Microsoft-Windows-Security-EnterpriseData-FileRevocationManager
6 events across 1 channel
Event ID 0: Application AppIDString created an enterprise protection key for EntIDString.
#Event ID 1: Application AppIDString failed to create an enterprise protection key for EntIDString.
#Event ID 17: Application AppIDString successfully deleted all EntIDString enterprise protection keys.
#Event ID 18: Application AppIDString successfully deleted its EntIDString enterprise protection key.
#Event ID 19: Application AppIDString failed to delete EntIDString enterprise protection key(s).
#Event ID 20: The following entry in the Group Policy "Allow Windows Runtime apps to revoke enterprise data" is formatted incorrectly and was ignored.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 2cd58181-0bb6-463e-828a-056ff837f966
Defined in efswrt.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3692, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4484, captured 2026-06-02