS is updating the managed account password due to an Azure-initiated request.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10051: LAPS is updating the managed account password in response to a post-authentication action.

#
Channel
Operational

Message #

LAPS is updating the managed account password in response to a post-authentication action.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10052: LAPS is processing the current policy per normal background scheduling.

#
Channel
Operational

Message #

LAPS is processing the current policy per normal background scheduling.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10053: LAPS is processing the current policy in response to an Administrator request.

#
Channel
Operational

Message #

LAPS is processing the current policy in response to an Administrator request.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10054: LAPS is processing the current policy in response to a Group Policy change notification.

#
Channel
Operational

Message #

LAPS is processing the current policy in response to a Group Policy change notification.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10055: LAPS is using the following domain controller.

#
Channel
Operational

Message #

LAPS is using the following domain controller:
 
 DCName: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString

Event ID 10056: LAPS failed to locate a writable domain controller.

#
Channel
Operational

Message #

LAPS failed to locate a writable domain controller.
 
 Error code: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10057: LAPS was unable to bind over LDAP to the domain controller.

#
Channel
Operational

Message #

LAPS was unable to bind over LDAP to the domain controller:
 %
 DCName: %1
 Error code: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10058: The current policy is configured to backup the password to Azure Active Directory, but has a configured PasswordAgeDays value that is less than the...

#
Channel
Operational

Description

The current policy is configured to backup the password to Azure Active Directory, but has a configured PasswordAgeDays value that is less than the required minimum.

Message #

The current policy is configured to backup the password to Azure Active Directory, but has a configured PasswordAgeDays value that is less than the required minimum:
 
 Configured value: %1
 Minimum value: %2
 
 The configured value will be ignored and the minimum value will be used instead.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 Int32
Data2 Int32

Event ID 10059: Azure returned a failure code.

#
Channel
Operational

Message #

Azure returned a failure code.
 
 HTTP status code: %1
 
 Response text:
 %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 Int32
Data2 UnicodeString

Event ID 10060: The current policy is configured to backup the password to Azure Active Directory, but the machine is only joined to Active Directory.

#
Channel
Operational

Description

The current policy is configured to backup the password to Azure Active Directory, but the machine is only joined to Active Directory. Please configure the policy to backup the password to Active Directory. No action will be taken until this is corrected. See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

The current policy is configured to backup the password to Azure Active Directory, but the machine is only joined to Active Directory. Please configure the policy to backup the password to Active Directory. No action will be taken until this is corrected.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10061: The current policy is configured to backup the password to Azure Active Directory, but the machine is workplace-joined.

#
Channel
Operational

Description

The current policy is configured to backup the password to Azure Active Directory, but the machine is workplace-joined. LAPS does not support workplace-joined machines for any scenario.

Message #

The current policy is configured to backup the password to Azure Active Directory, but the machine is workplace-joined. LAPS does not support workplace-joined machines for any scenario.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10062: The current policy is configured to backup the password to Active Directory, but the machine is only joined to Azure Active Directory.

#
Channel
Operational

Description

The current policy is configured to backup the password to Active Directory, but the machine is only joined to Azure Active Directory. Please configure the policy to backup the password to Azure Active Directory. No action will be taken until this is corrected. See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

The current policy is configured to backup the password to Active Directory, but the machine is only joined to Azure Active Directory. Please configure the policy to backup the password to Azure Active Directory. No action will be taken until this is corrected.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10063: The current policy is configured to backup the password to Active Directory, but the machine is workplace-joined.

#
Channel
Operational

Description

The current policy is configured to backup the password to Active Directory, but the machine is workplace-joined. LAPS does not support workplace-joined machines for any scenario.

Message #

The current policy is configured to backup the password to Active Directory, but the machine is workplace-joined. LAPS does not support workplace-joined machines for any scenario.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10064: The current policy is configured to backup the DSRM account password to Active Directory, but password encryption is not enabled.

#
Channel
Operational

Description

The current policy is configured to backup the DSRM account password to Active Directory, but password encryption is not enabled. Please configure the policy to enable password encryption. No action will be taken until this is corrected. See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

The current policy is configured to backup the DSRM account password to Active Directory, but password encryption is not enabled. Please configure the policy to enable password encryption. No action will be taken until this is corrected.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10065: LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password using the legacy LAPS password attribute.

#
Channel
Operational

Description

LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password using the legacy LAPS password attribute. You should update the permissions on this computer's container using the Update-AdmPwdComputerSelfPermission cmdlet, for example: Update-AdmPwdComputerSelfPermission -Identity 'Data1' See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password using the legacy LAPS password attribute. You should update the permissions on this computer's container using the Update-AdmPwdComputerSelfPermission cmdlet, for example:
 
 Update-AdmPwdComputerSelfPermission -Identity '%1' 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString

Event ID 10066: LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password using the LAPS password attribute.

#
Channel
Operational

Description

LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password using the LAPS password attribute. You should update the permissions on this computer's container using the Set-LapsADComputerSelfPermission cmdlet, for example: Set-LapsADComputerSelfPermission -Identity 'Data1' See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

LAPS received an LDAP_INSUFFICIENT_RIGHTS error trying to update the password using the LAPS password attribute. You should update the permissions on this computer's container using the Set-LapsADComputerSelfPermission cmdlet, for example:
 
 Set-LapsADComputerSelfPermission -Identity '%1' 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString

Event ID 10067: The configured local account is currently disabled.

#
Channel
Operational

Description

The configured local account is currently disabled. The account must be enabled before it can be used.

Message #

The configured local account is currently disabled. The account must be enabled before it can be used.
 
 Account name: %1
 Account RID: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10068: This device has been joined to Azure AD.

#
Channel
Operational

Description

This device has been joined to Azure AD. This message is informational only and no action is necessary.

Message #

This device has been joined to Azure AD. This message is informational only and no action is necessary.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10069: This device has been unjoined from Azure AD.

#
Channel
Operational

Description

This device has been unjoined from Azure AD. This message is informational only and no action is necessary.

Message #

This device has been unjoined from Azure AD. This message is informational only and no action is necessary.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10070: This device has been joined to Active Directory.

#
Channel
Operational

Description

This device has been joined to Active Directory. This message is informational only and no action is necessary.

Message #

This device has been joined to Active Directory. This message is informational only and no action is necessary.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10071: This device has been unjoined from Active Directory.

#
Channel
Operational

Description

This device has been unjoined from Active Directory. This message is informational only and no action is necessary.

Message #

This device has been unjoined from Active Directory. This message is informational only and no action is necessary.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10072: Encryption of the new password failed.

#
Channel
Operational

Message #

Encryption of the new password failed.
 
 Error code: %1
 
 This problem may occur if a KDS root key is not available. Verify that a KDS root key is available by running the Get-KdsRootKey PowerShell cmdlet, and also verify that the root key's EffectiveTime field is valid right now.
 
 If a KDS root key is not present, you must add one by running the Add-KdsRootKey PowerShell cmdlet with the -EffectiveImmediately parameter. Allow sufficient time for the new key to replicate around your forest.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10073: LAPS is now executing the configured post-authentication actions for the target account.

#
Channel
Operational

Message #

LAPS is now executing the configured post-authentication actions for the target account.
 
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString

Event ID 10074: LAPS has successfully completed all configured post-authentication actions for the LAPS-managed account identity.

#
Channel
Operational

Message #

LAPS has successfully completed all configured post-authentication actions for the LAPS-managed account identity.
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString

Event ID 10075: LAPS has completed all configured post-authentication actions for the LAPS-managed account identity.

#
Channel
Operational

Description

LAPS has completed all configured post-authentication actions for the LAPS-managed account identity. One or more of these actions encountered a failure. See the other intervening event log messages for more details. Account name: Data1 Account sid: Data2 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

LAPS has completed all configured post-authentication actions for the LAPS-managed account identity. One or more of these actions encountered a failure. See the other intervening event log messages for more details.
 
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString

Event ID 10076: A post-authentication action was pending for the account below, but the current policy is now targeting a different account.

#
Channel
Operational

Description

A post-authentication action was pending for the account below, but the current policy is now targeting a different account. No post-authentication actions for the original account will be executed.

Message #

A post-authentication action was pending for the account below, but the current policy is now targeting a different account. No post-authentication actions for the original account will be executed.
 
 Original account sid: %1
 Current account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString

Event ID 10077: LAPS found Data1 interactive logon sessions using the managed account.

#
Channel
Operational

Message #

LAPS found %1 interactive logon sessions using the managed account.
 
 Account name: %2
 Account sid: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 Int32
Data2 UnicodeString
Data3 UnicodeString

Event ID 10078: LAPS successfully notified the following session that a logoff is pending shortly.

#
Channel
Operational

Message #

LAPS successfully notified the following session that a logoff is pending shortly.
 
 ExecEnvId: %1
 State: %2
 SessionId: %3
 Session name: %4
 Host name: %5
 User name: %6
 Domain name: %7
 Farm name: %8
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
ExecEnvId Int32
State Int32
SessionId Int32
SessionName UnicodeString
HostName UnicodeString
UserName UnicodeString
DomainName UnicodeString
FarmName UnicodeString

Event ID 10079: LAPS failed to notify the following session that a logoff is pending shortly.

#
Channel
Operational

Description

LAPS failed to notify the following session that a logoff is pending shortly. The logoff action will proceed regardless.

Message #

LAPS failed to notify the following session that a logoff is pending shortly. The logoff action will proceed regardless.
 
 ExecEnvId: %1
 State: %2
 SessionId: %3
 Session name: %4
 Host name: %5
 User name: %6
 Domain name: %7
 Farm name: %8
 
 Error: %9
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
ExecEnvId Int32
State Int32
SessionId Int32
SessionName UnicodeString
HostName UnicodeString
UserName UnicodeString
DomainName UnicodeString
FarmName UnicodeString
Error Int32

Event ID 10080: LAPS is now pausing for Data1 seconds to give the notified sessions time to logoff.

#
Channel
Operational

Message #

LAPS is now pausing for %1 seconds to give the notified sessions time to logoff.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 Int32

Event ID 10081: LAPS is now logging off all notified sessions.

#
Channel
Operational

Message #

LAPS is now logging off all notified sessions.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10082: LAPS successfully logged off the following session.

#
Channel
Operational

Message #

LAPS successfully logged off the following session.
 
 ExecEnvId: %1
 State: %2
 SessionId: %3
 Session name: %4
 Host name: %5
 User name: %6
 Domain name: %7
 Farm name: %8
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
ExecEnvId Int32
State Int32
SessionId Int32
SessionName UnicodeString
HostName UnicodeString
UserName UnicodeString
DomainName UnicodeString
FarmName UnicodeString

Event ID 10083: LAPS received an error trying to log off the following session.

#
Channel
Operational

Description

LAPS received an error trying to log off the following session. This action will not be retried.

Message #

LAPS received an error trying to log off the following session. This action will not be retried.
 
 ExecEnvId: %1
 State: %2
 SessionId: %3
 Session name: %4
 Host name: %5
 User name: %6
 Domain name: %7
 Farm name: %8
 
 Error: %9
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
ExecEnvId Int32
State Int32
SessionId Int32
SessionName UnicodeString
HostName UnicodeString
UserName UnicodeString
DomainName UnicodeString
FarmName UnicodeString
Error Int32

Event ID 10084: LAPS found Data1 file share sessions using the managed account.

#
Channel
Operational

Message #

LAPS found %1 file share sessions using the managed account.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 Int32

Event ID 10085: LAPS successfully deleted the following file share session.

#
Channel
Operational

Message #

LAPS successfully deleted the following file share session.
 
 SessionId: %1
 ClientComputerName: %2
 ClientUserName: %3
 NumOpens: %4
 SecondsIdle: %5
 SecondsExisted: %6
 ServerName: %7
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
SessionId HexInt64
ClientComputerName UnicodeString
ClientUserName UnicodeString
NumOpens Int64
SecondsIdle Int32
SecondsExisted Int32
ServerName UnicodeString

Event ID 10086: LAPS failed to disconnect the following file share session.

#
Channel
Operational

Description

LAPS failed to disconnect the following file share session. This action will not be retried.

Message #

LAPS failed to disconnect the following file share session. This action will not be retried.
 
 SessionId: %1
 ClientComputerName: %2
 ClientUserName: %3
 NumOpens: %4
 SecondsIdle: %5
 SecondsExisted: %6
 ServerName: %7
 
 Error: %8
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
SessionId HexInt64
ClientComputerName UnicodeString
ClientUserName UnicodeString
NumOpens Int64
SecondsIdle Int32
SecondsExisted Int32
ServerName UnicodeString
Error Int32

Event ID 10087: LAPS found Data1 processes using the managed account.

#
Channel
Operational

Message #

LAPS found %1 processes using the managed account.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 Int32

Event ID 10088: LAPS successfully terminated the following process.

#
Channel
Operational

Message #

LAPS successfully terminated the following process.
 
 Path: %1
 Process id: %2
 Account name: %3
 Account sid: %4
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 Int32
Data3 UnicodeString
Data4 UnicodeString

Event ID 10089: LAPS failed to terminate the following process.

#
Channel
Operational

Description

LAPS failed to terminate the following process. This action will not be retried.

Message #

LAPS failed to terminate the following process. This action will not be retried.
 
 Path: %1
 Process id: %2
 Account name: %3
 Account sid: %4
 Error: %5
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 Int32
Data3 UnicodeString
Data4 UnicodeString
Data5 HexInt32

Event ID 10090: The LAPS managed account was enabled.

#
Channel
Operational

Message #

The LAPS managed account was enabled.
 
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString

Event ID 10091: The LAPS managed account was disabled.

#
Channel
Operational

Message #

The LAPS managed account was disabled.
 
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString

Event ID 10092: The LAPS policy is configured for automatic account management mode, but the account name or prefix is too long and will be truncated.

#
Channel
Operational

Description

The LAPS policy is configured for automatic account management mode, but the account name or prefix is too long and will be truncated. The maximum allowable length is 20 characters when account name randomization is disabled, or 14 characters when account name randomization is enabled. Configured account name or prefix: Data1 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

The LAPS policy is configured for automatic account management mode, but the account name or prefix is too long and will be truncated. The maximum allowable length is 20 characters when account name randomization is disabled, or 14 characters when account name randomization is enabled.
 
 Configured account name or prefix: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString

Event ID 10093: The current automatically LAPS managed account was renamed.

#
Channel
Operational

Message #

The current automatically LAPS managed account was renamed.
 
 Previous account name: %1
 New account name: %2
 Account sid: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString
Data3 UnicodeString

Event ID 10094: LAPS failed to rename the managed account.

#
Channel
Operational

Message #

LAPS failed to rename the managed account.
 
 Account name: %1
 Account sid: %2
 Intended new account name: %3
 Error: %4
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString
Data3 UnicodeString
Data4 HexInt32

Event ID 10095: LAPS failed to enable the managed account.

#
Channel
Operational

Message #

LAPS failed to enable the managed account.
 
 Account name: %1
 Account sid: %2
 Error: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString
Data3 HexInt32

Event ID 10096: LAPS failed to disable the managed account.

#
Channel
Operational

Message #

LAPS failed to disable the managed account.
 
 Account name: %1
 Account sid: %2
 Error: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString
Data3 HexInt32

Event ID 10097: LAPS deleted the previously managed account.

#
Channel
Operational

Message #

LAPS deleted the previously managed account.
 
 Account name: %1
 Account sid: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString

Event ID 10098: LAPS failed to delete the previously managed account.

#
Channel
Operational

Message #

LAPS failed to delete the previously managed account.
 
 Account name: %1
 Account sid: %2
 Error: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString
Data3 HexInt32

Event ID 10099: LAPS renamed and disabled the previously managed builtin administrator account.

#
Channel
Operational

Message #

LAPS renamed and disabled the previously managed builtin administrator account.
 
 Previous account name: %1
 New account name: %2
 Account sid: %3
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 UnicodeString
Data3 UnicodeString

Event ID 10100: LAPS failed to rename and disable the previously managed builtin administrator account.

#
Channel
Operational

Message #

LAPS failed to rename and disable the previously managed builtin administrator account.
 
 Account sid: %1
 Error: %2
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 UnicodeString
Data2 HexInt32

Event ID 10101: LAPS blocked an external request that attempted to modify the current automatically managed account.

#
Channel
Operational

Message #

LAPS blocked an external request that attempted to modify the current automatically managed account.
 
 Account name: %1
 Account sid: %2
 Client name: %3
 Client address: %4
 Client process ID: %5
 Client process exe: %6
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
LAPSManagedAccountName UnicodeString
LAPSManagedAccountSid UnicodeString
ClientName UnicodeString
ClientAddress UnicodeString
ClientProcessID Int32
ClientProcessExe UnicodeString

Event ID 10102: LAPS blocked an external request that attempted to delete the current automatically managed account.

#
Channel
Operational

Message #

LAPS blocked an external request that attempted to delete the current automatically managed account.
 
 Account name: %1
 Account sid: %2
 Client name: %3
 Client address: %4
 Client process ID: %5
 Client process exe: %6
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
LAPSManagedAccountName UnicodeString
LAPSManagedAccountSid UnicodeString
ClientName UnicodeString
ClientAddress UnicodeString
ClientProcessID Int32
ClientProcessExe UnicodeString

Event ID 10103: LAPS blocked an external request that attempted to modify the security descriptor of the current automatically managed account.

#
Channel
Operational

Message #

LAPS blocked an external request that attempted to modify the security descriptor of the current automatically managed account.
 
 Account name: %1
 Account sid: %2
 Client name: %3
 Client address: %4
 Client process ID: %5
 Client process exe: %6
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
LAPSManagedAccountName UnicodeString
LAPSManagedAccountSid UnicodeString
ClientName UnicodeString
ClientAddress UnicodeString
ClientProcessID Int32
ClientProcessExe UnicodeString

Event ID 10104: LAPS blocked an external request that attempted to remove the current automatically managed account from the local administrators group.

#
Channel
Operational

Message #

LAPS blocked an external request that attempted to remove the current automatically managed account from the local administrators group.
 
 Account name: %1
 Account sid: %2
 Client name: %3
 Client address: %4
 Client process ID: %5
 Client process exe: %6
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
LAPSManagedAccountName UnicodeString
LAPSManagedAccountSid UnicodeString
ClientName UnicodeString
ClientAddress UnicodeString
ClientProcessID Int32
ClientProcessExe UnicodeString

Event ID 10105: LAPS failed to update its local registry state.

#
Channel
Operational

Message #

LAPS failed to update its local registry state.
 
 Error: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10106: LAPS has successfully completed all sysprep cleanup operations.

#
Channel
Operational

Message #

LAPS has successfully completed all sysprep cleanup operations.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 10107: LAPS failed to complete one or more sysprep cleanup operations.

#
Channel
Operational

Message #

LAPS failed to complete one or more sysprep cleanup operations.
 
 Error: %1
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Fields #

NameDescription
Data1 HexInt32

Event ID 10108: The msLAPSCurrentPasswordVersion attribute has not been added to the Active Directory schema.

#
Channel
Operational

Description

The msLAPSCurrentPasswordVersion attribute has not been added to the Active Directory schema. This attribute is used to detect torn state conditions caused by OS image rollback scenarios. All primary scenarios will function without this attribute however it is recommended that administrator fix this by re-running the latest Update-LapsADSchema cmdlet. See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Message #

The msLAPSCurrentPasswordVersion attribute has not been added to the Active Directory schema. This attribute is used to detect torn state conditions caused by OS image rollback scenarios. All primary scenarios will function without this attribute however it is recommended that administrator fix this by re-running the latest Update-LapsADSchema cmdlet.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Event ID 20000: One or more Local Administrator Password Solution (LAPS) MDM policy values were blocked from being set because the current machine is joined to nei...

#
Channel
Operational

Description

One or more Local Administrator Password Solution (LAPS) MDM policy values were blocked from being set because the current machine is joined to neither Azure Active Directory or Active Directory.

Message #

One or more Local Administrator Password Solution (LAPS) MDM policy values were blocked from being set because the current machine is joined to neither Azure Active Directory or Active Directory.
 
 This message may be safely ignored but is likely to re-occur periodically. To stop further instances of this warning, please reconfigure your MDM policy so that no LAPS policy settings are applied to this machine.
 
 See https://go.microsoft.com/fwlink/?linkid=2220550 for more information.

Provenance

ETW provider GUID 4fcc72a9-d7ca-5dd2-8d34-6f41a0cdb7e0

Defined in laps.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB