Microsoft-Windows-Privacy-Auditing-CPSS

12 events across 1 channel

Event ID 1000: The System Setting {(Area) (SubArea) (ID)} owned by Component was changed from OldSettingValue to NewSettingValue by ProcessName.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Level
Informational
Task
ValueChanged

Description

The System Setting {(Area) (SubArea) (ID)} owned by Component was changed from OldSettingValue to NewSettingValue by ProcessName. Justification: Justification.

Message #

The System Setting {(%9) (%10) (%11)} owned by %8 was changed from %4 to %5 by %2. Justification: %12.

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
OldSettingValue UnicodeString
NewSettingValue UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Justification UnicodeString2. Justification.
TestCode Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Privacy-Auditing-CPSS",
    "guid": "15F4CD44-CA53-5422-DB17-4E76821B5A69",
    "event_source_name": "",
    "event_id": 1000,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 0,
    "keywords": 9223372036854775809,
    "time_created": "2023-10-26T04:17:21.725904+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 2748,
      "thread_id": 2976
    },
    "channel": "Microsoft-Windows-Privacy-Auditing/Operational",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ProcessUserSid": "S-1-5-18",
    "ProcessName": "svchost.exe",
    "ProcessAppPackageFullName": "",
    "OldSettingValue": "NULL",
    "NewSettingValue": "false",
    "TargetUserSid": "",
    "HResult": "0x0",
    "Component": "TailoredExperiencesWithDiagnosticDataEnabled",
    "Area": "Area",
    "SubArea": "SubArea",
    "ID": "ID",
    "Justification": "Projection overrode CPSS value",
    "TestCode": false
  },
  "message": ""
}

References #

Event ID 1001: ProcessName failed to change the System Setting {(Area) (SubArea) (ID)} owned by Component.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Task
ValueChanged

Description

ProcessName failed to change the System Setting {(Area) (SubArea) (ID)} owned by Component. Justification: Justification.

Message #

%2 failed to change the System Setting {(%9) (%10) (%11)} owned by %8. Justification: %12.

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
OldSettingValue UnicodeString
NewSettingValue UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Justification UnicodeString
TestCode Boolean

Event ID 1002: The User Setting {(Area) (SubArea) (ID)} for user TargetUserSid owned by Component was changed from OldSettingValue to NewSettingValue by ProcessName.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Level
Informational
Task
ValueChanged

Description

The User Setting {(Area) (SubArea) (ID)} for user TargetUserSid owned by Component was changed from OldSettingValue to NewSettingValue by ProcessName. Justification: Justification.

Message #

The User Setting {(%9) (%10) (%11)} for user %6 owned by %8 was changed from %4 to %5 by %2. Justification: %12.

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
OldSettingValue UnicodeString
NewSettingValue UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Justification UnicodeString2. Justification.
TestCode Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Privacy-Auditing-CPSS",
    "guid": "15F4CD44-CA53-5422-DB17-4E76821B5A69",
    "event_source_name": "",
    "event_id": 1002,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 0,
    "keywords": 9223372036854775810,
    "time_created": "2023-11-05T22:28:55.211293+00:00",
    "event_record_id": 98,
    "correlation": {},
    "execution": {
      "process_id": 2748,
      "thread_id": 2616
    },
    "channel": "Microsoft-Windows-Privacy-Auditing/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ProcessUserSid": "S-1-5-18",
    "ProcessName": "svchost.exe",
    "ProcessAppPackageFullName": "",
    "OldSettingValue": "NULL",
    "NewSettingValue": "2",
    "TargetUserSid": "S-1-5-21-1992711665-1655669231-58201500-1000",
    "HResult": "0x0",
    "Component": "TailoredExperiencesWithDiagnosticDataEnabled",
    "Area": "Area",
    "SubArea": "SubArea",
    "ID": "ID",
    "Justification": "Projection overrode CPSS value",
    "TestCode": false
  },
  "message": ""
}

References #

Event ID 1003: ProcessName failed to change the User Setting {(Area) (SubArea) (ID)} for user TargetUserSid owned by Component.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Task
ValueChanged

Description

ProcessName failed to change the User Setting {(Area) (SubArea) (ID)} for user TargetUserSid owned by Component. Justification: Justification.

Message #

%2 failed to change the User Setting {(%9) (%10) (%11)} for user %6 owned by %8. Justification: %12.

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
OldSettingValue UnicodeString
NewSettingValue UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Justification UnicodeString
TestCode Boolean

Event ID 1004: The System Setting {(Area) (SubArea) (ID)} owned by Component was successfully created as NewSettingValue by ProcessName.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Task
DefaultSettingCreated

Description

The System Setting {(Area) (SubArea) (ID)} owned by Component was successfully created as NewSettingValue by ProcessName. Source: Source.

Message #

The System Setting {(%8) (%9) (%10)} owned by %7 was successfully created as %4 by %2. Source: %11

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
NewSettingValue UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Source UnicodeString

Event ID 1005: ProcessName failed to create the System Setting {(Area) (SubArea) (ID)} owned by Component.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Task
DefaultSettingCreated

Description

ProcessName failed to create the System Setting {(Area) (SubArea) (ID)} owned by Component. Source: Source.

Message #

%2 failed to create the System Setting {(%8) (%9) (%10)} owned by %7. Source: %11

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
NewSettingValue UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Source UnicodeString

Event ID 1006: The User Setting {(Area) (SubArea) (ID)} owned by Component for user TargetUserSid was successfully created as NewSettingValue by ProcessName.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Task
DefaultSettingCreated

Description

The User Setting {(Area) (SubArea) (ID)} owned by Component for user TargetUserSid was successfully created as NewSettingValue by ProcessName. Source: Source.

Message #

The User Setting {(%8) (%9) (%10)} owned by %7 for user %5 was successfully created as %4 by %2. Source: %11

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
NewSettingValue UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Source UnicodeString

Event ID 1007: ProcessName failed to create the User Setting {(Area) (SubArea) (ID)} owned by Component for user TargetUserSid.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Task
DefaultSettingCreated

Description

ProcessName failed to create the User Setting {(Area) (SubArea) (ID)} owned by Component for user TargetUserSid. Source: Source.

Message #

%2 failed to create the User Setting {(%8) (%9) (%10)} owned by %7 for user %5. Source: %11

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
NewSettingValue UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Source UnicodeString

Event ID 1008: The User Setting {(Area) (SubArea) (ID)} owned by Component for user HResult was successfully removed by ProcessName.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Task
ValueRemoved

Description

The User Setting {(Area) (SubArea) (ID)} owned by Component for user HResult was successfully removed by ProcessName. Justification: TestCode.

Message #

The User Setting {(%7) (%8) (%9)} owned by %6 for user %5 was successfully removed by %2. Justification: %11

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Justification UnicodeString
TestCode Boolean

Event ID 1009: ProcessName failed to remove the User Setting {(Area) (SubArea) (ID)} owned by Component for user HResult.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Task
ValueRemoved

Description

ProcessName failed to remove the User Setting {(Area) (SubArea) (ID)} owned by Component for user HResult. Justification: TestCode.

Message #

%2 failed to remove the User Setting {(%7) (%8) (%9)} owned by %6 for user %5. Justification: %11

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Justification UnicodeString
TestCode Boolean

Event ID 1010: The System Setting {(Area) (SubArea) (ID)} owned by Component was successfully removed by ProcessName.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Task
ValueRemoved

Description

The System Setting {(Area) (SubArea) (ID)} owned by Component was successfully removed by ProcessName. Justification: TestCode.

Message #

The System Setting {(%7) (%8) (%9)} owned by %6 was successfully removed by %2. Justification: %11

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Justification UnicodeString
TestCode Boolean

Event ID 1011: ProcessName failed to remove the System Setting {(Area) (SubArea) (ID)} owned by Component.

#
Provider
Microsoft-Windows-Privacy-Auditing-CPSS
Channel
Operational
Task
ValueRemoved

Description

ProcessName failed to remove the System Setting {(Area) (SubArea) (ID)} owned by Component. Justification: TestCode.

Message #

%2 failed to remove the System Setting {(%7) (%8) (%9)} owned by %6. Justification: %11

Fields #

NameDescription
ProcessUserSid UnicodeString
ProcessName UnicodeString
ProcessAppPackageFullName UnicodeString
TargetUserSid UnicodeStringSID of the target account.
HResult HexInt32
Component UnicodeString
Area UnicodeString
SubArea UnicodeString
ID UnicodeString
Justification UnicodeString
TestCode Boolean

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 15f4cd44-ca53-5422-db17-4e76821b5a69

Defined in CorePrivacySettingsStore.dll, which carries the event manifest.

Observed on:

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1882, captured 2026-06-02

Downloads