Microsoft-Windows-LUA

45 events across 2 channels

EventTitleChannelSample
15001ConsentUI_GetUserDesktopSnapshotStartDiagnosticN
15002ConsentUI_GetUserDesktopSnapshotStopDiagnosticN
15003ConsentUI_WindowThreadStartDiagnosticN
15004ConsentUI_WindowThreadStopDiagnosticN
15005ConsentUI_WindowThreadDiagnosticN
15006ConsentUI_SwitchDesktopStartDiagnosticN
15007ConsentUI_SwitchDesktopStopDiagnosticN
15008ConsentUI_ReturnUserDesktopStartDiagnosticN
15009ConsentUI_ReturnUserDesktopStopDiagnosticN
15010ConsentUI_WindowThreadStart15010DiagnosticN
15011ConsentUI_WindowThreadStop15011DiagnosticN
15012ConsentUI_CheckActiveDesktopStartDiagnosticN
15013ConsentUI_CheckActiveDesktopStopDiagnosticN
15014ConsentUI_CheckActiveDesktopStart15014DiagnosticN
15015ConsentUI_CheckActiveDesktopStop15015DiagnosticN
15016ConsentUI_WindowThreadStart15016DiagnosticN
15017ConsentUI_WindowThreadStop15017DiagnosticN
15018ConsentUI_WindowThreadStart15018DiagnosticN
15019ConsentUI_WindowThreadStop15019DiagnosticN
15020ConsentUI_WindowThreadStart15020DiagnosticN
15021ConsentUI_WindowThreadStop15021DiagnosticN
15022ConsentUI_ExperienceStartDiagnosticN
15023ConsentUI_ExperienceStopDiagnosticN
15024ConsentUI_ExperienceStart15024DiagnosticN
15025ConsentUI_ExperienceStop15025DiagnosticN
15026ConsentUI_ExperienceStart15026DiagnosticN
15027ConsentUI_ExperienceStop15027DiagnosticN
15028ConsentUI_LEASVCDiagnosticN
15029ConsentUI_AMScanStartDiagnosticN
15030ConsentUI_AMScanStopDiagnosticN
15031Success: Elevation prompt for executable FullCommandLine (ProgramName published …DiagnosticN
15031Success: Elevation prompt for executable FullCommandLine (ProgramName published …ElevationN
15032Elevation prompt for executable FullCommandLine (ProgramName published by …DiagnosticN
15032Elevation prompt for executable FullCommandLine (ProgramName published by …ElevationN
16001AppInfo_PerfTrack_ElevationPathStartDiagnosticN
16002AppInfo_PerfTrack_ElevationPathStopDiagnosticN
16003AppInfo_PerfTrack_ElevationPathStart16003DiagnosticN
16004AppInfo_PerfTrack_ElevationPathStop16004DiagnosticN
16005AppInfo_PerfTrack_ElevationPathStart16005DiagnosticN
16006AppInfo_PerfTrack_ElevationPathStop16006DiagnosticN
16007AppInfo_PerfTrack_ElevationPathStart16007DiagnosticN
16008AppInfo_PerfTrack_ElevationPathStop16008DiagnosticN
16009AppInfo_PerfTrack_ElevationPathStop16009DiagnosticN
16010AppInfo_PerfTrack_ElevationPathStart16010DiagnosticN
16011AppInfo_PerfTrack_ElevationPathStop16011DiagnosticN

Event ID 15001: ConsentUI_GetUserDesktopSnapshotStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_GetUserDesktopSnapshot
Opcode
Start

Event ID 15002: ConsentUI_GetUserDesktopSnapshotStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_GetUserDesktopSnapshot
Opcode
Stop

Event ID 15003: ConsentUI_WindowThreadStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Start

Event ID 15004: ConsentUI_WindowThreadStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Stop

Event ID 15005: ConsentUI_WindowThread

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread

Event ID 15006: ConsentUI_SwitchDesktopStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_SwitchDesktop
Opcode
Start

Event ID 15007: ConsentUI_SwitchDesktopStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_SwitchDesktop
Opcode
Stop

Event ID 15008: ConsentUI_ReturnUserDesktopStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_ReturnUserDesktop
Opcode
Start

Event ID 15009: ConsentUI_ReturnUserDesktopStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_ReturnUserDesktop
Opcode
Stop

Event ID 15010: ConsentUI_WindowThreadStart15010

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Start

Event ID 15011: ConsentUI_WindowThreadStop15011

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Stop

Event ID 15012: ConsentUI_CheckActiveDesktopStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_CheckActiveDesktop
Opcode
Start

Event ID 15013: ConsentUI_CheckActiveDesktopStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_CheckActiveDesktop
Opcode
Stop

Event ID 15014: ConsentUI_CheckActiveDesktopStart15014

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_CheckActiveDesktop
Opcode
Start

Event ID 15015: ConsentUI_CheckActiveDesktopStop15015

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_CheckActiveDesktop
Opcode
Stop

Event ID 15016: ConsentUI_WindowThreadStart15016

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Start

Event ID 15017: ConsentUI_WindowThreadStop15017

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Stop

Event ID 15018: ConsentUI_WindowThreadStart15018

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Start

Event ID 15019: ConsentUI_WindowThreadStop15019

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Stop

Event ID 15020: ConsentUI_WindowThreadStart15020

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Start

Event ID 15021: ConsentUI_WindowThreadStop15021

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_WindowThread
Opcode
Stop

Event ID 15022: ConsentUI_ExperienceStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Start

Event ID 15023: ConsentUI_ExperienceStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Stop

Event ID 15024: ConsentUI_ExperienceStart15024

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Start

Event ID 15025: ConsentUI_ExperienceStop15025

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Stop

Event ID 15026: ConsentUI_ExperienceStart15026

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Start

Event ID 15027: ConsentUI_ExperienceStop15027

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_Experience
Opcode
Stop

Event ID 15028: ConsentUI_LEASVC

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_LEASVC

Fields #

NameDescription
Parameters Pointer

Event ID 15029: ConsentUI_AMScanStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_AMScan
Opcode
Start

Event ID 15030: ConsentUI_AMScanStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
ConsentUI_AMScan
Opcode
Stop

Event ID 15031: Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
CredUI_Elevation

Description

Success: Elevation prompt for executable ( published by ) answered by , will elevate as .

Fields #

NameDescription
ProgramName UnicodeString
Publisher UnicodeString
FullCommandLine UnicodeString
UserName UnicodeString
ShadowAdmin UnicodeString
ShadowAdminSID UnicodeString
ReturnCode UInt32
ReturnMessage UnicodeString

Event ID 15031: Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as ShadowAdmin.

#
Provider
Microsoft-Windows-LUA
Channel
Elevation
Task
CredUI_Elevation

Description

Success: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName, will elevate as ShadowAdmin.

Message #

Success: Elevation prompt for executable %3 (%1 published by %2) answered by %4, will elevate as %5.

Fields #

NameDescription
ProgramName UnicodeString
Publisher UnicodeString
FullCommandLine UnicodeString
UserName UnicodeString
ShadowAdmin UnicodeString
ShadowAdminSID UnicodeString
ReturnCode UInt32
ReturnMessage UnicodeString

Event ID 15032: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
CredUI_Elevation_Failure

Description

Elevation prompt for executable ( published by ) answered by . Error : .

Fields #

NameDescription
ProgramName UnicodeString
Publisher UnicodeString
FullCommandLine UnicodeString
UserName UnicodeString
ShadowAdmin UnicodeString
ShadowAdminSID UnicodeString
ReturnCode UInt32
ReturnMessage UnicodeString

Event ID 15032: Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName.

#
Provider
Microsoft-Windows-LUA
Channel
Elevation
Task
CredUI_Elevation_Failure

Description

Elevation prompt for executable FullCommandLine (ProgramName published by Publisher) answered by UserName. Error ReturnCode: ReturnMessage.

Message #

Elevation prompt for executable %3 (%1 published by %2) answered by %4. Error %7: %8.

Fields #

NameDescription
ProgramName UnicodeString
Publisher UnicodeString
FullCommandLine UnicodeString
UserName UnicodeString
ShadowAdmin UnicodeString
ShadowAdminSID UnicodeString
ReturnCode UInt32
ReturnMessage UnicodeString

Event ID 16001: AppInfo_PerfTrack_ElevationPathStart

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Start

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16002: AppInfo_PerfTrack_ElevationPathStop

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16003: AppInfo_PerfTrack_ElevationPathStart16003

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Start

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16004: AppInfo_PerfTrack_ElevationPathStop16004

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16005: AppInfo_PerfTrack_ElevationPathStart16005

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Start

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16006: AppInfo_PerfTrack_ElevationPathStop16006

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16007: AppInfo_PerfTrack_ElevationPathStart16007

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Start

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16008: AppInfo_PerfTrack_ElevationPathStop16008

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16009: AppInfo_PerfTrack_ElevationPathStop16009

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16010: AppInfo_PerfTrack_ElevationPathStart16010

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Start

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Event ID 16011: AppInfo_PerfTrack_ElevationPathStop16011

#
Provider
Microsoft-Windows-LUA
Channel
Diagnostic
Task
AppInfo_PerfTrack_ElevationPath
Opcode
Stop

Fields #

NameDescription
EventId UInt32
UACElevateFileID UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 93c05d69-51a3-485e-877f-1806a8731346

Defined in appinfo.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4484, captured 2026-06-02

Downloads