Microsoft-Windows-ModernDeployment-Diagnostics-Provider

EventTitleChannelSampleRule
100Autopilot policy [Message1] not found.AutopilotYN
101AutopilotGetPolicyDwordByName succeeded: policy name = Message1; policy value = …AutopilotNN
102AutopilotGetPolicyDwordByName error: policy name = Message1; HRESULT = HRESULT.AutopilotNN
103AutopilotGetPolicyStringByName succeeded: policy name = Message1; policy value = …AutopilotNN
104AutopilotGetPolicyStringByName error: policy name = Message1; HRESULT = HRESULT.AutopilotNN
105AutopilotDisable succeeded.AutopilotNN
106AutopilotDisable error: HRESULT = HRESULT.AutopilotNN
107Autopilot state = Message1.AutopilotNN
108AutopilotIsDisabled error: HRESULT = HRESULT.AutopilotNN
109AutopilotGetOobeSettingsOverride succeeded: OOBE setting = Message1; state = …AutopilotNN
110AutopilotGetOobeSettingsOverride error: OOBE setting = Message1; HRESULT = …AutopilotNN
111AutopilotRetrieveSettings succeeded.AutopilotNN
112AutopilotRetrieveSettings error: HRESULT = HRESULT.AutopilotNN
113Autopilot reported the DLL was unloaded while there were Int1 outstanding calls.AutopilotNN
114AutopilotRetrieveSettings was skipped because this version of Windows does not …AutopilotNN
115Autopilot discovery failed to find a valid MDM.AutopilotNN
116Autopilot Device ESP Domain Controller override was not set.AutopilotNN
117Autopilot Device ESP Domain Controller override was set by state UInt1.AutopilotNN
118Autopilot task to detect hardware change started.AutopilotNN
119Autopilot task to detect hardware change finished successfully.AutopilotNN
120Autopilot task to detect hardware change failed.AutopilotNN
121Autopilot task to detect hardware change finished successfully.AutopilotNN
122Autopilot task to detect hardware change finished successfully.AutopilotNN
123Autopilot task to detect hardware change was aborted or cancelled before …AutopilotNN
124Autopilot starting to disable task: Message1.AutopilotNN
125Autopilot successfully disabled task: Autopilot_successfully_disabled_task.AutopilotNN
126Autopilot failed to disable task.AutopilotNN
127Autopilot starting to enable task: Message1.AutopilotNN
128Autopilot successfully enabled task: Autopilot_successfully_enabled_task.AutopilotNN
129Autopilot failed to enable task.AutopilotNN
130Autopilot hardware remediation report failed.AutopilotNN
131Autopilot hardware remediation must wait before reporting again.DiagnosticsNN
132Autopilot hardware remediation failed to process response.AutopilotNN
133Autopilot hardware remediation failed to read cached hardware.AutopilotNN
134Autopilot hardware remediation failed to write cached hardware.AutopilotNN
150AutopilotManager started the MSA service for TPM attestation identity.AutopilotNN
151AutopilotManager started the TPM maintenance task to update TPM attestation.AutopilotNN
152AutopilotManager reported TPM maintenance task is complete.AutopilotNN
153AutopilotManager reported the state changed from InitialState to UpdateState.AutopilotYN
154AutopilotManager failed to start MSA service.AutopilotNN
155AutopilotManager failed to start TPM task.AutopilotNN
156AutopilotManager reported that MSA TPM is not configured for hardware TPM …AutopilotNN
157AutopilotManager reported that TPM attestation lasted UInt1 microseconds.AutopilotNN
158AutopilotManager reported that TPM enhanced diagnostics logging was enabled for …AutopilotNN
160AutopilotRetrieveSettings beginning acquisition.AutopilotNN
161AutopilotManager retrieve settings succeeded.AutopilotYN
162AutopilotManager determined download is not required and the device is not …AutopilotYN
163AutopilotManager determined download is not required and the device is already …AutopilotNN
164AutopilotManager determined Internet is available to attempt policy download.AutopilotYN
165AutopilotManager determined Internet is not available; policy download will …AutopilotNN
166AutopilotManager reported Internet is now available.AutopilotYN
167AutopilotManager reported Internet is still not available.AutopilotNN
168AutopilotManager reported MSA TPM device identity was updated.AutopilotNN
169AutopilotManager set TPM identity confirmed.AutopilotNN
170AutopilotManager reported that Autopilot profile download is now complete.AutopilotYN
171AutopilotManager failed to set TPM identity confirmed.AutopilotNN
172AutopilotManager failed to set Autopilot profile as available.AutopilotNN
173AutopilotManager failed to register for network availability.AutopilotNN
174AutopilotManager failed to register for device identity availability.AutopilotNN
175AutopilotManager failed to register for device identity task update.AutopilotNN
176MSA TPM keystate has been updated.AutopilotNN
177Configuring TPM for attestation.AutopilotNN
178AutopilotManager began device enrollment with internal state Int1.AutopilotNN
179AutopilotManager began device enrollment phase State.AutopilotNN
180AutopilotManager failed during device enrollment phase State.AutopilotNN
181AutopilotManager completed device enrollment phase State.AutopilotNN
182AutopilotManager reported that the retry timer event was set to UInt1 …AutopilotNN
183AutopilotManager reported that the retry timer event occurredAutopilotNN
184AutopilotManager failed to register for MSA keystate update availability.AutopilotNN
185AutopilotManager failed to retrieve settings.AutopilotNN
186AutopilotManager TPM configuration already in progress.AutopilotNN
187AutopilotManager TPM configuration occurred before retry timer ready.AutopilotNN
189Configuring TPM exceeded maximum number of attempts.AutopilotNN
190Windows AIK certificate enrollment task was triggered.AutopilotNN
191Windows TPM maintenance task is being skipped since AIK certificate is already …AutopilotNN
192Autopilot device enrollment failed with error HRESULT = HRESULT.AutopilotNN
193Autopilot manager is attempting profile download retry.AutopilotNN
194Autopilot manager will re-attempt the download after UInt1 milliseconds.AutopilotNN
195AutopilotManager began device unenrollmentAutopilotNN
196AutopilotManager completed device unenrollment.AutopilotNN
197AutopilotManager failed device unenrollment.AutopilotNN
200Windows AIK object could not be loaded.AutopilotNN
201Windows AIK key not found by name.AutopilotNN
202Windows AIK certificate download failed.AutopilotNN
203Windows AIK alternative load failed.AutopilotNN
204Windows AIK certificate request did not result in a new certificate.AutopilotNN
205Windows AIK certificate request succeeded and a new certificate is available.AutopilotNN
206Windows AIK key could not be opened.AutopilotNN
207Windows AIK key failed certificate request.AutopilotNN
208Windows EK certificate is present.AutopilotNN
209Windows EK certificate is not present.AutopilotNN
210Windows AIK key was found even though the Windows EK certificate is not present.AutopilotNN
211AutopilotManager reported that a TPM was required but the TPM failed an …AutopilotNN
212AutopilotManager reported the TPM returned the following for known …AutopilotNN
213AutopilotManager reported the TPM returned the following for Key attestation …AutopilotNN
250AutopilotManager started AIK certificate acquisition task.AutopilotNN
251AutopilotManager reported AIK certificate acquisition task returned HRESULT = …AutopilotNN
252AutopilotManager reported AIK key was located.AutopilotNN
253AutopilotManager reported AIK certificate was located.AutopilotNN
254AutopilotManager reported AIK certificate was not located.AutopilotNN
285AutopilotManager is determining whether device has internet access.AutopilotYN
286AutopilotManager is determining Autopilot profile availability.AutopilotYN
287Tracking resource type Message1.AutopilotNN
288Tracking resource type Message1.AutopilotNN
289Tracking resource type Message1.AutopilotNN
290Tracking resource type Message1.AutopilotNN
291Tracking resource type Message1.AutopilotNN
292Tracking resource type Message1.AutopilotNN
293Tracking resource type Message1.AutopilotNN
294Tracking resource type Message1.AutopilotNN
295Tracking resource type Message1.AutopilotNN
296Tracking resource type Message1.AutopilotNN
297Tracking resource type Message1.AutopilotNN
298Tracking resource type Message1.AutopilotNN
299Tracking resource type Message1.AutopilotNN
300AutopilotManager device enrollment reported an initialization failure.AutopilotNN
301AutopilotManager device enrollment reported a blocking failure.AutopilotNN
302AutopilotManager device enrollment failed during stage State with error HRESULT.AutopilotNN
303AutopilotManager device enrollment succeeded.AutopilotNN
310Autopilot configuration file path: Autopilot_configuration_file_path.AutopilotNN
311Failed to load Autopilot configuration file, HRESULT = HRESULT.AutopilotNN
312Failed to parse Autopilot configuration file, HRESULT = HRESULT.AutopilotNN
313Invalid ZtdCorrelationId found in Autopilot configuration file, HRESULT = …AutopilotNN
314AutopilotManager reported that the Autopilot profile data could not be …AutopilotNN
315AutopilotManager failed to record the setting for Autopilot device not managed, …AutopilotNN
316AutopilotSync: Starting sync sessions for SyncType: UInt1.AutopilotNN
317AutopilotSync: Ending sync sessions for SyncType: UInt1.AutopilotNN
318AutopilotSync: Attempted sync session.AutopilotNN
319AutopilotSync: Skipped sync session.AutopilotNN
320AutopilotSync: Using user SID: AutopilotSync_Using_user_SID.AutopilotNN
321AutopilotSync: Current sync session.AutopilotNN
350Autopilot for Surface Hub encountered bad override data.DiagnosticsNN
351Autopilot for Surface Hub override succeeded.DiagnosticsNN
352Autopilot for Surface Hub failed to configure properties.DiagnosticsNN
353Autopilot for Surface Hub failed to apply properties.DiagnosticsNN
354Autopilot for Surface Hub applied properties successfullyDiagnosticsNN
355Autopilot for Surface Hub failed to validate a property.DiagnosticsNN
356Autopilot for Surface Hub failed to execute the Csp successfully.DiagnosticsNN
357Autopilot for Surface Hub validated and applied properties successfullyDiagnosticsNN
358Autopilot for Surface Hub failed to apply the device account successfully.DiagnosticsNN
400Autopilot Initial Provisioning reported a change in connection status.AutopilotNN
401Autopilot Initial Provisioning heartbeat occurred.AutopilotNN
402Autopilot Initial Provisioning detected a network state change.AutopilotNN
403Autopilot Provisioning change.AutopilotNN
404Autopilot Provisioning change started.AutopilotNN
405Autopilot Provisioning change succeeded.AutopilotNN
406Autopilot Provisioning change failed.AutopilotNN
407Autopilot Provisioning change failed with unspecified error.AutopilotNN
408Autopilot Provisioning reported a warning occurred.AutopilotNN
409Unexpected error: device preparation page settings are not configured or are …AutopilotNN
410Device preparation page settings were loaded successfully.AutopilotNN
411Unexpected error: a device preparation page setting value could not be …AutopilotNN
412Agent download completed.AutopilotNN
413Agent download notification complete.AutopilotNN
414Agent download notification handler changed.AutopilotNN
415Agent download notification handler changed.AutopilotNN
416Agent download was triggered.AutopilotNN
417A duplicate deployment workload with this id already exists.AutopilotNN
418A duplicate deployment workload batch with this id already exists.AutopilotNN
419Runtime activation of a device preparation class failed due to invalid mode.AutopilotNN
500Invalid data specified in Autopilot policy override configuration.AutopilotNN
501AutopilotManager failed to load Json for HRESULT.ManagementServiceNN
502AutopilotManager failed to clear for HRESULT.ManagementServiceNN
503AutopilotManager failed to delete Json for HRESULT.ManagementServiceNN
504AutopilotManager deleted configuration file Message1.ManagementServiceNN
505AutopilotManager loaded configuration file Message1.ManagementServiceYN
506AutopilotManager failed to expand path for Message1.ManagementServiceNN
507AutopilotManager explictly disabled TPM required due to registry setting.ManagementServiceNN
508AutopilotManager explictly enabled TPM required due to registry setting.ManagementServiceNN
509AutopilotManager enabled TPM requirement due to WhiteGlove policy value UInt1.ManagementServiceNN
700Autopilot downloader failed to load override registsry data for Message1.AutopilotNN
701Autopilot downloader did not save new profile information because the new …AutopilotNN
702Autopilot downloader saved the new profile to Message1.AutopilotYN
703Autopilot downloader retrieved a new profile for Message1.AutopilotNN
704Autopilot downloader retrieved an empty profile for Message1.AutopilotYN
705Autopilot downloader cleared the local profile for Message1.AutopilotYN
706Autopilot downloader failed to download profile for HRESULT.AutopilotNN
707Autopilot downloader failed to download profile for HRESULT.AutopilotNN
708Autopilot downloader failed to extract additional error details from response.AutopilotNN
709Autopilot failed to download data.AutopilotNN
710Autopilot failed to acquire a device ticket for target URL Message1.AutopilotNN
711Autopilot downloader failed to parse target URL.AutopilotNN
712Autopilot downloader failed to convert time Message1.AutopilotNN
713Autopilot downloader will use MSA Pre-production environment.AutopilotNN
714Autopilot downloader reported a failure acquiring the MSA device ticket.AutopilotNN
750Autopilot downloader reported a failure acquiring the MSA device ticket due to …AutopilotNN
751Autopilot downloader reported time sync succeeded.AutopilotNN
752Autopilot downloader reported time sync failed with error = HRESULT.AutopilotNN
753Autopilot downloader reported that the machine clock is too far off the server …AutopilotNN
1000Management service starting.ManagementServiceYN
1001Management service started.ManagementServiceYN
1002Management service failed to start.ManagementServiceNN
1003Management service failed to register.ManagementServiceNN
1004Management service shutdown.ManagementServiceYN
1005Management service WIL error was reported.ManagementServiceNN
1006Management service call Message1 is deprecated!ManagementServiceNN
1007Management service cleared the local Autopilot cached state.ManagementServiceYN
1008Management service failed to clear the local Autopilot cached state.ManagementServiceNN
1009Management InProc Objects WIL error was reported.ManagementServiceNN
1010Autopilot.ManagementServiceNN
1100Management service will use Message1 for persisted storage.ManagementServiceYN
1101Management service did not find Message1.ManagementServiceYN
1102Management service created Message1.ManagementServiceYN
1103Management service found ProcMon.ManagementServiceNN
1104Management service determined ProcMon.ManagementServiceNN
1105Management service determined ProcMon.ManagementServiceNN
1106Management service is beginning ProcMon.ManagementServiceNN
1107Management service is began ProcMon.ManagementServiceNN
1108Management service is stopping ProcMon.ManagementServiceNN
1109Management service has stopped ProcMon.ManagementServiceNN
1500[Unit Tests] This is a test event string.DiagnosticsNN
1501[Unit Tests] This is a test CXH event string.DiagnosticsNN
1502[Unit Tests] This is a test Resource event string.DiagnosticsNN
1503Failed to export logs for ETW channel 'Message1'.DiagnosticsNN
1504ETW decoder failed to read next block of events.DiagnosticsNN
1505Abstraction of exported ETW record failed.DiagnosticsNN
1506An error occurred while extracting the registry value for diagnostic data …DiagnosticsNN
1507Expected channel 'Message1' could not be found in the EtwProcessingData JSON …DiagnosticsNN
1508Expected EtwProcessingData entry corresponding to event 'Message1' could not be …DiagnosticsNN
1509Expected diagnostic data 'Message1' could not be found.DiagnosticsNN
1510CXH event was malformed.DiagnosticsNN
1511Expected required diagnostic data 'Message1' from the extracted data list was …DiagnosticsNN
1512The API executed all actions successfully.DiagnosticsNN
1513The API encountered an error at state 'FailedApiState'.DiagnosticsNN
1514The expected key 'Message1' was not found in the 'Message2' map.DiagnosticsNN
1515The expected diagnostic data 'Message1' was missing.DiagnosticsNN
1516Resource event was malformed.DiagnosticsNN
1517CXH event was missing data.DiagnosticsNN
1518The API is entering the 'Message1' state.DiagnosticsNN
1519The API completed the 'Message1' state successfully.DiagnosticsNN
1520The API successfully retrieved the serialized JSON from the 'Message1' file.DiagnosticsNN
1521The API successfully deserialized the 'Message1' file JSON string.DiagnosticsNN
1522The API successfully aggregated the source data.DiagnosticsNN
1523The 'Message1' concurrent worker has begun.DiagnosticsNN
1524The 'Message1' concurrent worker completed successfully.DiagnosticsNN
1525An exception occurred while processing diagnostic data.DiagnosticsNN
1526Diagnostic extraction failed.DiagnosticsNN
1527The localized string for 'Message1' could not be loaded.DiagnosticsNN
1700MDM Alert sync session: FeatureName: MDM_Alert_sync_session_FeatureName, …AutopilotNN

Event ID 100: Autopilot policy [Message1] not found.

#
Channel
Autopilot
Level
Warning

Message #

Autopilot policy [%1] not found.

Fields #

NameDescription
Message1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-09T18:21:02.188508+00:00",
    "event_record_id": 28,
    "correlation": {},
    "execution": {
      "process_id": 4888,
      "thread_id": 3512
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Message1": "ZtdCorrelationId"
  },
  "message": ""
}

Event ID 101: AutopilotGetPolicyDwordByName succeeded: policy name = Message1; policy value = Int1.

#
Channel
Autopilot

Message #

AutopilotGetPolicyDwordByName succeeded:  policy name = %1; policy value = %2.

Fields #

NameDescription
Message1 UnicodeString
Int1 Int32

Event ID 102: AutopilotGetPolicyDwordByName error: policy name = Message1; HRESULT = HRESULT.

#
Channel
Autopilot

Message #

AutopilotGetPolicyDwordByName error:  policy name = %2; HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 103: AutopilotGetPolicyStringByName succeeded: policy name = Message1; policy value = Message2.

#
Channel
Autopilot

Message #

AutopilotGetPolicyStringByName succeeded:  policy name = %1; policy value = %2.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 104: AutopilotGetPolicyStringByName error: policy name = Message1; HRESULT = HRESULT.

#
Channel
Autopilot

Message #

AutopilotGetPolicyStringByName error:  policy name = %2; HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 105: AutopilotDisable succeeded.

#
Channel
Autopilot

Event ID 106: AutopilotDisable error: HRESULT = HRESULT.

#
Channel
Autopilot

Message #

AutopilotDisable error:  HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 107: Autopilot state = Message1.

#
Channel
Autopilot

Message #

Autopilot state = %1.

Fields #

NameDescription
Message1 UnicodeString

Event ID 108: AutopilotIsDisabled error: HRESULT = HRESULT.

#
Channel
Autopilot

Message #

AutopilotIsDisabled error:  HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 109: AutopilotGetOobeSettingsOverride succeeded: OOBE setting = Message1; state = Message2.

#
Channel
Autopilot

Message #

AutopilotGetOobeSettingsOverride succeeded:  OOBE setting = %1; state = %2.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 110: AutopilotGetOobeSettingsOverride error: OOBE setting = Message1; HRESULT = HRESULT.

#
Channel
Autopilot

Message #

AutopilotGetOobeSettingsOverride error:  OOBE setting = %2; HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 111: AutopilotRetrieveSettings succeeded.

#
Channel
Autopilot

Event ID 112: AutopilotRetrieveSettings error: HRESULT = HRESULT.

#
Channel
Autopilot

Message #

AutopilotRetrieveSettings error:  HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 113: Autopilot reported the DLL was unloaded while there were Int1 outstanding calls.

#
Channel
Autopilot

Message #

Autopilot reported the DLL was unloaded while there were %1 outstanding calls.

Fields #

NameDescription
Int1 Int32

Event ID 114: AutopilotRetrieveSettings was skipped because this version of Windows does not support Azure Active Directory join.

#
Channel
Autopilot

Event ID 115: Autopilot discovery failed to find a valid MDM.

#
Channel
Autopilot

Description

Autopilot discovery failed to find a valid MDM. Confirm that the AAD tenant is properly provisioned and licensed for exactly one MDM. HRESULT = HRESULT.

Message #

Autopilot discovery failed to find a valid MDM.  Confirm that the AAD tenant is properly provisioned and licensed for exactly one MDM.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 116: Autopilot Device ESP Domain Controller override was not set.

#
Channel
Autopilot

Event ID 117: Autopilot Device ESP Domain Controller override was set by state UInt1.

#
Channel
Autopilot

Message #

Autopilot Device ESP Domain Controller override was set by state %1

Fields #

NameDescription
UInt1 UInt32

Event ID 118: Autopilot task to detect hardware change started.

#
Channel
Autopilot

Description

Autopilot task to detect hardware change started. Task argument: Message1.

Message #

Autopilot task to detect hardware change started. Task argument: %1

Fields #

NameDescription
Message1 UnicodeString

Event ID 119: Autopilot task to detect hardware change finished successfully.

#
Channel
Autopilot

Description

Autopilot task to detect hardware change finished successfully. Task argument: Message1.

Message #

Autopilot task to detect hardware change finished successfully. Task argument: %1

Fields #

NameDescription
Message1 UnicodeString

Event ID 120: Autopilot task to detect hardware change failed.

#
Channel
Autopilot

Description

Autopilot task to detect hardware change failed. Result: HRESULT.

Message #

Autopilot task to detect hardware change failed. Result: %1
Task argument: %2

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 121: Autopilot task to detect hardware change finished successfully.

#
Channel
Autopilot

Description

Autopilot task to detect hardware change finished successfully. No change was detected.

Message #

Autopilot task to detect hardware change finished successfully. No change was detected.

Event ID 122: Autopilot task to detect hardware change finished successfully.

#
Channel
Autopilot

Description

Autopilot task to detect hardware change finished successfully. A change was detected and reported.

Message #

Autopilot task to detect hardware change finished successfully. A change was detected and reported.

Event ID 123: Autopilot task to detect hardware change was aborted or cancelled before completion.

#
Channel
Autopilot

Description

Autopilot task to detect hardware change was aborted or cancelled before completion. Task: Message1.

Message #

Autopilot task to detect hardware change was aborted or cancelled before completion. Task: %1

Fields #

NameDescription
Message1 UnicodeString

Event ID 124: Autopilot starting to disable task: Message1.

#
Channel
Autopilot

Message #

Autopilot starting to disable task: %1

Fields #

NameDescription
Message1 UnicodeString

Event ID 125: Autopilot successfully disabled task: Autopilot_successfully_disabled_task.

#
Channel
Autopilot

Message #

Autopilot successfully disabled task: %1

Fields #

NameDescription
Message1 UnicodeString

Event ID 126: Autopilot failed to disable task.

#
Channel
Autopilot

Description

Autopilot failed to disable task. HRESULT: HRESULT.

Message #

Autopilot failed to disable task. HRESULT: %1
Task: %2

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 127: Autopilot starting to enable task: Message1.

#
Channel
Autopilot

Message #

Autopilot starting to enable task: %1

Fields #

NameDescription
Message1 UnicodeString

Event ID 128: Autopilot successfully enabled task: Autopilot_successfully_enabled_task.

#
Channel
Autopilot

Message #

Autopilot successfully enabled task: %1

Fields #

NameDescription
Message1 UnicodeString

Event ID 129: Autopilot failed to enable task.

#
Channel
Autopilot

Description

Autopilot failed to enable task. HRESULT: HRESULT.

Message #

Autopilot failed to enable task. HRESULT: %1
Task: %2

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 130: Autopilot hardware remediation report failed.

#
Channel
Autopilot

Description

Autopilot hardware remediation report failed. HRESULT: HRESULT.

Message #

Autopilot hardware remediation report failed. HRESULT: %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 131: Autopilot hardware remediation must wait before reporting again.

#
Channel
Diagnostics

Description

Autopilot hardware remediation must wait before reporting again. Delay in minutes: Int1.

Message #

Autopilot hardware remediation must wait before reporting again. Delay in minutes: %1

Fields #

NameDescription
Int1 Int32

Event ID 132: Autopilot hardware remediation failed to process response.

#
Channel
Autopilot

Description

Autopilot hardware remediation failed to process response. HRESULT = Stage.

Message #

Autopilot hardware remediation failed to process response. HRESULT = %1
Stage: %2

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 133: Autopilot hardware remediation failed to read cached hardware.

#
Channel
Autopilot

Description

Autopilot hardware remediation failed to read cached hardware. HRESULT = Hardware_location.

Message #

Autopilot hardware remediation failed to read cached hardware. HRESULT = %1
Hardware location: %2

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 134: Autopilot hardware remediation failed to write cached hardware.

#
Channel
Autopilot

Description

Autopilot hardware remediation failed to write cached hardware. HRESULT = Hardware_location.

Message #

Autopilot hardware remediation failed to write cached hardware. HRESULT = %1
Hardware location: %2

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 150: AutopilotManager started the MSA service for TPM attestation identity.

#
Channel
Autopilot

Event ID 151: AutopilotManager started the TPM maintenance task to update TPM attestation.

#
Channel
Autopilot

Event ID 152: AutopilotManager reported TPM maintenance task is complete.

#
Channel
Autopilot

Event ID 153: AutopilotManager reported the state changed from InitialState to UpdateState.

#
Channel
Autopilot
Level
Informational

Message #

AutopilotManager reported the state changed from %1 to %2.

Fields #

NameDescription
InitialState UInt32
UpdateState UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 153,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-09T18:21:06.069716+00:00",
    "event_record_id": 29,
    "correlation": {
      "ActivityID": "C5B1AF6E-270C-4D62-8042-94BEA2A2BA55"
    },
    "execution": {
      "process_id": 4888,
      "thread_id": 9948
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "InitialState": 0,
    "UpdateState": 1
  },
  "message": ""
}

Event ID 154: AutopilotManager failed to start MSA service.

#
Channel
Autopilot

Description

AutopilotManager failed to start MSA service. HRESULT = HRESULT.

Message #

AutopilotManager failed to start MSA service.  HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 155: AutopilotManager failed to start TPM task.

#
Channel
Autopilot

Description

AutopilotManager failed to start TPM task. HRESULT = HRESULT.

Message #

AutopilotManager failed to start TPM task.  HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 156: AutopilotManager reported that MSA TPM is not configured for hardware TPM attestation even though the profile indicates it is required.

#
Channel
Autopilot

Description

AutopilotManager reported that MSA TPM is not configured for hardware TPM attestation even though the profile indicates it is required. Autopilot cannot proceed.

Message #

AutopilotManager reported that MSA TPM is not configured for hardware TPM attestation even though the profile indicates it is required.  Autopilot cannot proceed.

Event ID 157: AutopilotManager reported that TPM attestation lasted UInt1 microseconds.

#
Channel
Autopilot

Message #

AutopilotManager reported that TPM attestation lasted %1 microseconds.

Fields #

NameDescription
UInt1 UInt64

Event ID 158: AutopilotManager reported that TPM enhanced diagnostics logging was enabled for UInt1 providers.

#
Channel
Autopilot

Message #

AutopilotManager reported that TPM enhanced diagnostics logging was enabled for %1 providers.

Fields #

NameDescription
UInt1 UInt32

Event ID 160: AutopilotRetrieveSettings beginning acquisition.

#
Channel
Autopilot

Event ID 161: AutopilotManager retrieve settings succeeded.

#
Channel
Autopilot
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 161,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2025-12-31T19:33:27.264631+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6752
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 162: AutopilotManager determined download is not required and the device is not provisioned.

#
Channel
Autopilot
Level
Informational

Description

AutopilotManager determined download is not required and the device is not provisioned. Clean or reset the device to change this.

Message #

AutopilotManager determined download is not required and the device is not provisioned.  Clean or reset the device to change this.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 162,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2025-12-31T19:33:31.162906+00:00",
    "event_record_id": 14,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6752
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 163: AutopilotManager determined download is not required and the device is already provisioned.

#
Channel
Autopilot

Description

AutopilotManager determined download is not required and the device is already provisioned. Clean or reset the device to change this.

Message #

AutopilotManager determined download is not required and the device is already provisioned.  Clean or reset the device to change this.

Event ID 164: AutopilotManager determined Internet is available to attempt policy download.

#
Channel
Autopilot
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 164,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2025-12-31T19:33:25.048353+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6752
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 165: AutopilotManager determined Internet is not available; policy download will queue when available.

#
Channel
Autopilot

Event ID 166: AutopilotManager reported Internet is now available.

#
Channel
Autopilot
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 166,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2025-12-31T19:33:25.038727+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6752
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 167: AutopilotManager reported Internet is still not available.

#
Channel
Autopilot

Event ID 168: AutopilotManager reported MSA TPM device identity was updated.

#
Channel
Autopilot

Event ID 169: AutopilotManager set TPM identity confirmed.

#
Channel
Autopilot

Event ID 170: AutopilotManager reported that Autopilot profile download is now complete.

#
Channel
Autopilot
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 170,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-09T18:21:06.070120+00:00",
    "event_record_id": 30,
    "correlation": {
      "ActivityID": "C5B1AF6E-270C-4D62-8042-94BEA2A2BA55"
    },
    "execution": {
      "process_id": 4888,
      "thread_id": 9948
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 171: AutopilotManager failed to set TPM identity confirmed.

#
Channel
Autopilot

Description

AutopilotManager failed to set TPM identity confirmed. HRESULT = HRESULT.

Message #

AutopilotManager failed to set TPM identity confirmed.  HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 172: AutopilotManager failed to set Autopilot profile as available.

#
Channel
Autopilot

Description

AutopilotManager failed to set Autopilot profile as available. HRESULT = HRESULT.

Message #

AutopilotManager failed to set Autopilot profile as available.  HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 173: AutopilotManager failed to register for network availability.

#
Channel
Autopilot

Description

AutopilotManager failed to register for network availability. HRESULT = HRESULT.

Message #

AutopilotManager failed to register for network availability.  HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 174: AutopilotManager failed to register for device identity availability.

#
Channel
Autopilot

Description

AutopilotManager failed to register for device identity availability. HRESULT = HRESULT.

Message #

AutopilotManager failed to register for device identity availability.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 175: AutopilotManager failed to register for device identity task update.

#
Channel
Autopilot

Description

AutopilotManager failed to register for device identity task update. HRESULT = HRESULT.

Message #

AutopilotManager failed to register for device identity task update.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 176: MSA TPM keystate has been updated.

#
Channel
Autopilot

Description

MSA TPM keystate has been updated. New server state = ServerState, new client state = ClientState.

Message #

MSA TPM keystate has been updated.  New server state = %1, new client state = %2

Fields #

NameDescription
ServerState UInt32
ClientState UInt32

Event ID 177: Configuring TPM for attestation.

#
Channel
Autopilot

Description

Configuring TPM for attestation. Current attempt Uint1 of Uint2 maximum.

Message #

Configuring TPM for attestation.  Current attempt %1 of %2 maximum.

Fields #

NameDescription
Uint1 UInt32
Uint2 UInt32

Event ID 178: AutopilotManager began device enrollment with internal state Int1.

#
Channel
Autopilot

Message #

AutopilotManager began device enrollment with internal state %1.

Fields #

NameDescription
Int1 Int32

Event ID 179: AutopilotManager began device enrollment phase State.

#
Channel
Autopilot

Message #

AutopilotManager began device enrollment phase %1.

Fields #

NameDescription
State UInt32

Event ID 180: AutopilotManager failed during device enrollment phase State.

#
Channel
Autopilot

Description

AutopilotManager failed during device enrollment phase State. HRESULT = HRESULT.

Message #

AutopilotManager failed during device enrollment phase %1.  HRESULT = %2

Fields #

NameDescription
State UInt32
HRESULT HexInt32

Event ID 181: AutopilotManager completed device enrollment phase State.

#
Channel
Autopilot

Description

AutopilotManager completed device enrollment phase State. HRESULT = HRESULT.

Message #

AutopilotManager completed device enrollment phase %1.  HRESULT = %2

Fields #

NameDescription
State UInt32
HRESULT HexInt32

Event ID 182: AutopilotManager reported that the retry timer event was set to UInt1 milliseconds.

#
Channel
Autopilot

Message #

AutopilotManager reported that the retry timer event was set to %1 milliseconds.

Fields #

NameDescription
UInt1 UInt32

Event ID 183: AutopilotManager reported that the retry timer event occurred

#
Channel
Autopilot

Event ID 184: AutopilotManager failed to register for MSA keystate update availability.

#
Channel
Autopilot

Description

AutopilotManager failed to register for MSA keystate update availability. HRESULT = HRESULT.

Message #

AutopilotManager failed to register for MSA keystate update availability.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 185: AutopilotManager failed to retrieve settings.

#
Channel
Autopilot

Description

AutopilotManager failed to retrieve settings. HRESULT = HRESULT.

Message #

AutopilotManager failed to retrieve settings.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 186: AutopilotManager TPM configuration already in progress.

#
Channel
Autopilot

Event ID 187: AutopilotManager TPM configuration occurred before retry timer ready.

#
Channel
Autopilot

Event ID 189: Configuring TPM exceeded maximum number of attempts.

#
Channel
Autopilot

Event ID 190: Windows AIK certificate enrollment task was triggered.

#
Channel
Autopilot

Event ID 191: Windows TPM maintenance task is being skipped since AIK certificate is already present.

#
Channel
Autopilot

Event ID 192: Autopilot device enrollment failed with error HRESULT = HRESULT.

#
Channel
Autopilot

Description

Autopilot device enrollment failed with error HRESULT = HRESULT. Waiting WaitMs milliseconds then retrying.

Message #

Autopilot device enrollment failed with error HRESULT = %1. Waiting %2 milliseconds then retrying.
Current attempt %3 of %4.

Fields #

NameDescription
HRESULT HexInt32
WaitMs Int32
AttemptNumber Int32
MaxAttempts Int32

Event ID 193: Autopilot manager is attempting profile download retry.

#
Channel
Autopilot

Description

Autopilot manager is attempting profile download retry. Current attempt Uint1 of Uint2.

Message #

Autopilot manager is attempting profile download retry.  Current attempt %1 of %2.

Fields #

NameDescription
Uint1 UInt32
Uint2 UInt32

Event ID 194: Autopilot manager will re-attempt the download after UInt1 milliseconds.

#
Channel
Autopilot

Message #

Autopilot manager will re-attempt the download after %1 milliseconds.

Fields #

NameDescription
UInt1 UInt32

Event ID 195: AutopilotManager began device unenrollment

#
Channel
Autopilot

Event ID 196: AutopilotManager completed device unenrollment.

#
Channel
Autopilot

Description

AutopilotManager completed device unenrollment. HRESULT = HRESULT.

Message #

AutopilotManager completed device unenrollment.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 197: AutopilotManager failed device unenrollment.

#
Channel
Autopilot

Description

AutopilotManager failed device unenrollment. HRESULT = HRESULT.

Message #

AutopilotManager failed device unenrollment.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 200: Windows AIK object could not be loaded.

#
Channel
Autopilot

Description

Windows AIK object could not be loaded. HRESULT = HRESULT.

Message #

Windows AIK object could not be loaded.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 201: Windows AIK key not found by name.

#
Channel
Autopilot

Event ID 202: Windows AIK certificate download failed.

#
Channel
Autopilot

Description

Windows AIK certificate download failed. HRESULT = HRESULT.

Message #

Windows AIK certificate download failed. HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 203: Windows AIK alternative load failed.

#
Channel
Autopilot

Description

Windows AIK alternative load failed. HRESULT = HRESULT.

Message #

Windows AIK alternative load failed. HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 204: Windows AIK certificate request did not result in a new certificate.

#
Channel
Autopilot

Event ID 205: Windows AIK certificate request succeeded and a new certificate is available.

#
Channel
Autopilot

Event ID 206: Windows AIK key could not be opened.

#
Channel
Autopilot

Description

Windows AIK key could not be opened. HRESULT = HRESULT.

Message #

Windows AIK key could not be opened. HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 207: Windows AIK key failed certificate request.

#
Channel
Autopilot

Description

Windows AIK key failed certificate request. HRESULT = HRESULT.

Message #

Windows AIK key failed certificate request. HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 208: Windows EK certificate is present.

#
Channel
Autopilot

Event ID 209: Windows EK certificate is not present.

#
Channel
Autopilot

Event ID 210: Windows AIK key was found even though the Windows EK certificate is not present.

#
Channel
Autopilot

Description

Windows AIK key was found even though the Windows EK certificate is not present. Attempting to re-initialize the TPM task.

Message #

Windows AIK key was found even though the Windows EK certificate is not present. Attempting to re-initialize the TPM task.

Event ID 211: AutopilotManager reported that a TPM was required but the TPM failed an attestation capability check.

#
Channel
Autopilot

Description

AutopilotManager reported that a TPM was required but the TPM failed an attestation capability check. HRESULT = HRESULT.

Message #

AutopilotManager reported that a TPM was required but the TPM failed an attestation capability check.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 212: AutopilotManager reported the TPM returned the following for known vulnerabilities: HRESULT = HRESULT.

#
Channel
Autopilot

Message #

AutopilotManager reported the TPM returned the following for known vulnerabilities: HRESULT = %1
HasVulnerability = %2
VulnerabilityFlags = %3

Fields #

NameDescription
HRESULT HexInt32
VulnerabilityDetected Int32
VulnerabilityFlags UInt64

Event ID 213: AutopilotManager reported the TPM returned the following for Key attestation capability: HRESULT = HRESULT.

#
Channel
Autopilot

Message #

AutopilotManager reported the TPM returned the following for Key attestation capability: HRESULT = %1
Key flags = %2

Fields #

NameDescription
HRESULT HexInt32
int1 Int32

Event ID 250: AutopilotManager started AIK certificate acquisition task.

#
Channel
Autopilot

Event ID 251: AutopilotManager reported AIK certificate acquisition task returned HRESULT = Elapsed_time.

#
Channel
Autopilot

Message #

AutopilotManager reported AIK certificate acquisition task returned HRESULT = %1.
Elapsed time: %2 microseconds (maximum allowed time was %3 milliseconds).

Fields #

NameDescription
HRESULT HexInt32
UInt1 UInt64
Int1 Int32

Event ID 252: AutopilotManager reported AIK key was located.

#
Channel
Autopilot

Event ID 253: AutopilotManager reported AIK certificate was located.

#
Channel
Autopilot

Event ID 254: AutopilotManager reported AIK certificate was not located.

#
Channel
Autopilot

Event ID 285: AutopilotManager is determining whether device has internet access.

#
Channel
Autopilot
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 285,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2025-12-31T19:33:24.908119+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6752
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 286: AutopilotManager is determining Autopilot profile availability.

#
Channel
Autopilot
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 286,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2025-12-31T19:33:31.162893+00:00",
    "event_record_id": 13,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6752
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 287: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. Starting installation of policy provider 'Message2'.

Message #

Tracking resource type %1. Starting installation of policy provider '%2'.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 288: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. Policy provider 'Message2' installation completed successfully.

Message #

Tracking resource type %1. Policy provider '%2' installation completed successfully.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 289: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. Policy provider 'Message2' installation timed out after Int1 minutes.

Message #

Tracking resource type %1. Policy provider '%2' installation timed out after %3 minutes.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
Int1 Int32

Event ID 290: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. An error occured while installing policy provider 'Message2'. Error: HRESULT.

Message #

Tracking resource type %1. An error occured while installing policy provider '%2'. Error: %3

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
HRESULT HexInt32

Event ID 291: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. Installation of policy provider 'Message2' not required.

Message #

Tracking resource type %1. Installation of policy provider '%2' not required.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 292: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. Retrieving tracking list from policy provider 'Message2'.

Message #

Tracking resource type %1. Retrieving tracking list from policy provider '%2'.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 293: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. Policy provider 'Message2' provided a list of Int1 policies to track.

Message #

Tracking resource type %1. Policy provider '%2' provided a list of %3 policies to track.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
Int1 Int32

Event ID 294: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. Policy provider 'Message2' encountered an error and the tracking list could not be completed. Error: HRESULT.

Message #

Tracking resource type %1. Policy provider '%2' encountered an error and the tracking list could not be completed. Error: %3

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
HRESULT HexInt32

Event ID 295: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. Policy provider 'Message2' provided an empty list of policies.

Message #

Tracking resource type %1. Policy provider '%2' provided an empty list of policies.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 296: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. App 'Message2' installation completed successfully.

Message #

Tracking resource type %1. App '%2' installation completed successfully.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 297: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. Starting installation tracking app 'Message2'.

Message #

Tracking resource type %1. Starting installation tracking app '%2'.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 298: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. An error occurred while installing app 'Message2'. HRESULT = HRESULT.

Message #

Tracking resource type %1. An error occurred while installing app '%2'.  HRESULT = %3

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
HRESULT HexInt32

Event ID 299: Tracking resource type Message1.

#
Channel
Autopilot

Description

Tracking resource type Message1. Reboot required to complete installation of app 'Message2'.

Message #

Tracking resource type %1. Reboot required to complete installation of app '%2'.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 300: AutopilotManager device enrollment reported an initialization failure.

#
Channel
Autopilot

Description

AutopilotManager device enrollment reported an initialization failure. HRESULT = HRESULT.

Message #

AutopilotManager device enrollment reported an initialization failure.  HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 301: AutopilotManager device enrollment reported a blocking failure.

#
Channel
Autopilot

Description

AutopilotManager device enrollment reported a blocking failure. Overall error HRESULT, last reported stage State.

Message #

AutopilotManager device enrollment reported a blocking failure.  Overall error %2, last reported stage %1.

Fields #

NameDescription
State UInt32
HRESULT HexInt32

Event ID 302: AutopilotManager device enrollment failed during stage State with error HRESULT.

#
Channel
Autopilot

Message #

AutopilotManager device enrollment failed during stage %1 with error %2.

Fields #

NameDescription
State UInt32
HRESULT HexInt32

Event ID 303: AutopilotManager device enrollment succeeded.

#
Channel
Autopilot

Description

AutopilotManager device enrollment succeeded. Last valid stage: State.

Message #

AutopilotManager device enrollment succeeded.  Last valid stage: %1.

Fields #

NameDescription
State UInt32

Event ID 310: Autopilot configuration file path: Autopilot_configuration_file_path.

#
Channel
Autopilot

Message #

Autopilot configuration file path: %1 
Expanded path:%2

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 311: Failed to load Autopilot configuration file, HRESULT = HRESULT.

#
Channel
Autopilot

Message #

Failed to load Autopilot configuration file, HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 312: Failed to parse Autopilot configuration file, HRESULT = HRESULT.

#
Channel
Autopilot

Message #

Failed to parse Autopilot configuration file, HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 313: Invalid ZtdCorrelationId found in Autopilot configuration file, HRESULT = HRESULT.

#
Channel
Autopilot

Description

Invalid ZtdCorrelationId found in Autopilot configuration file, HRESULT = HRESULT. ZtdCorrelationId: 'Message1'.

Message #

Invalid ZtdCorrelationId found in Autopilot configuration file, HRESULT = %1. ZtdCorrelationId: '%2'.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 314: AutopilotManager reported that the Autopilot profile data could not be downloaded.

#
Channel
Autopilot

Description

AutopilotManager reported that the Autopilot profile data could not be downloaded. Any Autopilot settings will not be used and the device will not be managed.

Message #

AutopilotManager reported that the Autopilot profile data could not be downloaded. Any Autopilot settings will not be used and the device will not be managed.

Event ID 315: AutopilotManager failed to record the setting for Autopilot device not managed, HRESULT = HRESULT.

#
Channel
Autopilot

Message #

AutopilotManager failed to record the setting for Autopilot device not managed, HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 316: AutopilotSync: Starting sync sessions for SyncType: UInt1.

#
Channel
Autopilot

Message #

AutopilotSync: Starting sync sessions for SyncType: %1.

Fields #

NameDescription
UInt1 UInt32

Event ID 317: AutopilotSync: Ending sync sessions for SyncType: UInt1.

#
Channel
Autopilot

Message #

AutopilotSync: Ending sync sessions for SyncType: %1.

Fields #

NameDescription
UInt1 UInt32

Event ID 318: AutopilotSync: Attempted sync session.

#
Channel
Autopilot

Description

AutopilotSync: Attempted sync session. Result: HRESULT, EnrollmentId: Message1, SyncType: Uint1, SyncSessionId: Message2.

Message #

AutopilotSync: Attempted sync session. Result: %1, EnrollmentId: %2, SyncType: %3, SyncSessionId: %4.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString
Uint1 UInt32
Message2 UnicodeString

Event ID 319: AutopilotSync: Skipped sync session.

#
Channel
Autopilot

Description

AutopilotSync: Skipped sync session. Result: HRESULT, EnrollmentId: Message1, SyncType: Uint1, PreviousSessionCompleted: Uint2.

Message #

AutopilotSync: Skipped sync session. Result: %1, EnrollmentId: %2, SyncType: %3, PreviousSessionCompleted: %4.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString
Uint1 UInt32
Uint2 UInt32

Event ID 320: AutopilotSync: Using user SID: AutopilotSync_Using_user_SID.

#
Channel
Autopilot

Message #

AutopilotSync: Using user SID: %1.

Fields #

NameDescription
Message1 UnicodeString

Event ID 321: AutopilotSync: Current sync session.

#
Channel
Autopilot

Description

AutopilotSync: Current sync session. IsCompleted: Uint1, SessionState: Uint2, SyncSessionId: Message1, EnrollmentId: Message2, SyncType: Uint3.

Message #

AutopilotSync: Current sync session. IsCompleted: %1, SessionState: %2, SyncSessionId: %3, EnrollmentId: %4, SyncType: %5.

Fields #

NameDescription
Uint1 UInt32
Uint2 UInt32
Message1 UnicodeString
Message2 UnicodeString
Uint3 UInt32

Event ID 350: Autopilot for Surface Hub encountered bad override data.

#
Channel
Diagnostics

Description

Autopilot for Surface Hub encountered bad override data. HRESULT = HRESULT.

Message #

Autopilot for Surface Hub encountered bad override data. HRESULT = %1
Policy name=%2

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 351: Autopilot for Surface Hub override succeeded.

#
Channel
Diagnostics

Fields #

NameDescription
Message1 UnicodeString

Event ID 352: Autopilot for Surface Hub failed to configure properties.

#
Channel
Diagnostics

Description

Autopilot for Surface Hub failed to configure properties. HRESULT = HRESULT.

Message #

Autopilot for Surface Hub failed to configure properties. HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 353: Autopilot for Surface Hub failed to apply properties.

#
Channel
Diagnostics

Description

Autopilot for Surface Hub failed to apply properties. HRESULT = HRESULT.

Message #

Autopilot for Surface Hub failed to apply properties. HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 354: Autopilot for Surface Hub applied properties successfully

#
Channel
Diagnostics

Event ID 355: Autopilot for Surface Hub failed to validate a property.

#
Channel
Diagnostics

Message #

Autopilot for Surface Hub failed to validate a property. 
HRESULT = %1
Property name:%2

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 356: Autopilot for Surface Hub failed to execute the Csp successfully.

#
Channel
Diagnostics

Description

Autopilot for Surface Hub failed to execute the Csp successfully. HRESULT = HRESULT.

Message #

Autopilot for Surface Hub failed to execute the Csp successfully. HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 357: Autopilot for Surface Hub validated and applied properties successfully

#
Channel
Diagnostics

Event ID 358: Autopilot for Surface Hub failed to apply the device account successfully.

#
Channel
Diagnostics

Description

Autopilot for Surface Hub failed to apply the device account successfully.HRESULT = {HRESULT}Phase = {Message1}.

Message #

Autopilot for Surface Hub failed to apply the device account successfully.HRESULT = {HRESULT}Phase = {Message1}

Fields #

NameDescription
HRESULT
Message1

Event ID 400: Autopilot Initial Provisioning reported a change in connection status.

#
Channel
Autopilot

Message #

Autopilot Initial Provisioning reported a change in connection status.
Change type: %1
Host result: %2
Agent result: %3
Overall result: %4

Fields #

NameDescription
ChangeType UInt32
DisplayPageResult HexInt32
AgentResult HexInt32
OverallResult HexInt32

Event ID 401: Autopilot Initial Provisioning heartbeat occurred.

#
Channel
Autopilot

Message #

Autopilot Initial Provisioning heartbeat occurred.
Host result: %1
Agent result: %2
Overall result: %3
Host failure count: %4
Agent failure count: %5

Fields #

NameDescription
DisplayPageResult HexInt32
AgentResult HexInt32
OverallResult HexInt32
ConsecutiveHostFailures UInt32
ConsecutiveAgentFailures UInt32

Event ID 402: Autopilot Initial Provisioning detected a network state change.

#
Channel
Autopilot

Description

Autopilot Initial Provisioning detected a network state change. New value: Int1.

Message #

Autopilot Initial Provisioning detected a network state change. New value: %1

Fields #

NameDescription
Int1 Int32

Event ID 403: Autopilot Provisioning change.

#
Channel
Autopilot

Description

Autopilot Provisioning change. Session Id: Autopilot_Provisioning_change_Session_Id, sequence number: sequence_number.

Message #

Autopilot Provisioning change. Session Id: %1, sequence number: %4.
Source:%2Details: %3

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
Message3 UnicodeString
Int1 Int32

Event ID 404: Autopilot Provisioning change started.

#
Channel
Autopilot

Description

Autopilot Provisioning change started. Session Id: Message1, Context Id: Message2, sequence number: Int1.

Message #

Autopilot Provisioning change started. Session Id: %1, Context Id: %2, sequence number: %4.
Source:%3

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
Message3 UnicodeString
Int1 Int32

Event ID 405: Autopilot Provisioning change succeeded.

#
Channel
Autopilot

Description

Autopilot Provisioning change succeeded. Session Id: Message1, Context Id: Message2, sequence number: Int1.

Message #

Autopilot Provisioning change succeeded. Session Id: %1, Context Id: %2, sequence number: %5.
Source:%3
Additional Details: %4
Result: %6

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
Message3 UnicodeString
Message4 UnicodeString
Int1 Int32
HRESULT HexInt32

Event ID 406: Autopilot Provisioning change failed.

#
Channel
Autopilot

Description

Autopilot Provisioning change failed. Session Id: Message1, Context Id: Message2, sequence number: Int1.

Message #

Autopilot Provisioning change failed. Session Id: %1, Context Id: %2, sequence number: %5.
Source:%3Additional Details: %4
Result: %6

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
Message3 UnicodeString
Message4 UnicodeString
Int1 Int32
HRESULT HexInt32

Event ID 407: Autopilot Provisioning change failed with unspecified error.

#
Channel
Autopilot

Description

Autopilot Provisioning change failed with unspecified error. Session Id: Message1, Context Id: Message2, sequence number: Int1.

Message #

Autopilot Provisioning change failed with unspecified error. Session Id: %1, Context Id: %2, sequence number: %5.
Source:%3
Additional Details: %4
Result: %6

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
Message3 UnicodeString
Message4 UnicodeString
Int1 Int32
HRESULT HexInt32

Event ID 408: Autopilot Provisioning reported a warning occurred.

#
Channel
Autopilot

Description

Autopilot Provisioning reported a warning occurred. Session Id: Message1, Context Id: Message2, sequence number: Int1.

Message #

Autopilot Provisioning reported a warning occurred. Session Id: %1, Context Id: %2, sequence number: %5.
Source:%3
Additional Details: %4
Result: %6

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString
Message3 UnicodeString
Message4 UnicodeString
Int1 Int32
HRESULT HexInt32

Event ID 409: Unexpected error: device preparation page settings are not configured or are invalid.

#
Channel
Autopilot

Description

Unexpected error: device preparation page settings are not configured or are invalid. Default values will be used. Result: HRESULT.

Message #

Unexpected error: device preparation page settings are not configured or are invalid. Default values will be used. Result: %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 410: Device preparation page settings were loaded successfully.

#
Channel
Autopilot

Event ID 411: Unexpected error: a device preparation page setting value could not be loaded/converted.

#
Channel
Autopilot

Description

Unexpected error: a device preparation page setting value could not be loaded/converted. Setting name: Message1, result: HRESULT.

Message #

Unexpected error: a device preparation page setting value could not be loaded/converted. Setting name: %2, result: %1

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 412: Agent download completed.

#
Channel
Autopilot

Description

Agent download completed. Notification state: Int1.

Message #

Agent download completed. Notification state: %1

Fields #

NameDescription
Int1 Int32

Event ID 413: Agent download notification complete.

#
Channel
Autopilot

Description

Agent download notification complete. HRESULT = HRESULT.

Message #

Agent download notification complete. HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 414: Agent download notification handler changed.

#
Channel
Autopilot

Description

Agent download notification handler changed. Callback was added.

Message #

Agent download notification handler changed. Callback was added.

Event ID 415: Agent download notification handler changed.

#
Channel
Autopilot

Description

Agent download notification handler changed. Callback was removed.

Message #

Agent download notification handler changed. Callback was removed.

Event ID 416: Agent download was triggered.

#
Channel
Autopilot

Event ID 417: A duplicate deployment workload with this id already exists.

#
Channel
Autopilot

Description

A duplicate deployment workload with this id already exists. This may indicate bad logic. Id: Message1, current count: Uint1.

Message #

A duplicate deployment workload with this id already exists. This may indicate bad logic. Id: %1, current count: %2

Fields #

NameDescription
Message1 UnicodeString
Uint1 UInt32

Event ID 418: A duplicate deployment workload batch with this id already exists.

#
Channel
Autopilot

Description

A duplicate deployment workload batch with this id already exists. This may indicate bad logic. Id: Uint1, current count: Uint2.

Message #

A duplicate deployment workload batch with this id already exists. This may indicate bad logic. Id: %1, current count: %2

Fields #

NameDescription
Uint1 UInt32
Uint2 UInt32

Event ID 419: Runtime activation of a device preparation class failed due to invalid mode.

#
Channel
Autopilot

Description

Runtime activation of a device preparation class failed due to invalid mode. Device must be in OOBE and under DPP provisioning to succeed. HRESULT = HRESULT.

Message #

Runtime activation of a device preparation class failed due to invalid mode. Device must be in OOBE and under DPP provisioning to succeed. HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 500: Invalid data specified in Autopilot policy override configuration.

#
Channel
Autopilot

Message #

Invalid data specified in Autopilot policy override configuration.
HRESULT = %1
Policy name: %2.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 501: AutopilotManager failed to load Json for HRESULT.

#
Channel
ManagementService

Message #

AutopilotManager failed to load Json for %2.
HRESULT = %1
Path: %3.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString
Message2 UnicodeString

Event ID 502: AutopilotManager failed to clear for HRESULT.

#
Channel
ManagementService

Message #

AutopilotManager failed to clear for %2.
HRESULT = %1
Path: %3.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString
Message2 UnicodeString

Event ID 503: AutopilotManager failed to delete Json for HRESULT.

#
Channel
ManagementService

Message #

AutopilotManager failed to delete Json for %2.
HRESULT = %1
Path: %3.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString
Message2 UnicodeString

Event ID 504: AutopilotManager deleted configuration file Message1.

#
Channel
ManagementService

Message #

AutopilotManager deleted configuration file %1.

Fields #

NameDescription
Message1 UnicodeString

Event ID 505: AutopilotManager loaded configuration file Message1.

#
Channel
ManagementService
Level
Informational

Message #

AutopilotManager loaded configuration file %1.

Fields #

NameDescription
Message1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 505,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-09T18:21:02.141371+00:00",
    "event_record_id": 17,
    "correlation": {
      "ActivityID": "78324F2B-4F77-4BDB-AD31-1593143E4213"
    },
    "execution": {
      "process_id": 4888,
      "thread_id": 9948
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Message1": "AutopilotDDSZTDFile.json"
  },
  "message": ""
}

Event ID 506: AutopilotManager failed to expand path for Message1.

#
Channel
ManagementService

Message #

AutopilotManager failed to expand path for %2.
HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 507: AutopilotManager explictly disabled TPM required due to registry setting.

#
Channel
ManagementService

Event ID 508: AutopilotManager explictly enabled TPM required due to registry setting.

#
Channel
ManagementService

Event ID 509: AutopilotManager enabled TPM requirement due to WhiteGlove policy value UInt1.

#
Channel
ManagementService

Message #

AutopilotManager enabled TPM requirement due to WhiteGlove policy value %1

Fields #

NameDescription
UInt1 UInt32

Event ID 700: Autopilot downloader failed to load override registsry data for Message1.

#
Channel
Autopilot

Message #

Autopilot downloader failed to load override registsry data for %2.
HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 701: Autopilot downloader did not save new profile information because the new profile was empty.

#
Channel
Autopilot

Event ID 702: Autopilot downloader saved the new profile to Message1.

#
Channel
Autopilot
Level
Informational

Message #

Autopilot downloader saved the new profile to %1.

Fields #

NameDescription
Message1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 702,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2025-12-31T19:33:27.256412+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6520
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Message1": "C:\\Windows\\ServiceState\\wmansvc\\AutopilotDDSZTDFile.json"
  },
  "message": ""
}

Event ID 703: Autopilot downloader retrieved a new profile for Message1.

#
Channel
Autopilot

Message #

Autopilot downloader retrieved a new profile for %1.

Fields #

NameDescription
Message1 UnicodeString

Event ID 704: Autopilot downloader retrieved an empty profile for Message1.

#
Channel
Autopilot
Level
Informational

Message #

Autopilot downloader retrieved an empty profile for %1.

Fields #

NameDescription
Message1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 704,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2025-12-31T19:33:27.255925+00:00",
    "event_record_id": 6,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6520
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Message1": "DdsZtdPolicyManager"
  },
  "message": ""
}

Event ID 705: Autopilot downloader cleared the local profile for Message1.

#
Channel
Autopilot
Level
Informational

Message #

Autopilot downloader cleared the local profile for %1.

Fields #

NameDescription
Message1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 705,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2025-12-31T19:33:24.392812+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6752
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Message1": "DdsZtdPolicyManager"
  },
  "message": ""
}

Event ID 706: Autopilot downloader failed to download profile for HRESULT.

#
Channel
Autopilot

Message #

Autopilot downloader failed to download profile for %2.
HRESULT = %1.
Correlation vector: %3

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString
Message2 UnicodeString

Event ID 707: Autopilot downloader failed to download profile for HRESULT.

#
Channel
Autopilot

Message #

Autopilot downloader failed to download profile for %2.
HRESULT = %1.
Correlation vector: %3

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString
Message2 UnicodeString

Event ID 708: Autopilot downloader failed to extract additional error details from response.

#
Channel
Autopilot

Description

Autopilot downloader failed to extract additional error details from response. Response data: Message1.

Message #

Autopilot downloader failed to extract additional error details from response. Response data: %2.
Extraction failure HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 709: Autopilot failed to download data.

#
Channel
Autopilot

Description

Autopilot failed to download data. Response code: HRESULT.

Message #

Autopilot failed to download data.  Response code: %1
Detail message:
%2

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 710: Autopilot failed to acquire a device ticket for target URL Message1.

#
Channel
Autopilot

Message #

Autopilot failed to acquire a device ticket for target URL %2.
HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 711: Autopilot downloader failed to parse target URL.

#
Channel
Autopilot

Message #

Autopilot downloader failed to parse target URL:
%1

Fields #

NameDescription
Message1 UnicodeString

Event ID 712: Autopilot downloader failed to convert time Message1.

#
Channel
Autopilot

Message #

Autopilot downloader failed to convert time %2
HRESULT = %1.

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 713: Autopilot downloader will use MSA Pre-production environment.

#
Channel
Autopilot

Description

Autopilot downloader will use MSA Pre-production environment. This will result in Autopilot failures if production device identities were used.

Message #

Autopilot downloader will use MSA Pre-production environment. This will result in Autopilot failures if production device identities were used.

Event ID 714: Autopilot downloader reported a failure acquiring the MSA device ticket.

#
Channel
Autopilot

Description

Autopilot downloader reported a failure acquiring the MSA device ticket. This most likely occurred because MSA and CXH environments do not match (production versus PPE).

Message #

Autopilot downloader reported a failure acquiring the MSA device ticket. This most likely occurred because MSA and CXH environments do not match (production versus PPE).

Event ID 750: Autopilot downloader reported a failure acquiring the MSA device ticket due to certificate errors.

#
Channel
Autopilot

Description

Autopilot downloader reported a failure acquiring the MSA device ticket due to certificate errors. This may be caused by the wrong clock time on the machine so a forced time sync will be attempted.

Message #

Autopilot downloader reported a failure acquiring the MSA device ticket due to certificate errors. This may be caused by the wrong clock time on the machine so a forced time sync will be attempted.

Event ID 751: Autopilot downloader reported time sync succeeded.

#
Channel
Autopilot

Event ID 752: Autopilot downloader reported time sync failed with error = HRESULT.

#
Channel
Autopilot

Message #

Autopilot downloader reported time sync failed with error = %1.

Fields #

NameDescription
HRESULT HexInt32

Event ID 753: Autopilot downloader reported that the machine clock is too far off the server time and a forced time sync will be attempted.

#
Channel
Autopilot

Message #

Autopilot downloader reported that the machine clock is too far off the server time and a forced time sync will be attempted.
Server time: %1
Client time: %2
Sync attempt %3 of %4

Fields #

NameDescription
ServerTime UnicodeString
ClientTime UnicodeString
AttemptNumber Int32
MaxAttempts Int32

Event ID 1000: Management service starting.

#
Channel
ManagementService
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 1000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-09T18:21:01.066409+00:00",
    "event_record_id": 14,
    "correlation": {},
    "execution": {
      "process_id": 4888,
      "thread_id": 4516
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1001: Management service started.

#
Channel
ManagementService
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 1001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-09T18:21:02.125001+00:00",
    "event_record_id": 16,
    "correlation": {},
    "execution": {
      "process_id": 4888,
      "thread_id": 4516
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1002: Management service failed to start.

#
Channel
ManagementService

Description

Management service failed to start. HRESULT = HRESULT.

Message #

Management service failed to start.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 1003: Management service failed to register.

#
Channel
ManagementService

Event ID 1004: Management service shutdown.

#
Channel
ManagementService
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 1004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-09T18:21:21.532518+00:00",
    "event_record_id": 18,
    "correlation": {},
    "execution": {
      "process_id": 4888,
      "thread_id": 4516
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1005: Management service WIL error was reported.

#
Channel
ManagementService

Message #

Management service WIL error was reported.
HRESULT: %1
File: %2, line %3
Message: %4

Fields #

NameDescription
HRESULT HexInt32
File AnsiString
Line Int32
Message UnicodeString

Event ID 1006: Management service call Message1 is deprecated!

#
Channel
ManagementService

Message #

Management service call %1 is deprecated!

Fields #

NameDescription
Message1 UnicodeString

Event ID 1007: Management service cleared the local Autopilot cached state.

#
Channel
ManagementService
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 1007,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2025-12-31T19:33:24.564324+00:00",
    "event_record_id": 6,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6752
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1008: Management service failed to clear the local Autopilot cached state.

#
Channel
ManagementService

Description

Management service failed to clear the local Autopilot cached state. HRESULT = HRESULT.

Message #

Management service failed to clear the local Autopilot cached state.  HRESULT = %1

Fields #

NameDescription
HRESULT HexInt32

Event ID 1009: Management InProc Objects WIL error was reported.

#
Channel
ManagementService

Message #

Management InProc Objects WIL error was reported.
HRESULT: %1
File: %2, line %3
Message: %4

Fields #

NameDescription
HRESULT HexInt32
File AnsiString
Line Int32
Message UnicodeString

Event ID 1010: Autopilot.

#
Channel
ManagementService

Description

Autopilot.dll WIL error was reported.

Message #

Autopilot.dll WIL error was reported.
HRESULT: %1
File: %2, line %3
Message: %4

Fields #

NameDescription
HRESULT HexInt32
File AnsiString
Line Int32
Message UnicodeString

Event ID 1100: Management service will use Message1 for persisted storage.

#
Channel
ManagementService
Level
Informational

Message #

Management service will use %1 for persisted storage

Fields #

NameDescription
Message1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 1100,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-09T18:21:01.074751+00:00",
    "event_record_id": 15,
    "correlation": {},
    "execution": {
      "process_id": 4888,
      "thread_id": 4516
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Message1": "C:\\Windows\\ServiceState\\wmansvc"
  },
  "message": ""
}

Event ID 1101: Management service did not find Message1.

#
Channel
ManagementService
Level
Informational

Description

Management service did not find Message1. Attempting to create it.

Message #

Management service did not find %1.  Attempting to create it.

Fields #

NameDescription
Message1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 1101,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2025-12-31T19:33:20.250928+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6792
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Message1": "C:\\Windows\\ServiceState\\wmansvc"
  },
  "message": ""
}

Event ID 1102: Management service created Message1.

#
Channel
ManagementService
Level
Informational

Message #

Management service created %1.

Fields #

NameDescription
Message1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider",
    "guid": "BAB3AD92-FB96-5902-450B-B8421BDEC7BD",
    "event_source_name": "",
    "event_id": 1102,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2025-12-31T19:33:20.251448+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 6772,
      "thread_id": 6792
    },
    "channel": "Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Message1": "C:\\Windows\\ServiceState\\wmansvc"
  },
  "message": ""
}

Event ID 1103: Management service found ProcMon.

#
Channel
ManagementService

Description

Management service found ProcMon.exe for startup profiling.

Message #

Management service found ProcMon.exe for startup profiling.

Event ID 1104: Management service determined ProcMon.

#
Channel
ManagementService

Description

Management service determined ProcMon.exe startup profiling is not enabled in the registry.

Message #

Management service determined ProcMon.exe startup profiling is not enabled in the registry.

Event ID 1105: Management service determined ProcMon.

#
Channel
ManagementService

Description

Management service determined ProcMon.exe startup profiling is enabled in the registry.

Message #

Management service determined ProcMon.exe startup profiling is enabled in the registry.

Event ID 1106: Management service is beginning ProcMon.

#
Channel
ManagementService

Description

Management service is beginning ProcMon.exe startup profiling.

Message #

Management service is beginning ProcMon.exe startup profiling.

Event ID 1107: Management service is began ProcMon.

#
Channel
ManagementService

Description

Management service is began ProcMon.exe startup profiling.

Message #

Management service is began ProcMon.exe startup profiling.

Event ID 1108: Management service is stopping ProcMon.

#
Channel
ManagementService

Description

Management service is stopping ProcMon.exe startup profiling.

Message #

Management service is stopping ProcMon.exe startup profiling.

Event ID 1109: Management service has stopped ProcMon.

#
Channel
ManagementService

Description

Management service has stopped ProcMon.exe startup profiling.

Message #

Management service has stopped ProcMon.exe startup profiling.

Event ID 1500: [Unit Tests] This is a test event string.

#
Channel
Diagnostics

Event ID 1501: [Unit Tests] This is a test CXH event string.

#
Channel
Diagnostics

Event ID 1502: [Unit Tests] This is a test Resource event string.

#
Channel
Diagnostics

Event ID 1503: Failed to export logs for ETW channel 'Message1'.

#
Channel
Diagnostics

Description

Failed to export logs for ETW channel 'Message1'. [Error Code: HRESULT].

Message #

Failed to export logs for ETW channel '%2'. [Error Code: %1]

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 1504: ETW decoder failed to read next block of events.

#
Channel
Diagnostics

Event ID 1505: Abstraction of exported ETW record failed.

#
Channel
Diagnostics

Event ID 1506: An error occurred while extracting the registry value for diagnostic data 'Message1'.

#
Channel
Diagnostics

Description

An error occurred while extracting the registry value for diagnostic data 'Message1'. [Error Code: HRESULT].

Message #

An error occurred while extracting the registry value for diagnostic data '%2'. [Error Code: %1]

Fields #

NameDescription
HRESULT HexInt32
Message1 UnicodeString

Event ID 1507: Expected channel 'Message1' could not be found in the EtwProcessingData JSON object.

#
Channel
Diagnostics

Message #

Expected channel '%1' could not be found in the EtwProcessingData JSON object.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1508: Expected EtwProcessingData entry corresponding to event 'Message1' could not be found.

#
Channel
Diagnostics

Message #

Expected EtwProcessingData entry corresponding to event '%1' could not be found.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1509: Expected diagnostic data 'Message1' could not be found.

#
Channel
Diagnostics

Message #

Expected diagnostic data '%1' could not be found.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1510: CXH event was malformed.

#
Channel
Diagnostics

Description

CXH event was malformed. [Name: 'Message1'].

Message #

CXH event was malformed. [Name: '%1']

Fields #

NameDescription
Message1 UnicodeString

Event ID 1511: Expected required diagnostic data 'Message1' from the extracted data list was missing some expected data.

#
Channel
Diagnostics

Message #

Expected required diagnostic data '%1' from the extracted data list was missing some expected data.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1512: The API executed all actions successfully.

#
Channel
Diagnostics

Event ID 1513: The API encountered an error at state 'FailedApiState'.

#
Channel
Diagnostics

Description

The API encountered an error at state 'FailedApiState'. [Error Code: HRESULT].

Message #

The API encountered an error at state '%3'. [Error Code: %1]

Fields #

NameDescription
HRESULT HexInt32
ErrorMessage UnicodeString
FailedApiState UnicodeString
Trace UnicodeString

Event ID 1514: The expected key 'Message1' was not found in the 'Message2' map.

#
Channel
Diagnostics

Message #

The expected key '%1' was not found in the '%2' map.

Fields #

NameDescription
Message1 UnicodeString
Message2 UnicodeString

Event ID 1515: The expected diagnostic data 'Message1' was missing.

#
Channel
Diagnostics

Message #

The expected diagnostic data '%1' was missing.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1516: Resource event was malformed.

#
Channel
Diagnostics

Description

Resource event was malformed. [Event ID: Int1, Channel: 'Message1'].

Message #

Resource event was malformed. [Event ID: %1, Channel: '%2']

Fields #

NameDescription
Int1 Int32
Message1 UnicodeString

Event ID 1517: CXH event was missing data.

#
Channel
Diagnostics

Description

CXH event was missing data. [Event ID: Int1, Channel: 'Message1'].

Message #

CXH event was missing data. [Event ID: %1, Channel: '%2']

Fields #

NameDescription
Int1 Int32
Message1 UnicodeString

Event ID 1518: The API is entering the 'Message1' state.

#
Channel
Diagnostics

Message #

The API is entering the '%1' state.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1519: The API completed the 'Message1' state successfully.

#
Channel
Diagnostics

Message #

The API completed the '%1' state successfully.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1520: The API successfully retrieved the serialized JSON from the 'Message1' file.

#
Channel
Diagnostics

Message #

The API successfully retrieved the serialized JSON from the '%1' file.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1521: The API successfully deserialized the 'Message1' file JSON string.

#
Channel
Diagnostics

Message #

The API successfully deserialized the '%1' file JSON string.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1522: The API successfully aggregated the source data.

#
Channel
Diagnostics

Event ID 1523: The 'Message1' concurrent worker has begun.

#
Channel
Diagnostics

Message #

The '%1' concurrent worker has begun.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1524: The 'Message1' concurrent worker completed successfully.

#
Channel
Diagnostics

Message #

The '%1' concurrent worker completed successfully.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1525: An exception occurred while processing diagnostic data.

#
Channel
Diagnostics

Description

An exception occurred while processing diagnostic data. Error code: Int1.

Message #

An exception occurred while processing diagnostic data. Error code: %1
Trace:%2

Fields #

NameDescription
Int1 Int32
Message1 UnicodeString

Event ID 1526: Diagnostic extraction failed.

#
Channel
Diagnostics

Description

Diagnostic extraction failed. Error: Diagnostic_extraction_failed_Error, State: State.

Message #

Diagnostic extraction failed. Error: %1, State: %2

Fields #

NameDescription
Uint1 UInt32
Uint2 UInt32

Event ID 1527: The localized string for 'Message1' could not be loaded.

#
Channel
Diagnostics

Message #

The localized string for '%1' could not be loaded.

Fields #

NameDescription
Message1 UnicodeString

Event ID 1700: MDM Alert sync session: FeatureName: MDM_Alert_sync_session_FeatureName, IsCompleted: IsCompleted, SessionState: SessionState, SyncSessionId: SyncSessionId, EnrollmentId: EnrollmentId.

#
Channel
Autopilot

Message #

MDM Alert sync session: FeatureName: %1, IsCompleted: %2, SessionState: %3, SyncSessionId: %4, EnrollmentId: %5.

Fields #

NameDescription
Message1 UnicodeString
Uint1 UInt32
Uint2 UInt32
Message2 UnicodeString
Message3 UnicodeString

Provenance

ETW provider GUID bab3ad92-fb96-5902-450b-b8421bdec7bd

Defined in autopilotdiag.dll, which carries the event manifest.

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB