Microsoft-Windows-Management-SecureAssessment

11 events across 1 channel

Event ID 100: An error was encountered.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Opcode
Info

Description

An error was encountered. (error code = ErrorCode; function = Function; line number = LineNumber).

Message #

An error was encountered. (error code = %1; function = %2; line number = %3)

Fields #

NameDescription
ErrorCode HexInt32
Function AnsiString
LineNumber UInt32

Event ID 101: A process was forcibly terminated.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Opcode
Info

Description

A process was forcibly terminated. (process name = ProcessName; result = TerminationResult).

Message #

A process was forcibly terminated. (process name = %1; result = %2)

Fields #

NameDescription
ProcessName UnicodeString
TerminationResult Boolean

Event ID 200: A new lockdown request has been received.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Task
Lockdown

Description

A new lockdown request has been received. (enable lockdown = Enable; already locked down = CurrentlyEnabled).

Message #

A new lockdown request has been received. (enable lockdown = %1; already locked down = %2)

Fields #

NameDescription
Enable Boolean
CurrentlyEnabled Boolean

Event ID 201: Creating a lockdown context for the app.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Task
Lockdown

Description

Creating a lockdown context for the app. (Create new = NewContextCreated).

Message #

Creating a lockdown context for the app. (Create new = %1)

Fields #

NameDescription
NewContextCreated Boolean

Event ID 202: Enrolling the device succeeded.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Task
Lockdown

Description

Enrolling the device succeeded. (enrollment ID = EnrollmentID).

Message #

Enrolling the device succeeded. (enrollment ID = %1)

Fields #

NameDescription
EnrollmentID UnicodeString

Event ID 203: Enrolling the device failed.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Task
Lockdown

Description

Enrolling the device failed. (error = ErrorCode).

Message #

Enrolling the device failed. (error = %1)

Fields #

NameDescription
ErrorCode HexInt32

Event ID 204: Lockdown policies were successfully applied.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Task
Lockdown

Description

Lockdown policies were successfully applied. (enrollment ID = EnrollmentID).

Message #

Lockdown policies were successfully applied. (enrollment ID = %1)

Fields #

NameDescription
EnrollmentID UnicodeString

Event ID 205: Lockdown is enforced.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Task
Lockdown

Description

Lockdown is enforced. (enrollment ID = EnrollmentID; caller ID = CallerID).

Message #

Lockdown is enforced. (enrollment ID = %1; caller ID = %2)

Fields #

NameDescription
EnrollmentID UnicodeString
CallerID UnicodeString

Event ID 206: Lockdown request completed successfully.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Task
Lockdown

Description

Lockdown request completed successfully. (Enable = Enable).

Message #

Lockdown request completed successfully. (Enable = %1)

Fields #

NameDescription
Enable Boolean

Event ID 207: Device enrollment was skipped for this lockdown session.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Task
Lockdown

Description

Device enrollment was skipped for this lockdown session.

Message #

Device enrollment was skipped for this lockdown session.

Event ID 208: Unenrollment completed successfully.

#
Provider
Microsoft-Windows-Management-SecureAssessment
Channel
Operational
Task
Lockdown

Description

Unenrollment completed successfully. (enrollment ID = EnrollmentID).

Message #

Unenrollment completed successfully. (enrollment ID = %1)

Fields #

NameDescription
EnrollmentID UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID a329cf81-57ec-46ed-ab7c-261a52b0754a

Defined in Windows.Management.SecureAssessment.Diagnostics.dll, which carries the event manifest.

Observed on:

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads