Microsoft-Windows-Security-EnterpriseData-FileRevocationManager

6 events across 1 channel

Event ID 0: Application AppIDString created an enterprise protection key for EntIDString.

#
Provider
Microsoft-Windows-Security-EnterpriseData-FileRevocationManager
Channel
Operational
Opcode
ProtectIdentityoperation.

Description

Application AppIDString created an enterprise protection key for EntIDString.

Message #

Application %2 created an enterprise protection key for %1.

Fields #

NameDescription
EntIDString UnicodeString
AppIDString UnicodeString

Event ID 1: Application AppIDString failed to create an enterprise protection key for EntIDString.

#
Provider
Microsoft-Windows-Security-EnterpriseData-FileRevocationManager
Channel
Operational
Opcode
ProtectIdentityoperation.

Description

Application AppIDString failed to create an enterprise protection key for EntIDString. Error: ErrorCode.

Message #

Application %2 failed to create an enterprise protection key for %1. Error: %3.

Fields #

NameDescription
EntIDString UnicodeString
AppIDString UnicodeString
ErrorCode HexInt32

Event ID 17: Application AppIDString successfully deleted all EntIDString enterprise protection keys.

#
Provider
Microsoft-Windows-Security-EnterpriseData-FileRevocationManager
Channel
Operational
Opcode
RevokeIdentityoperation.

Description

Application AppIDString successfully deleted all EntIDString enterprise protection keys.

Message #

Application %2 successfully deleted all %1 enterprise protection keys.

Fields #

NameDescription
EntIDString UnicodeString
AppIDString UnicodeString

Event ID 18: Application AppIDString successfully deleted its EntIDString enterprise protection key.

#
Provider
Microsoft-Windows-Security-EnterpriseData-FileRevocationManager
Channel
Operational
Opcode
RevokeIdentityoperation.

Description

Application AppIDString successfully deleted its EntIDString enterprise protection key.

Message #

Application %2 successfully deleted its %1 enterprise protection key.

Fields #

NameDescription
EntIDString UnicodeString
AppIDString UnicodeString

Event ID 19: Application AppIDString failed to delete EntIDString enterprise protection key(s).

#
Provider
Microsoft-Windows-Security-EnterpriseData-FileRevocationManager
Channel
Operational
Opcode
RevokeIdentityoperation.

Description

Application AppIDString failed to delete EntIDString enterprise protection key(s). Error: ErrorCode.

Message #

Application %2 failed to delete %1 enterprise protection key(s). Error: %3.

Fields #

NameDescription
EntIDString UnicodeString
AppIDString UnicodeString
ErrorCode HexInt32

Event ID 20: The following entry in the Group Policy "Allow Windows Runtime apps to revoke enterprise data" is formatted incorrectly and was ignored.

#
Provider
Microsoft-Windows-Security-EnterpriseData-FileRevocationManager
Channel
Operational
Opcode
Delegationoperation.

Description

The following entry in the Group Policy "Allow Windows Runtime apps to revoke enterprise data" is formatted incorrectly and was ignored.

Message #

The following entry in the Group Policy "Allow Windows Runtime apps to revoke enterprise data" is formatted incorrectly and was ignored:
%1

Fields #

NameDescription
PolicyString UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 2cd58181-0bb6-463e-828a-056ff837f966

Defined in efswrt.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3692, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4484, captured 2026-06-02

Downloads