Microsoft-Windows-Security-SPP

EventTitleChannelSampleRule
1SLSvcInit_PhaseOneStartPerfNN
2SLSvcInit_PhaseOneStopPerfNN
3SLSvcInit_PhaseTwoStartPerfNN
4SLSvcInit_PhaseTwoStopPerfNN
5SLSvcInit_TokenStoreStartPerfNN
6SLSvcInit_TokenStoreStopPerfNN
7SLSvcInit_ConsumeRightStartPerfNN
8SLSvcInit_ConsumeRightStopPerfNN
10SLSvc_HwidCollectStartPerfNN
11SLSvc_HwidCollectStopPerfNN
12SLSVC_ActionStateCollectStartPerfNN
13SLSVC_ActionStateCollectStopPerfNN
14SLSVC_InstallEncryptedLicenseStartPerfNN
15SLSVC_InstallEncryptedLicenseStopPerfNN
16SLSVC_GenuineCollectStoresDataStartPerfNN
17SLSVC_GenuineCollectStoresDataStopPerfNN
900The Software Protection service is starting.ApplicationYN
900The Software Protection service is startingOperationalYN
902The Software Protection service has started.ApplicationYN
902The Software Protection service has startedOperationalYN
903The Software Protection service has stopped.ApplicationYN
903The Software Protection service has stoppedOperationalYN
1001The Software Protection service failed to startOperationalNN
1003The Software Protection service has completed licensing status check.ApplicationYN
1003The Software Protection service has completed licensing status checkOperationalYN
1004The Software Protection service has successfully installed the license.ApplicationYN
1004The Software Protection service has successfully installed the licenseOperationalYN
1007Acquisition of Secure Processor Certificate was successfulApplication, OperationalYN
1008Acquisition of Secure Processor Certificate failedOperationalNN
1009Acquisition of Rights Account Certificate was successfulApplication, OperationalYN
1010Acquisition of Rights Account Certificate failedOperationalNN
1011Acquisition of Product Certificate was successfulApplication, OperationalYN
1012Acquisition of Product Certificate failedOperationalNN
1013Acquisition of End User License was successful.ApplicationYN
1013Acquisition of End User License was successfulOperationalYN
1014Acquisition of End User License failed.ApplicationYN
1014Acquisition of End User License failedOperationalYN
1015Detailed HRESULTOperationalNN
1016Proof of Purchase installed successfully.ApplicationYN
1016Proof of Purchase installed successfullyOperationalYN
1017Installation of the Proof of Purchase failedOperationalNN
1018Proof of Purchase removed successfullyOperationalYN
1019Removal of the Proof of Purchase failedOperationalNN
1020Proxy Execution Key has failed to loadOperationalNN
1022The system has been tamperedOperationalNN
1024The hardware has changed.ApplicationYN
1024The hardware has changedOperationalYN
1025Grace period has been started.ApplicationYN
1025Grace period has been startedOperationalYN
1028There are %1 invalid license(s)OperationalNN
1029Unable to get detailed error information during license consumptionApplicationYN
1029Unable to get detailed error information during license consumptionOperationalYN
1032Kernel policy cache update failedOperationalNN
1033These policies are being excluded since they are only defined with override-only …ApplicationYN
1033These policies are being excluded since they are only defined with override-only …OperationalYN
1034Duplicate definition of policy found.ApplicationYN
1034Duplicate definition of policy foundOperationalYN
1035A higher priority policy without override-only attribute foundOperationalNN
1036Validity period has been started.ApplicationYN
1036Validity period has been startedOperationalYN
1037Time-based license remaining validity time 129600 minutes.ApplicationYN
1037Time-based license remaining Data_0 time Data_1 minutesOperationalYN
1040Hardware has changed from previous boot.ApplicationYN
1040Hardware has changed from previous bootOperationalYN
1041Failed to collect hardware dataOperationalNN
1044The following errors occurred during license evaluation:OperationalNN
1056Some data has been resetOperationalNN
1057Unable to update Windows PID information in the registry:OperationalNN
1058Installation of the Proof of Purchase from the ACPI table failedOperationalNN
1059Detected OS composition change triggered license re-evaluationOperationalNN
1060Kernel policy cache has not been updated after Windows Right consumptionOperationalNN
1061Edition changed from %1 to %2 after Windows Right consumptionOperationalNN
1062Deposition of Confirmation ID failedOperationalNN
1066Initialization status for service objects.ApplicationYN
1066Initialization status for service objectsOperationalYN
1067Genuine information set for application.ApplicationYN
1067Genuine information set for applicationOperationalYN
1072Successfully matched deposited Installation ID with Confirmation IDOperationalNN
1090The Software Licensing edition check failedOperationalNN
1184Invalid chunk hash detected in migration blobOperationalNN
1185Failed to gather PKEY information for SKUOperationalNN
1186Installing migrated PKEY failed withOperationalNN
1187The Sku associated with the IID/CID is not installed on the local machineOperationalNN
1188The Sku associated with the IID/CID does not have a PKEY installedOperationalNN
1189Failed to read migration blob - encryption key not recognizedOperationalNN
1190Unable to deposit chunk due to HWID mismatchOperationalNN
1191Unable to deposit chunk due to Trusted Store being recreatedOperationalNN
1192Failed to gather PKEY information for backup product keyOperationalNN
1193Failed to gather PKEY information for OEM:DM product keyOperationalNN
1194Failed to gather target OS information for PIDOperationalNN
1195Failed to gather target OS information input key dataOperationalNN
8195SLSetGenuineInformation in sppcomapi failed with the following error code:OperationalNN
8196LoadLibrary call for loading SppcommdlgOperationalNN
8197SLUI.ApplicationYN
8197SLUIOperationalYN
8198License Activation.ApplicationYN
8198License Activation (sluiOperationalYN
8200License acquisition failure details.ApplicationYN
8200License acquisition failure detailsOperationalYN
8205Token Store found to be corruptOperationalNN
8206Token Store not foundOperationalNN
8208Acquisition of genuine ticket failed (%1) for template IdOperationalNN
8209Genuine state set to non-genuine (%1) for application IdOperationalNN
8210Update current edition product key id failed withOperationalNN
8211Update Windows license and product key tokens failed withOperationalNN
8212Rearm failed for AppId = %2, SkuId = %3 - %4 Rearms RemainingOperationalNN
8213Activation Object cannot be retrieved from Active DirectoryOperationalNN
8214Active Directory Activation Object is not usableOperationalNN
8215Active Directory Activation has failedOperationalNN
8216HCI Marker has failed verificationOperationalNN
8217HCI Marker has bad dataOperationalNN
8218Failed ot retrieve HCI MarkerOperationalNN
8219OEM OA Binding failedOperationalNN
8220OEM OA Binding extraction failedOperationalNN
8221OEM OA Binding decode failedOperationalNN
8224Existing scheduler data could not be foundOperationalYN
8225The existing scheduler data does not match the expected dataOperationalNN
8226The existing scheduler data is incompleteOperationalYN
8227The existing schedule data is expiredOperationalNN
8228The rules engine failed to evaluate the rulesOperationalNN
8229The rules engine failed to perform one or more scheduled actionsOperationalNN
8230The rules engine successfully re-evaluated the schedule.ApplicationYN
8230The rules engine successfully re-evaluated the scheduleOperationalYN
8231The rules engine gathered the following context data:OperationalNN
8232The rules engine failed while trying to update the task triggers with codeOperationalNN
8233The rules engine reported a failed VL activation attemptApplicationYN
8233The rules engine reported a failed VL activation attemptOperationalYN
12288The client has sent an activation request to the key management service machineApplicationYN
12288The client has sent an activation request to the key management service machineOperationalYN
12289The client has processed an activation response from the key management service …OperationalNN
12290An activation request has been processedOperationalNN
12291Key Management Service (KMS) failed to startOperationalNN
12293Publishing the Key Management Service (KMS) to DNS in the '%2' domain failedOperationalNN
12294Publishing the Key Management Service (KMS) to DNS in the '%1' domain is …OperationalNN
12295Secure KMS initialization failed with code %1 at stageOperationalNN
12296Secure KMS initialization succeededOperationalNN
12304Successfully acquired genuine ticket for template Id …ApplicationYN
12304Successfully acquired genuine ticket for template IdOperationalYN
12305Genuine state set to genuine for application Id …ApplicationYN
12305Genuine state set to genuine for application IdOperationalYN
12306Rearm successful for AppId = 55c92734-d682-4d71-983e-d6ec3f16059f, SkuId = …ApplicationYN
12306Rearm successful for AppId = Data_0, SkuId = Data_1 - Data_2 Rearms RemainingOperationalYN
12307Skipped Rearm for AppId = 55c92734-d682-4d71-983e-d6ec3f16059f, SkuId = (null).ApplicationYN
12307Skipped Rearm for AppId = %1, SkuId =OperationalNN
12308Active Directory Activation has succeededOperationalNN
12309The client has processed an Automatic VM activation response from the parent …OperationalNN
12310An Automatic VM activation request has been processedOperationalNN
12311The MSA client has been successfully triggered to update the Device LicenseApplicationYN
12311The MSA client has been successfully triggered to update the Device LicenseOperationalYN
12320Token-based Activation has succeededOperationalNN
12322Failed to deposit Token-based Activation responseOperationalNN
16384Successfully scheduled Software Protection service for re-start at …ApplicationYN
16384Successfully scheduled Software Protection service for re-start atOperationalYN
16385Failed to schedule Software Protection service for re-start atOperationalNN
16386Successfully started task %1\OperationalNN
16387Failed to run task %2\OperationalNN
16388The current time is 2023-11-05T22:33:07Z : 2023-11-05T22:33:07Z.ApplicationYN
16388The current time is Data_0 :OperationalYN
16389Grace timer has expiredOperationalNN
16390Updated policy %1 with value of %2 from ClipOperationalNN
16391Downlevel Genuine Ticket deposit failedOperationalNN
16392Downlevel consumption failedOperationalNN
16393Downlevel Migration failedOperationalNN
16394Offline downlevel migration succeeded.ApplicationYN
16394Offline downlevel migration succeededOperationalYN
16395Operation status %2 with return codeOperationalNN
16396You are on an inactivated deviceOperationalNN
16397Device is in grace period for %1 minutes moreOperationalNN
16398Error occured during grace period %1 atOperationalNN
20481Health check initiated.ApplicationYN
20481Health check initiatedOperationalYN
20482Health check passed.ApplicationYN
20482Health check passedOperationalYN
20483Tamper detected:OperationalNN
20484Error occurred during Health check:OperationalNN
20485Genuine validation initiatedOperationalNN
20486Genuine validation result:OperationalNN
20487Genuine validation failure:OperationalNN
20488Genuine validation data collection started.ApplicationYN
20488Genuine validation data collection startedOperationalYN
20489Genuine validation data collection ended.ApplicationYN
20489Genuine validation data collection endedOperationalYN
20490Grace timer initialization failedOperationalNN
20491Grace timer previously createdOperationalNN
20492Grace period terminated with codeOperationalNN
1073742724The Software Protection service is starting.OperationalYN
1073742726The Software Protection service has started.OperationalYN
1073742727The Software Protection service has stopped.OperationalYN
1073742827The Software Protection service has completed licensing status check.OperationalYN
1073742828The Software Protection service has successfully installed the license.OperationalYN
1073742831Acquisition of Secure Processor Certificate was successful.OperationalNN
1073742833Acquisition of Rights Account Certificate was successful.OperationalNN
1073742835Acquisition of Product Certificate was successful.OperationalNN
1073742837Acquisition of End User License was successful.OperationalYN
1073742840Proof of Purchase installed successfully.OperationalYN
1073742842Proof of Purchase removed successfully.OperationalYN
1073742849Grace period has been started.OperationalYN
1073742857These policies are being excluded since they are only defined with override-only …OperationalYN
1073742858Duplicate definition of policy found.OperationalYN
1073742859A higher priority policy without override-only attribute found.OperationalNN
1073742860Validity period has been started.OperationalYN
1073742864Hardware has changed from previous boot.OperationalYN
1073742884Kernel policy cache has not been updated after Windows Right consumption.OperationalNN
1073742885Edition changed from param1 to param2 after Windows Right consumption.OperationalNN
1073742890Initialization status for service objects.OperationalYN
1073742896Successfully matched deposited Installation ID with Confirmation ID.OperationalNN
1073750030Token Store not found.OperationalNN
1073750048Existing scheduler data could not be found.OperationalYN
1073750049The existing scheduler data does not match the expected data.OperationalNN
1073750050The existing scheduler data is incomplete.OperationalYN
1073750051The existing schedule data is expired.OperationalNN
1073750052The rules engine failed to evaluate the rules.OperationalNN
1073750053The rules engine failed to perform one or more scheduled actions.OperationalNN
1073750054The rules engine successfully re-evaluated the schedule.OperationalYN
1073750055The rules engine gathered the following context data.OperationalNN
1073750056The rules engine failed while trying to update the task triggers with code …OperationalNN
1073750057The rules engine reported a failed VL activation attempt.OperationalYN
1073754112The client has sent an activation request to the key management service machine.OperationalNN
1073754113The client has processed an activation response from the key management service …OperationalNN
1073754114An activation request has been processed.OperationalNN
1073754115Key Management Service (KMS) failed to start.OperationalNN
1073754117Publishing the Key Management Service (KMS) to DNS in the '%2' domain failed.OperationalNN
1073754118Publishing the Key Management Service (KMS) to DNS in the 'param1' domain is …OperationalNN
1073754119Secure KMS initialization failed with code %1 at stage %2.OperationalNN
1073754120Secure KMS initialization succeeded.OperationalNN
1073754128Successfully acquired genuine ticket for template Id param1.OperationalYN
1073754129Genuine state set to genuine for application Id param1.OperationalYN
1073754130Rearm successful for AppId = param1, SkuId = param2 - param3 Rearms Remaining.OperationalYN
1073754131Skipped Rearm for AppId = param1, SkuId = param2.OperationalNN
1073754132Active Directory Activation has succeeded.OperationalNN
1073754133The client has processed an Automatic VM activation response from the parent …OperationalNN
1073754134An Automatic VM activation request has been processed.OperationalNN
1073754135The MSA client has been successfully triggered to update the Device LicenseOperationalYN
1073754144Token-based Activation has succeeded.OperationalNN
1073758208Successfully scheduled Software Protection service for re-start at %1.OperationalYN
1073758210Successfully started task param1\param2.OperationalNN
1073758212The current time is 1 : %2.OperationalYN
1073758213Grace timer has expired.OperationalNN
2147484663Detailed HRESULT.OperationalNN
2147484664Grace timer notification failed hr=.OperationalYN
2147484665Installation of the Proof of Purchase failed.OperationalNN
2147484666Grace timer creation result %1.OperationalYN
2147484667Removal of the Proof of Purchase failed.OperationalNN
2147484668Proxy Execution Key has failed to load.OperationalNN
2147484670The system has been tampered.OperationalNN
2147484672The hardware has changed.OperationalYN
2147484677Unable to get detailed error information during license consumption.OperationalYN
2147484680Kernel policy cache update failed.OperationalNN
2147484685Time-based license remaining param1 time param2 minutes.OperationalYN
2147484692The following errors occurred during license evaluation.OperationalNN
2147484704Some data has been reset.OperationalNN
2147484705Unable to update Windows PID information in the registry: …OperationalNN
2147484706Installation of the Proof of Purchase from the ACPI table failed.OperationalNN
2147484707Detected OS composition change triggered license re-evaluation.OperationalNN
2147484708Detected OEM product key change triggered license re-evaluation.OperationalNN
2147484715Genuine information set for application.OperationalYN
2147484738The Software Licensing edition check failed.OperationalNN
2147484832Invalid chunk hash detected in migration blob.OperationalNN
2147484833Failed to gather PKEY information for SKU.OperationalNN
2147484834Installing migrated PKEY failed with Sku_id.OperationalNN
2147484835The Sku associated with the IID/CID is not installed on the local machine.OperationalNN
2147484836The Sku associated with the IID/CID does not have a PKEY installed.OperationalNN
2147484838Unable to deposit chunk due to HWID mismatch.OperationalNN
2147484839Unable to deposit chunk due to Trusted Store being recreated.OperationalNN
2147484840Failed to gather PKEY information for backup product key.OperationalNN
2147484841Failed to gather PKEY information for OEM:DM product key.OperationalNN
2147484842Failed to gather target OS information for PID.OperationalNN
2147484843Failed to gather target OS information input key data.OperationalNN
3221226473The Software Protection service failed to start.OperationalNN
3221226480Acquisition of Secure Processor Certificate failed.OperationalNN
3221226482Acquisition of Rights Account Certificate failed.OperationalNN
3221226484Acquisition of Product Certificate failed.OperationalNN
3221226486Acquisition of End User License failed.OperationalYN
3221226500There are param1 invalid license(s).OperationalNN
3221226513Failed to collect hardware data.OperationalNN
3221226534Deposition of Confirmation ID failed.OperationalNN
3221226661Failed to read migration blob - encryption key not recognized.OperationalNN
3221233667SLSetGenuineInformation in sppcomapi failed with the following error code.OperationalNN
3221233668LoadLibrary call for loading Sppcommdlg.OperationalNN
3221233669SLUI.OperationalYN
3221233670License Activation.OperationalYN
3221233672License acquisition failure details.OperationalYN
3221233677Token Store found to be corrupt.OperationalNN
3221233680Acquisition of genuine ticket failed (param1) for template Id param2.OperationalNN
3221233681Genuine state set to non-genuine (param1) for application Id param2.OperationalNN
3221233682Update current edition product key id failed with param1.OperationalNN
3221233683Update Windows license and product key tokens failed with param1.OperationalNN
3221233684Rearm failed for AppId = %2, SkuId = %3 - %4 Rearms Remaining.OperationalNN
3221233685Activation Object cannot be retrieved from Active Directory.OperationalNN
3221233686Active Directory Activation Object is not usable.OperationalNN
3221233687Active Directory Activation has failed.OperationalNN
3221233688HCI Marker has failed verification.OperationalNN
3221233689HCI Marker has bad data.OperationalNN
3221233690Failed ot retrieve HCI Marker.OperationalNN
3221233691OEM OA Binding failed.OperationalNN
3221233692OEM OA Binding extraction failed.OperationalNN
3221233693OEM OA Binding decode failed.OperationalNN
3221237794Failed to deposit Token-based Activation response.OperationalNN
3221241857Failed to schedule Software Protection service for re-start at %2.OperationalNN
3221241859Failed to run task %2\%3.OperationalNN
3221241860Authorized upgrade for PID: AuthorizedUpgradeForPID.OperationalYN
3221241861Downlevel Genuine Ticket successfully deposited.OperationalNN
3221241862Updated policy param1 with value of param2 from Clip.OperationalNN
3221241863Downlevel Genuine Ticket deposit failed.OperationalNN
3221241864Downlevel consumption failed.OperationalNN
3221241865Downlevel Migration failed.OperationalNN
3221241866Offline downlevel migration succeeded.OperationalYN
3221241867Operation status %2 with return code %1.OperationalNN
3221241868You are on an inactivated device.OperationalNN
3221241869Device is in grace period for %1 minutes more.OperationalNN
3221241870Error occured during grace period %1 at %2.OperationalNN
3221245953Health check initiated.OperationalYN
3221245954Health check passed.OperationalYN
3221245955Tamper detected.OperationalNN
3221245956Error occurred during Health check.OperationalNN
3221245957Genuine validation initiated.OperationalNN
3221245958Genuine validation result.OperationalNN
3221245959Genuine validation failure.OperationalNN
3221245960Genuine validation data collection started.OperationalYN
3221245961Genuine validation data collection ended.OperationalYN
3221245962Grace timer initialization failed.OperationalNN
3221245963Grace timer previously created.OperationalNN
3221245964Grace period terminated with code %1.OperationalNN

Event ID 1: SLSvcInit_PhaseOneStart

#
Channel
Perf
Task
SLSvcInit_PhaseOne
Opcode
Start

Event ID 2: SLSvcInit_PhaseOneStop

#
Channel
Perf
Task
SLSvcInit_PhaseOne
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 3: SLSvcInit_PhaseTwoStart

#
Channel
Perf
Task
SLSvcInit_PhaseTwo
Opcode
Start

Fields #

NameDescription
IsLowPriorityInit Boolean

Event ID 4: SLSvcInit_PhaseTwoStop

#
Channel
Perf
Task
SLSvcInit_PhaseTwo
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 5: SLSvcInit_TokenStoreStart

#
Channel
Perf
Task
SLSvcInit_TokenStore
Opcode
Start

Event ID 6: SLSvcInit_TokenStoreStop

#
Channel
Perf
Task
SLSvcInit_TokenStore
Opcode
Stop

Event ID 7: SLSvcInit_ConsumeRightStart

#
Channel
Perf
Task
SLSvcInit_ConsumeRight
Opcode
Start

Event ID 8: SLSvcInit_ConsumeRightStop

#
Channel
Perf
Task
SLSvcInit_ConsumeRight
Opcode
Stop

Event ID 10: SLSvc_HwidCollectStart

#
Channel
Perf
Task
SLSvc_HwidCollect
Opcode
Start

Event ID 11: SLSvc_HwidCollectStop

#
Channel
Perf
Task
SLSvc_HwidCollect
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 12: SLSVC_ActionStateCollectStart

#
Channel
Perf
Task
SLSVC_ActionStateCollect
Opcode
Start

Event ID 13: SLSVC_ActionStateCollectStop

#
Channel
Perf
Task
SLSVC_ActionStateCollect
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 14: SLSVC_InstallEncryptedLicenseStart

#
Channel
Perf
Task
SLSVC_InstallEncryptedLicense
Opcode
Start

Event ID 15: SLSVC_InstallEncryptedLicenseStop

#
Channel
Perf
Task
SLSVC_InstallEncryptedLicense
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 16: SLSVC_GenuineCollectStoresDataStart

#
Channel
Perf
Task
SLSVC_GenuineCollectStoresData
Opcode
Start

Event ID 17: SLSVC_GenuineCollectStoresDataStop

#
Channel
Perf
Task
SLSVC_GenuineCollectStoresData
Opcode
Stop

Event ID 900: The Software Protection service is starting.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 900,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:34:24.586774+00:00",
    "event_record_id": 1585,
    "correlation": {},
    "execution": {
      "process_id": 7300,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "<explicit>"
    ]
  },
  "message": "The Software Protection service is starting.\nParameters:<explicit>"
}

Event ID 900: The Software Protection service is starting

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 900,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:35:28.3709306+00:00",
    "event_record_id": 725,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<explicit>"
  },
  "message": "The Software Protection service is starting.\r\nParameters:<explicit>"
}

Event ID 902: The Software Protection service has started.

#
Channel
Application

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 902,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:24.555246+00:00",
    "event_record_id": 1550,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "10.0.22621.2428"
    ]
  },
  "message": "The Software Protection service has started.\n10.0.22621.2428"
}

Event ID 902: The Software Protection service has started

#
Channel
Operational

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 902,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:14.7146737+00:00",
    "event_record_id": 718,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "10.0.20348.587"
  },
  "message": "The Software Protection service has started.\r\n10.0.20348.587"
}

Event ID 903: The Software Protection service has stopped.

#
Channel
Application

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 903,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:38.447304+00:00",
    "event_record_id": 1583,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The Software Protection service has stopped.\n"
}

Event ID 903: The Software Protection service has stopped

#
Channel
Operational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 903,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:46.2302972+00:00",
    "event_record_id": 722,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The Software Protection service has stopped.\r\n"
}

Event ID 1001: The Software Protection service failed to start

#
Channel
Operational

Event ID 1003: The Software Protection service has completed licensing status check.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1003,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:07.803890+00:00",
    "event_record_id": 1576,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "55c92734-d682-4d71-983e-d6ec3f16059f",
      "\n1: 3f4c0546-36c6-46a8-a37f-be13cdd0cf25, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 9 0x00000000 90 129600)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )(3 )]\n\n"
    ]
  },
  "message": "The Software Protection service has completed licensing status check.\nApplication Id=55c92734-d682-4d71-983e-d6ec3f16059f\nLicensing Status=\n1: 3f4c0546-36c6-46a8-a37f-be13cdd0cf25, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 9 0x00000000 90 129600)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )(3 )]\n\n"
}

Event ID 1003: The Software Protection service has completed licensing status check

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1003,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:14.6834309+00:00",
    "event_record_id": 716,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "55c92734-d682-4d71-983e-d6ec3f16059f",
    "Data_1": "\n1: c1a197b6-ba5e-4394-b9bf-b659a6c1b873, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 9 0x00000000 180 44820)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )(3 )]\n\n"
  },
  "message": "The Software Protection service has completed licensing status check.\r\nApplication Id=55c92734-d682-4d71-983e-d6ec3f16059f\r\nLicensing Status=\n1: c1a197b6-ba5e-4394-b9bf-b659a6c1b873, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 9 0x00000000 180 44820)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )(3 )]\n\n"
}

Event ID 1004: The Software Protection service has successfully installed the license.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:49.517533+00:00",
    "event_record_id": 1562,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}",
      "5bb83ecf-2e3a-448d-be9a-99bab42fd5c6"
    ]
  },
  "message": "The Software Protection service has successfully installed the license.\nLicense Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}\nLicense Id=5bb83ecf-2e3a-448d-be9a-99bab42fd5c6"
}

Event ID 1004: The Software Protection service has successfully installed the license

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:10.9521355+00:00",
    "event_record_id": 207,
    "correlation": {},
    "execution": {
      "process_id": 3904,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}",
    "Data_1": "03b44ff3-84e6-41a9-bc4a-f0e0c9ee1a79"
  },
  "message": "The Software Protection service has successfully installed the license.\r\nLicense Title=XrML 2.1 License - {msft:sl/EUL/ACTIVATED/PRIVATE}\r\nLicense Id=03b44ff3-84e6-41a9-bc4a-f0e0c9ee1a79"
}

Event ID 1007: Acquisition of Secure Processor Certificate was successful

#
Channel
Application, Operational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1007,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2016-08-24T21:21:10.000000Z",
    "event_record_id": 1635,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE10Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {}
}

References #

Event ID 1008: Acquisition of Secure Processor Certificate failed

#
Channel
Operational

Event ID 1009: Acquisition of Rights Account Certificate was successful

#
Channel
Application, Operational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1009,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2016-08-24T21:21:11.000000Z",
    "event_record_id": 1638,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE10Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {}
}

References #

Event ID 1010: Acquisition of Rights Account Certificate failed

#
Channel
Operational

Event ID 1011: Acquisition of Product Certificate was successful

#
Channel
Application, Operational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1011,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2016-08-24T21:21:11.000000Z",
    "event_record_id": 1641,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE10Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {}
}

References #

Event ID 1012: Acquisition of Product Certificate failed

#
Channel
Operational

Event ID 1013: Acquisition of End User License was successful.

#
Channel
Application

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1013,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:49.411554+00:00",
    "event_record_id": 1560,
    "correlation": {},
    "execution": {
      "process_id": 5592,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
    ]
  },
  "message": "Acquisition of End User License was successful.\nSku Id=3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
}

Event ID 1013: Acquisition of End User License was successful

#
Channel
Operational

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1013,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:10.9235875+00:00",
    "event_record_id": 205,
    "correlation": {},
    "execution": {
      "process_id": 4256,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
  },
  "message": "Acquisition of End User License was successful.\r\nSku Id=3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
}

Event ID 1014: Acquisition of End User License failed.

#
Channel
Application
Level
Error

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1014,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T16:48:32.202000+00:00",
    "event_record_id": 25,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "hr=0x80072EE7",
      "c1a197b6-ba5e-4394-b9bf-b659a6c1b873"
    ]
  },
  "message": "Acquisition of End User License failed. hr=0x80072EE7\nSku Id=c1a197b6-ba5e-4394-b9bf-b659a6c1b873"
}

Event ID 1014: Acquisition of End User License failed

#
Channel
Operational
Level
2

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1014,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T17:00:42.1930828+00:00",
    "event_record_id": 186,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-MEM-c",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "hr=0x8004FE93",
    "Data_1": "c1a197b6-ba5e-4394-b9bf-b659a6c1b873"
  },
  "message": "Acquisition of End User License failed. hr=0x8004FE93\r\nSku Id=c1a197b6-ba5e-4394-b9bf-b659a6c1b873"
}

Event ID 1015: Detailed HRESULT

#
Channel
Operational

Event ID 1016: Proof of Purchase installed successfully.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1016,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T16:45:32.242626+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "c1a197b6-ba5e-4394-b9bf-b659a6c1b873",
      "88d68b6f-8762-54b3-a3a4-920848fabd33"
    ]
  },
  "message": "Proof of Purchase installed successfully. \nACID=c1a197b6-ba5e-4394-b9bf-b659a6c1b873\nPKeyId=88d68b6f-8762-54b3-a3a4-920848fabd33"
}

Event ID 1016: Proof of Purchase installed successfully

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1016,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T16:53:25.4473625+00:00",
    "event_record_id": 155,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN-TPT4AT2LF95",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "c1a197b6-ba5e-4394-b9bf-b659a6c1b873",
    "Data_1": "88d68b6f-8762-54b3-a3a4-920848fabd33"
  },
  "message": "Proof of Purchase installed successfully. \r\nACID=c1a197b6-ba5e-4394-b9bf-b659a6c1b873\r\nPKeyId=88d68b6f-8762-54b3-a3a4-920848fabd33"
}

Event ID 1017: Installation of the Proof of Purchase failed

#
Channel
Operational

Event ID 1018: Proof of Purchase removed successfully

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1018,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-17T18:19:51.5906816+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1019: Removal of the Proof of Purchase failed

#
Channel
Operational

Event ID 1020: Proxy Execution Key has failed to load

#
Channel
Operational

Event ID 1022: The system has been tampered

#
Channel
Operational

Event ID 1024: The hardware has changed.

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1024,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-07 23:45:21.190804+00:00",
    "event_record_id": 182,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 3016,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "",
    "Binary": "XgAAABMAMAAAAAIAAwABAAEAAQAAAAAAAQABAAAAlisGZooKAYtSyJ7WQeBuIiQd+a8zhMBiDQACAAEBAAIFAAMBAAQCAAUAAAYBAAcAAAgHAAkDAAoBAAsAAAwHAA=="
  },
  "message": "The hardware has changed."
}

Event ID 1024: The hardware has changed

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1024,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:03.9119705+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Binary": "5E0000001300300000000200030001000100010000000000010001000000962B06668A0A018B52C89ED641E06E22241DF9AF3384C0620D0002000101000205000301000402000500000601000700000807000903000A01000B00000C0700"
  }
}

Example keys not documented in the fields table: Binary

Event ID 1025: Grace period has been started.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1025,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2013-10-23T16:17:02+00:00",
    "event_record_id": 66,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "37L4247D28-05",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "10",
      "5"
    ]
  },
  "message": "Grace period has been started. Grace days=10  Grace type=5."
}

Event ID 1025: Grace period has been started

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1025,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T17:06:26.7000973+00:00",
    "event_record_id": 196,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-MEM-c.cell-c.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "10",
    "Data_1": "6"
  },
  "message": "Grace period has been started. Grace days=10  Grace type=6."
}

Event ID 1028: There are %1 invalid license(s)

#
Channel
Operational

Event ID 1029: Unable to get detailed error information during license consumption

#
Channel
Application
Level
Warning

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1029,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-14T16:34:52.232627+00:00",
    "event_record_id": 37498,
    "correlation": {},
    "execution": {
      "process_id": 4876,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "0xC004F015",
    "Binary": ""
  },
  "message": ""
}

Event ID 1029: Unable to get detailed error information during license consumption

#
Channel
Operational
Level
3

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1029,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:08:57.3977547+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "0xC004F015"
  }
}

Example keys not documented in the fields table: Data

Event ID 1032: Kernel policy cache update failed

#
Channel
Operational

Event ID 1033: These policies are being excluded since they are only defined with override-only attribute.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1033,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:07.619160+00:00",
    "event_record_id": 1574,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "(Security-SPP-Reserved-EnableNotificationMode) ",
      "55c92734-d682-4d71-983e-d6ec3f16059f",
      "3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
    ]
  },
  "message": "These policies are being excluded since they are only defined with override-only attribute.\nPolicy Names=(Security-SPP-Reserved-EnableNotificationMode) \nApp Id=55c92734-d682-4d71-983e-d6ec3f16059f\nSku Id=3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
}

Event ID 1033: These policies are being excluded since they are only defined with override-only attribute

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1
Data_2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1033,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T05:23:08.5247865+00:00",
    "event_record_id": 1020,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "(Security-SPP-Reserved-EnableNotificationMode) ",
    "Data_1": "55c92734-d682-4d71-983e-d6ec3f16059f",
    "Data_2": "c1a197b6-ba5e-4394-b9bf-b659a6c1b873"
  },
  "message": "These policies are being excluded since they are only defined with override-only attribute.\r\nPolicy Names=(Security-SPP-Reserved-EnableNotificationMode) \r\nApp Id=55c92734-d682-4d71-983e-d6ec3f16059f\r\nSku Id=c1a197b6-ba5e-4394-b9bf-b659a6c1b873"
}

Event ID 1034: Duplicate definition of policy found.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1034,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:07.616984+00:00",
    "event_record_id": 1573,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "Security-SPP-Reserved-LicenseProperties",
      "100"
    ]
  },
  "message": "Duplicate definition of policy found. Policy name=Security-SPP-Reserved-LicenseProperties  Priority=100"
}

Event ID 1034: Duplicate definition of policy found

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1034,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T05:23:08.5247865+00:00",
    "event_record_id": 1019,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "Security-SPP-Reserved-LicenseProperties",
    "Data_1": "100"
  },
  "message": "Duplicate definition of policy found. Policy name=Security-SPP-Reserved-LicenseProperties  Priority=100"
}

Event ID 1035: A higher priority policy without override-only attribute found

#
Channel
Operational

Event ID 1036: Validity period has been started.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1036,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:07.555440+00:00",
    "event_record_id": 1572,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "129600",
      "9"
    ]
  },
  "message": "Validity period has been started. Validity minutes=129600  Grace type=9."
}

Event ID 1036: Validity period has been started

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1036,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-04-18T00:30:29.8360639+00:00",
    "event_record_id": 80,
    "correlation": {},
    "execution": {
      "process_id": 3644,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "129600",
    "Data_1": "9"
  },
  "message": "Validity period has been started. Validity minutes=129600  Grace type=9."
}

Event ID 1037: Time-based license remaining validity time 129600 minutes.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1037,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:07.810237+00:00",
    "event_record_id": 1577,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "validity",
      "129600"
    ]
  },
  "message": "Time-based license remaining validity time 129600 minutes."
}

Event ID 1037: Time-based license remaining Data_0 time Data_1 minutes

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1037,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:14.6834309+00:00",
    "event_record_id": 717,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "validity",
    "Data_1": "44820"
  },
  "message": "Time-based license remaining validity time 44820 minutes."
}

Event ID 1040: Hardware has changed from previous boot.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1040,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-01-28T02:48:07.177709+00:00",
    "event_record_id": 187,
    "correlation": {},
    "execution": {
      "process_id": 3848,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "55c92734-d682-4d71-983e-d6ec3f16059f",
      "3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
    ],
    "Binary": "XgAAAAoAMAAAAAIAAwABAAEAAQAAAAAAAQABAAAAlit6tYoKAYtSyJ7WQeBuIiQd+a/NUsBiDQABAAEBAAIBAAMBAAQBAAUAAAYBAAcAAAgBAAkBAAoBAAsAAAwBACwAAAABAAIAAQABAAEAAAAAAAEAAQAAANamEuqKClLIntZuIiQd+a/ptaj2"
  },
  "message": "Hardware has changed from previous boot.\n AppId=55c92734-d682-4d71-983e-d6ec3f16059f, SkuId=3f4c0546-36c6-46a8-a37f-be13cdd0cf25."
}

References #

Event ID 1040: Hardware has changed from previous boot

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1040,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:03.7447578+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Binary": "5E0000000A00300000000200030001000100010000000000010001000000962B06668A0A018B52C89ED641E06E22241DF9AF3384C0620D0001000101000201000301000401000500000601000700000801000901000A01000B00000C0100280000000000010001000100010000000000010001000000CA4B381A9ED66E22241DF9AF89F13600",
    "Data": "3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
  }
}

Example keys not documented in the fields table: Binary, Data

Event ID 1041: Failed to collect hardware data

#
Channel
Operational

Event ID 1044: The following errors occurred during license evaluation:

#
Channel
Operational

Event ID 1056: Some data has been reset

#
Channel
Operational

Event ID 1057: Unable to update Windows PID information in the registry:

#
Channel
Operational

Event ID 1058: Installation of the Proof of Purchase from the ACPI table failed

#
Channel
Operational

Event ID 1059: Detected OS composition change triggered license re-evaluation

#
Channel
Operational

Event ID 1060: Kernel policy cache has not been updated after Windows Right consumption

#
Channel
Operational

Event ID 1061: Edition changed from %1 to %2 after Windows Right consumption

#
Channel
Operational

Event ID 1062: Deposition of Confirmation ID failed

#
Channel
Operational

Event ID 1066: Initialization status for service objects.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1066,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:23.779219+00:00",
    "event_record_id": 1548,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "C:\\Windows\\system32\\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000\n"
    ]
  },
  "message": "Initialization status for service objects.\nC:\\Windows\\system32\\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000\n"
}

Event ID 1066: Initialization status for service objects

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1066,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:12.9490486+00:00",
    "event_record_id": 715,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "C:\\Windows\\system32\\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000\n"
  },
  "message": "Initialization status for service objects.\r\nC:\\Windows\\system32\\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000\nC:\\Windows\\system32\\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000\n"
}

Event ID 1067: Genuine information set for application.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 1067,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:49.567022+00:00",
    "event_record_id": 1563,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "0x00000000",
      "3f4c0546-36c6-46a8-a37f-be13cdd0cf25",
      "SL_ACTIVATION_VALIDATION_IN_PROGRESS"
    ],
    "Binary": "AQAAAA=="
  },
  "message": "Genuine information set for application. 0x00000000, 3f4c0546-36c6-46a8-a37f-be13cdd0cf25, SL_ACTIVATION_VALIDATION_IN_PROGRESS.\n"
}

Event ID 1067: Genuine information set for application

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1
Data_2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 1067,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:11.0085310+00:00",
    "event_record_id": 208,
    "correlation": {},
    "execution": {
      "process_id": 3904,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "0x00000000",
    "Data_1": "3f4c0546-36c6-46a8-a37f-be13cdd0cf25",
    "Data_2": "SL_ACTIVATION_VALIDATION_IN_PROGRESS"
  },
  "message": "Genuine information set for application. 0x00000000, 3f4c0546-36c6-46a8-a37f-be13cdd0cf25, SL_ACTIVATION_VALIDATION_IN_PROGRESS.\r\n"
}

Event ID 1072: Successfully matched deposited Installation ID with Confirmation ID

#
Channel
Operational

Event ID 1090: The Software Licensing edition check failed

#
Channel
Operational

Event ID 1184: Invalid chunk hash detected in migration blob

#
Channel
Operational

Event ID 1185: Failed to gather PKEY information for SKU

#
Channel
Operational

Event ID 1186: Installing migrated PKEY failed with

#
Channel
Operational

Event ID 1187: The Sku associated with the IID/CID is not installed on the local machine

#
Channel
Operational

Event ID 1188: The Sku associated with the IID/CID does not have a PKEY installed

#
Channel
Operational

Event ID 1189: Failed to read migration blob - encryption key not recognized

#
Channel
Operational

Event ID 1190: Unable to deposit chunk due to HWID mismatch

#
Channel
Operational

Event ID 1191: Unable to deposit chunk due to Trusted Store being recreated

#
Channel
Operational

Event ID 1192: Failed to gather PKEY information for backup product key

#
Channel
Operational

Event ID 1193: Failed to gather PKEY information for OEM:DM product key

#
Channel
Operational

Event ID 1194: Failed to gather target OS information for PID

#
Channel
Operational

Event ID 1195: Failed to gather target OS information input key data

#
Channel
Operational

Event ID 8195: SLSetGenuineInformation in sppcomapi failed with the following error code:

#
Channel
Operational

Event ID 8196: LoadLibrary call for loading Sppcommdlg

#
Channel
Operational

Event ID 8197: SLUI.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 8197,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:08.267091+00:00",
    "event_record_id": 1581,
    "correlation": {},
    "execution": {
      "process_id": 6476,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "RuleId=379cccfb-d4e0-48fe-b0f2-0136097be147;Action=CleanupState;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=3f4c0546-36c6-46a8-a37f-be13cdd0cf25;Trigger=TimerEvent"
    ]
  },
  "message": "SLUI.exe was launched with the following command-line parameters:\nRuleId=379cccfb-d4e0-48fe-b0f2-0136097be147;Action=CleanupState;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=3f4c0546-36c6-46a8-a37f-be13cdd0cf25;Trigger=TimerEvent"
}

Event ID 8197: SLUI

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 8197,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T05:39:32.5003904+00:00",
    "event_record_id": 763,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "RuleId=17fd3d63-7be4-49b1-8d16-2e0fe9fddbc2;Action=NotifyUser;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c1a197b6-ba5e-4394-b9bf-b659a6c1b873;NotificationInterval=1440;Trigger=TimerEvent"
  },
  "message": "SLUI.exe was launched with the following command-line parameters:\r\nRuleId=17fd3d63-7be4-49b1-8d16-2e0fe9fddbc2;Action=NotifyUser;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c1a197b6-ba5e-4394-b9bf-b659a6c1b873;NotificationInterval=1440;Trigger=TimerEvent"
}

Event ID 8198: License Activation.

#
Channel
Application
Level
Error

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 8198,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T16:48:32.513888+00:00",
    "event_record_id": 29,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "hr=0x80072EE7",
      "RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c1a197b6-ba5e-4394-b9bf-b659a6c1b873;NotificationInterval=1440;Trigger=UserLogon;SessionId=1"
    ]
  },
  "message": "License Activation (slui.exe) failed with the following error code:\nhr=0x80072EE7\nCommand-line arguments:\nRuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=c1a197b6-ba5e-4394-b9bf-b659a6c1b873;NotificationInterval=1440;Trigger=UserLogon;SessionId=1"
}

Event ID 8198: License Activation (slui

#
Channel
Operational
Level
2

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 8198,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:10.3819044+00:00",
    "event_record_id": 204,
    "correlation": {},
    "execution": {
      "process_id": 4576,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "hr=0xC004E028",
    "Data_1": "RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=3f4c0546-36c6-46a8-a37f-be13cdd0cf25;NotificationInterval=1440;Trigger=NetworkAvailable"
  },
  "message": "License Activation (slui.exe) failed with the following error code:\r\nhr=0xC004E028\r\nCommand-line arguments:\r\nRuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=3f4c0546-36c6-46a8-a37f-be13cdd0cf25;NotificationInterval=1440;Trigger=NetworkAvailable"
}

Event ID 8200: License acquisition failure details.

#
Channel
Application
Level
Error

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 8200,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T16:48:32.202000+00:00",
    "event_record_id": 24,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "hr=0x80072EE7",
      "00010001(0x00000000, 09:48:32:133 - https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail)\r\n00020001(0x00000000, 09:48:32:148)\r\n00030001(0x00000000, 09:48:32:148 - https://activation-v2.sls.microsoft.com)\r\n00030002(0x00000000, 09:48:32:148 - 0)\r\n00040001(0x00000000, 09:48:32:148 - https://activation-v2.sls.microsoft.com)\r\n00040002(0x00000000, 09:48:32:164 - 1, <NULL>, <NULL>, <NULL>)\r\n00050002(0x80072F94, 09:48:32:164 - 0, 1)\r\n00040006(0x00000001, 09:48:32:164 - 0, https://activation-v2.sls.microsoft.com, <N/A>, <N/A>)\r\n00020005(0x00000000, 09:48:32:164 - 0)\r\n00020008(0x80072EE7, 09:48:32:181 - SOAPAction: \"http://microsoft.com/SL/ProductActivationService/IssueToken\"\r\nContent-Type: text/xml; charset=utf-8\r\n, <soap:Envelope xmlns:soap=\"http://schemas.xmlsoap.org/soap/envelope/\" xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:xsd=\"http://www.w3.org/2001/XMLSchema\" xmlns:soapenc=\"http://schemas.xmlsoap.org/soap/encoding/\"><soap:Body><RequestSecurityToken xmlns=\"http://schemas.xmlsoap.org/ws/2004/04/security/trust\"><TokenType>ProductActivation</TokenType><RequestType>http://schemas.xmlsoap.org/ws/2004/04/security/trust/Issue</RequestType><UseKey><Values xmlns:q1=\"http://schemas.xmlsoap.org/ws/2004/04/security/trust\" soapenc:arrayType=\"q1:TokenEntry[1]\"><TokenEntry><Name>PublishLicense</Name><Value>u7vcfA07FX3foOdZL5/wyf4PcsewCGhrC1PPcf45mqjfmclqytn7rlUUNHCRNO0eVM4KnnXFnZKGdRlVA43lNY1uJycMif1KW4oYjUiXoEV7Bl56k2RoBv33OF0Ocs83ijddvocbAYbm/OEDQj3pqE4BqE2Qp2flA9PcESYcJkSNVeDTQbECAr3AhS5YUizF2SL68DZppSBd4V4Z5mr30B24TWkWTfzTO2pF1iTzYBHrcisoV2Qm4T8BujQLStbTeyosKEfzCn4ze/tz48s0ItI+/p5o4MZHIGX1q6QQP4s9Fb9gqpWDABooGCK9b1+eUNIwiHuBOrDV/wen1omKfjHv+ukug5f6KwnB4jOB9RBDRuivdjaLTD1lUfnWLbzkwAQ11jR0vP1I5aT2brGGKuXsUaHkRG8h6X8DJejn3I33858vGTeC2DcCLQXy2lNQ4iiz/ggGutZqVbqWXGdAZzeiz+zV9OuItWyBM8ALVJ3K58lfttJCv1H1n8v9BYlhptPCadqIDDtUenPOkGJVQwxRjCBvZYlE8o9nzgqNdt2tSeWsnmkYmwxI6hF8nkJjrHPRAvN8s5BWqUe0QHvxHU6HUeW1FBCPofibJP834XtCi0Auu6JYgdp4Qi81sUZI6riTdcOfcQOfWx5XfBfbn3678gHU0Hz4q0edcKgbR+ONZ/Wh0/arJ9QfDX+QiRoEQnY70+nkV4kw/f99phXogimkKfLZr0nMsU92oo/Ds+pUIuii29NzMXbIbR6jn3NWAO9t4ovjojoaA/NfT/9LUiwzb1PY64cjuB+6kz7+9QycUQlAQ9tV1LoV3+vs8Q/jI3Hkov84Rrmt8DriPHjJa3q0SwW/sulBDVZ2j8HBKRT1WGRaq80ZTmK6Z5en9ZNEIhAr3NWfh5w25Ke7oDwJPY5WQgviv6gxQzwnyJ97EIRTyobhxw2gKa6aciqFs1Tn6dqohzpN3tUrWT6B7UrgrzKdLBIbXpDUI8akogs4iJ0UKopQ+gmLfu7hF3LAuvBxSBOBD3AB11vtF55heh4+RaN2Z3EigvglI5CNnW5NymplxwgEDX+ph/Xdoa0M+TqL7od3WhqYE45isovu4KuYcaJ744cVUn04RMKVqPnD2Ss4g2E+qvkxns/AzDkDHa+42uxfXkb1tLKZcgwG2AwKw+HENIFEpeN+a1zZ5wDD0vZqfNQEiOuXkqF01AlsWbej0OEdLTgNjRSBtsEoo3tUuUN5wOs40jZY7ocZxY1bEkDS8WShHsEydLT855jZC/BsYTn2Cn+S70R6oW9g2mLU33o7OPHwiDQ20iNT7q0HlKF9SDSBvsGq4R2XXqky0rDPIhD3ueM+Bjkg2zTP1vbFxlaMpqeG+iTbEsICQqIbaTIoDkcf/cz7eqT1LICoKmMuGVr9eEPLQASSZ0/JvoDlajc8KdT4XM0iWuPG2FWpGkYdIg80wa9P5NK0ENiv51bfjpkB2GynyKepcRZE+KAyAPkFvGCHX5fn047HMr5y12ltjfe14pNaEc2p8WCNwt3P62fhVgtbE+tw13f1t+mxQPnWiN1qy42uhioAo7p/HTw+TCmkhuxIzCyl8tpDGx191qQRI0fCRYEqd8GtIpGeQgqVflqUqUk+CeC2uv0w7Y1R76dqS1ewK6jgC7YgNycIAGpuljqZuqCBHJEbWhNqGn9NLSzJQhT2d3R/5ZNWpjJL7xIf6JUIKkOSh2Nn/aNd/q6bVI9OJRgExULyT6694+TGYOePdsNKbVcAwSyp4JCqQ+YxHZVpv8mQPitV2HrQa5RaamJrbTXr9QeuFGq1InjgFdhNccOEKBxBnENe8KxJ7e8vTQiy2HtN5WCY8eRcYtiHFQiYe6AMuWq7Z+6NhRt/MOeLpby2J2oboDtuhIQ8Pj83GH/VftmKe8GIViOE9elvZbWWE25Gv4tkJSDWz0pciPxJTgD1vdUU44VTUt4g89Ve/UpLw8nf0b84NLdnCKr0YdycytRbfCb8bMOYnGCFhQ1D8AfC0RO7V2lAfrLX7Ay48ERizJti6zL79WgSbrORnjPTkIKjnOm3dtZJa6fBBlBxoM0hMah4bJnvA4jthrK0zIz3ICg/ZfY2+7ncwAwyDH48G9JVx8p35Cht7kU7zQIGmTqjjOG8PDxnzC+CFikvlEFIUE1d16s/EPFqX7jfYDzkEqVC5jGateqiXX0XPnf8s3Nwy0IC7InzVPrLteBGwW3e5on5uQrBvPhWFwrEW5nqTWR5FegOUlJ6io7NKVmkkQP30CaDwovbDy/gX55+4QRjcY/C5NIhrcWjByZG4Umth9c8mZWeR8vSWWQ9fXU8Z2Y6IUzOFum7Bfzm8QVm6S90/G6w+qwX89m8egX9LSOKhvF5M2H8j6fiF7yzwlRDSmupHl4gOS6zr81ytIlNiecNnowzTzkKHbQ6TETTw1RVaC2YLtfKNXzl7JS9g8tH/hNXjHSlRW836HpKSLvjUm1dCUsgVOFt3AKkeJOTssAtgpZ0cUP3Q6PnYk4neRRVY9j63SUFVNC/QU1Uw+pJ9nazDOeh1wAj8VeChOusqQAfD5z/UlvY8yd7v4Djx3PFqLR50ksUCPkdJhD/WQelNrg++Dw//jAQnMGTe096SO/Iid5txNAzO/TVWcogbU6fIPVdVcD+yB0WARpGykfpvtiqurFqIPq/gNwU1pB5C1jy3q24PCxAIw4iyuRkD7niDYCfeoXFRX3mQSJLFiTkVtOFSfd8gm9zEC2pQm1jSMM+5c/w+dq9EwwvJ8uE/kK+/ekYKKHQM2DQffzULtaKfm9mavY9K4P0qCpCpDDFC1I3By06v0c5DzIQ8CI2ng6YTUfPMLFF+aZBKBOY2hI3Pdkvg3cvvsc8RO2bi25JMCHkvo3nfrUlzBuaC2WeoEauwTBJjGo1lzR7oxl30p0sT/Z0DdyCMDuVZguoUQV+J2xqFOEmaSCjba0i0g2+09TE6jt+LVapRBDWcENimrWE+x8Lj5kap5dPsNtkM6ms4WpyCJUsOHhdPoG2PeBkNYdOtt+jI4Kzo1uxFSVe7Il8yEfOCgtRfMyqSBmC12GlQkhnojicn/ZZ/njVusroAxNTK7bmHhgrPENUALmb9ulTTyHdY35tQTkNzdydCVICeGhs7Ao9bwOuMp2dELbOwQ+h1ff37BPtF7DeyNJZep8pNKI2MYTSaFKrhtWLv0DmZinqttZHBNYonpuqCFKF9Z0bmAFZqS+x4EixJsDwsKJZkUZFeqJqo8rq1r6YBn0xnlceOWz45wDX/sow76ScBgadTSEPdobhhsdQod0Ju3V9mrrCk2PRAe/z8YgLBLiDCZg3m+aQdwgSM6WkmWiieft2toBmScNdw7Z7VGeL8iYAtrITWLDF27ZhNNa913+3O1gw0dQAWufv6jXS+8+EslhIHm01iK+4goVQIYmlCmiMd2hEaa/T5KvMDyJj4bUhH7pjhWvZyVuQ30Uj6q9m6jnH2Cc6+m7XXnU7pXCe5v1rZE0yCXRfPRVdiF2vkMWq36RFUcNiyAyZYv6GtYpgqAcMcmWC8j3VmysYk8gBzbhGpwI4Toq8ZXwsZjN5Z4miomYz9apDHFeoym+dIS3Wd0brjt7ASRvhCUeGCReqAsmoojpCmTH8S/j6PKsgdqdoH3FagNGYH8K3Xh5XxpnomaJEl2Y4AQqCOGr/jCdrw/P601x1ByeszpzVi+qNc+YLFFoW378DaPmGGldqOGH2pKbdE6yIEOkKpulLCBb/Rt4p4Mnerjd5k3Cd4Zku2h7p0DY5iwX0cad3N3VoUyU5SYxjW4OJD41pTo7N8/+G1mR0coXaIOXEeRoP4g1Ch9VcF7POoRn3U9bhIiD27LKRg7bf/O1fbGeXX3e8/8dCYW+3XmKuUNEbsSwPW2VniN48CQboseYGY32d4PZODVpSwDx/kx80PdpZvorc7Tg50ZC9wMGEpXYxBuQcx/4+7QKGGvlFnAdqwYiturxJp1tZYiP9398ZWKNT2288CpiI1kJmx1uq/44av3ZslQ98Ul5UzYIspjCLM2GZ/QlFcg+gjE1hgiIEPSbJDuvgkrg6JN/ZoAdJfy9OVAFoO60Br4sS1YlARAolkjDrAKfRnJiF87lD1jYhE1jRgkwsv1NSt18oIZqR1pvDGXb14c4/ijK7VDLuvsJLsv1MERVu/WtmUta8PKtotDimRt3IHd7/Z+Hr865SwRmggqlUhJIALUxeXUQEuj0FPqAS6V8Lurw6a0/QNmDLsI82hs+z45qQdiV6wP8dqbUu2/qsAvcdypd/M5U2dLnj57TGjEyccX9ZDZbEcbbFe34rg1oiL6q45uV9tpPFgD1mds+a2DVMYj9H67STdw3G4Uch/ge6kNyBnZfQyH33Ll1OA69rBLiBuF+fVKIT1dg5RciZ2Cl5umwfeL1jNm/VjRL05jiMjPqmS2YpnfxjBQMy6D0zgA2K/2pEIfnqj08FO6rv/pxvpsgdQ1HNl0u+4EwmINUv6guVKWrA+who49arStGCrN0UDXxtSigEokHDud1siNWQ0Cb9NHeuep42oCC7tbm/lo7uJeAEiPCljnXV4k38HBPgybdorc7HwshEuycJAUNtzqLRGJwHmTegOYW8NF40ddifAazhPzY5rtdh+zpLyJYOFxpmwB9ODYPDJcy3uigdC/wJt8dnIWl36Us0ziGluiV+MI1Rr+jrVtgAymVGBIuHN0hRnNkdTtIS2cNKavHRAZRlJBJfdSB4cpnzmeNmNkHYr16qMTMZNomMCx+xtZTWSRpsMmVMaHttfkxkvUgluShuxYs8llKzwPPacAj2sFfp7Ll6Baxd4pP6qgWyAkssofmFi9Wniv5f2M7VCZnh8hzKyGCttk43xKAA+HkGr6QzA2sulNbft/mYV3Wxdaz4YywqKG19RUr9OlCFhkFRaBrBYDLn1i2YVCq22WMSE15wa5zMrV9eeZ1ky1LkU/8F4BwVGjtAhE11ssNhQ3Sg7UU7cBUSUtNHYcrbOgpHSJCkEUskxZAFwB3Luo2KKRYSstflxbyersUb2a3L2Y/DoGxxOXzS9ftaoz3YLxeoChWbxRCs7vOXCINQVMLewEb5TCJRsW/CgB/+4hhYLdweka4F6jZAZldATQ/6agDjYcRApoBcSmX3hPGSGxT5pjGyRLvMwI42ztC1nrZJ4+s3hPFXpRl3tNVYucg36eljbF8ZT9KUHh2slTko3+esOWcgzaqAAE0/U69PFQyJ49c5F4FZIgoXU6/msvQ08DqZHpWO95ktSZ+7CXDSm+g2REd6U155J9q2g3/kfbqxv7Ndt3LmP3/ibD5ahkSs50N6u5vRSlb7vSFFEftwWLdUij8erUSc1Sae6C6mcqM13qvBcWhiaChxfKrPsRBwEyzgQb2CijtX+D317PIY1vWZh79oq/O+W8imBUteK117znc6m6Qi5+rJF3KeRlAiEM2R3Zo3VKOovewsslk8OIY290Prte7QiDEn8YiQX323YidToBhd6g2iAZ8TDCQj8kFLOih0fy3Z5wD7NIoOWt/GcQc+2l2Tekpeo4yaVWLroBgg507wSSP1HnzQEkIcXRUrNYR14q1xzzAEYg1aOPU786F5fr94kIP6EusiroNWNgElSCvyJMOeg0odOyUlZn9BI9OQrBvKYch0S3Dao5qqc99xEFM6pG5iFE0bAjUrr8oOBITyYK4YWwj8j6tX1V6eOuWZf81FnEyCIZuder9NaD/smpVRCmbpnln468L4rRmAsnw9JIPpiUi111FZKeR+mrkKjSKusgN0NjuRVIYHhaUnkUO1FhdlYMYWbiruZjhBYkK9yZlLVmZYvyyJkzzW5SmtRW+PY+but5T+IJLw7+i8sAt3K/ILwZV+wZ9fBaBMuAkozd47Hta+VUDPmngWu3v83vXRffJq/nPfc8z46v67HOjCFOgzDt7fck2eANtF5UXdVPMuVhoVQ4AFfKANnWNS4KQgoBvaendKZoOR3NE4FPNK0S93BkqE+zwMf7Td5CLVwwH+13AQSEjUuSz0Qmvw0CCtm9zrn3P9hL69ylB5mwQ/IxZqyqfNH91rKb55EjGUFatgO9wNZA7hJNQGoF66gdzUX2Tf5sHBRt6LDZCN1bYyr+dG6aR53f+kerAQAR9g/PKns+sPrj8vg7OGCcfNQEHSVuy/DgemtlfrOV3J3bbS2JRLCETYCJQx/eKYNyToSdb/IuMcWXXM08YVA8Q6Y0sUQfJvxRL9ItqZ/TUMCdfCOmdgadhqgtRlaf9gr8pLYnyme5flUc6xWqtKxvfyC14HStFZ/r/voHE743K9SciBSwPatg3zZS9Ml3nwYHUZXOq2I/KP2VS0RJT6Gxl4EbRJconl0uA92tR/9alc12/6lH0BYngkJhauJ4XU28eZc09VHqunfqTgg8dZqLb+sMWtdQtuLHEiFweAVXIo2LJGrog9mbQxzX3TlvLHWGyxl9Lw5JvQrnc5Pmh/MCXfPYYIXl5nFYhE9RrNKOZq2wxQimw/FfEn0tG7GCCIfYctnt0w8Mi1Am4MxayzRySqu9684gH2Owr0lPGZmOgynWKuStJBQK20Wpz+DdqHzI+YoKCCnt9sCf9Hpc49EeRmFR/VuVmN3pOmUwSm7kbKUFNzxuGm0Nt1Z0SnB1B1ncdxqrJCNK2Z2+83ngzoW3iQaK6rnE60lwjI+3RVyClqK1O1AwfTOXZsSqM/rK4qe+iL2HsFRDV1/c72eGyVH6bdpuBVdznnuhK1Mth0Gr3R+PcQLb2uWnnNWIryu5I9kf2fbVfEaUBGFGHmEIbSfc5ZKmSbQz1KAFGYbKAtJnE5fRCdmeyd2I/32dNlE+XLp1iEJ+aO6F5et6xx/uY9pVYotBFkJZFBwrT0xNGBxzsxjnuU8mTgXePps3d2KgTuQIvwd4aSiT61ph7Hc0ct1V73vjuWLg6KbdxGr2fkMgnhseP13JOL35h8gc7E7W8F2RIqOl+DGX5tOllxFcQbsBAbpIiXaZc1HWQDElzrXGTYq06QPDS5stmKNgjyc9vfm+Z5MJbrEgRHu1EEMADIwMB9KjotjoOF0GfE65lFURXo8okBoAtbF02GBx4Q8pqOr4ZvGmp7089O8gKgElla+NLcIP+HKZnJCNeW5elavG4KDgjFUu3A5wyWqD7wulZdx/GzxMJXJSWq45XtITwI925MxuY3LF97Py6nguoQSfHfwO4IoOPoXzstActHv9ULRf1iWkqOMrWa8+oGuZcqf40UGq+d/m2ZZuLCMTzbEPR1kl66R0CMkEZDaopeXbkXVAASdtEOJii4ea8zuA9tS5h+b9UrQgoUyPWjiZDOiREPuEcNKyccW5a+DLZ5wHOIlUQNgXpzj7GIKhZADt/u8bCCKfQs1TXxr78SnTl41StMqBdkPGQ0pnpOD9MHS/vOYs7O1ZTAZH4M4MiEV7hiqYpWVz+AllCZI/1vpkmUUrmUV+2JhDLOUOQNiT4DZY6ofaytHzX9rl98oizKYvRPjuc9eeWKJcJV7cT1oIinwym0YTpipfoHVIc3BCTMtCi082pwll6uFxYJlG+A73Rckn+r51EZkclg8+7jVdGxrnRqO6ia+9qE5coCtv2PH7E9x1iTGZKGQeWilTbq6t9XycUr0BIM5OfsSlSbKKWpwgm85xbytGScLgj5un42Ns3PJPTMAxRscekjKysUEzhR8yzOIYf1jUlJ73AHzc1qG4rSepRQjYoMR1KNSuKpGuugHRAh6auIbJ287yLvz/JXjOIcEEiP4L407lya/unDZmBt71R2MpREzHcyQBSLwlyL2qFKfjFSA/9Ut/+KiPH5R9PgjcR4gQXRCQXgD6k6MUaL+Mj+BJ3REM9hu9rjGq6C+U5KR4KcvfzjJhsMqi2LLJJnXOmgkyp0RFDtFxDG5o2fgizQ+0vAUC81XxXPajX+uVHT5uTaaVZoiKTqQa9kXoQG2YY89NUs9XZ/wer6IupIFjFEyoCxQ1xFUpSjH/NYkXmCNohUDURW/jBdVk3Z5JF1+esRMLeTlitnyFhr6W5eXRIIjTCtzmNjX3kIc8yO2dEx4Sg4OxU+xmFuEPuUXS6xeT3wYzH8SLHJh3OJqdKZ01HIi/75gm1d/cHguqA403ycIHUivGFmB5DJlatSTYBLZzHgxfiYZ53eHdxiue1LfhsFc9YDr/YJXZUcY0x6C1OlaUvjE2bYobZwCc2UxMzjaG3LQncjSMyJYID96rmkGT16AL8y0kKO1Qi/NSc2B7qduhUWm2jLrIqyUxBZ7VQCpgQP47ns+rqRBa5JK8PJ8GklikOqNeAZ4zU+3lsIAe7NTVBMVXcjotjhWt+M7VCHWpsSzM7aKpIO84hZmBhN7c29iLeL8IJTwEQa6mzKhBi77un8Amxo69V2BBRaYNC90zAIKIxDqDvYhssTvbHoRq7ekaF+mO3NcDz3tjNZzeee1ORmqf+4XJyqM/ABYrz2K2BtHZxzwxfahKF/6FL79pVvuhD+TG0zmj3r6A8UFK0Z8a9Tpi6IPJk6zu4ivyRV+ixV6uFxL1yZUWbZ0JaNtl0rLjoGmSWxBN76EQoGvLhrJNIdKMiQ24/oZAJd3NEkgVo3kQObEX9eUzjtQUksIxdttDqN8TTKKYseUtxLnLTX5hp6GRoN0wSFdpTTp1C6GazupwlgWfxskQOTCZxXSFyyIIUYmd0NHTBx+kwZJqYy6Sck2qQgMKxJvDI60xBecgclFgO44UQGOTVDWmgblsajnNgNj+slkkqOTo6M/VZ9RDOvmjJpHtIJz/EAxdHdvNN0TqO6kVa2tr68n902rMplnQAmd6AipwA4Jsy8PomhPnAKDt8KV7vPLLEJoyzeCnPmBFQh3+W234vg3BjwewRT+Dc8/I8zTKFSoRcp/6x2Minlbo7Z/7Lpg3N1AC9O2vEopHOi0JoWVnhZMmojaoBQFNg+2fRJEqVYBR9Ce6rx/Ng2nARoglS7hucHlM9TMbmRFxrRL78JoBY7pIhWPe0YYVwAqzapGGY3uAmL9xEgn7ghZLcdSFx0CFJv8TGlFseGGjqtVPs/rLYk1oqZ0kcS2dSPylvhfP8v1oom++0uZQ0ejB7ln3W3nWzwWWEp21k6oPhCTvTXjnlREUmwnhnMLG71RhN7Nm2hqQj7470DOGqbfftPxzVrL7nmmOI4kMKnD6Jm/VVLLr62uTCU67Hj5mSQYgHSuOz0U1pCGERbqY7yWtHtQ8RIgMR4fYW/nqpCheumMDyAei6LXwHW0mEu83OUSfr22O4K8OkmbFO7xVJ6/hJ6NAh6cJZYYCtUkXDs4aIG8nKVdkk6C5iNhuC47AwuMK12UEFSsJ/2RkDMO/4+62DoGS6k1x5+sRYB3x72mj1mip/frgYovWXq1wv0thzv5E9pdGjt2bvBtkaOB4zI4v71rBdG76nPTlkxZx9YerMSRAOvpSpan/3MlhqJaqMOvUcLq4K4eFqvV7C23TjKRItX+zupiIbVHSyjKrbgPPAS/AiZHnzqqRl/I5sgho/8rEwaY+dz262qrLoNBzlh0GRh/u+meN4p5yl+k65KOzGqn2s6vHJ04KJWQPoA90Bqcyi7SQAKuASS9qe3VDxHGGvn6zI9JnB8QTK6gDTqQjOIV5nwktiv55aP4JjioxDOySo/yEtvPSmG9a+r7kEr8p9HNyUtPqswzakCR+5AQsbIZsY+cz1CvZdugMxTjZAgupxIMmXI756xjWATwzYLq6Zvi3W50falqpM47VMWvbI9Xb6f0gNmFY0BPrUjQjDHBI8+G2d/yEZ+DMZpRn7nXXOTlzwYrCe2VxR7mYuXCnwtBBJ2tsqmP85W/NlWeTnFuhLV0LItDMio2e8ubRqP4ahc1FLdRw2Hgyo2Lm6/tDW7NgmICbmLTUjXWhaWFZTq784xVy+xnTYJBaRSPt9mYYkIp9TNKDYZwRHSjU1U8GmHnKVnW3x/xk+XATgFNNgr47jpcrnOjGHX6TLTSmzStU/TIi0xBk1S3FDzB3vfdJkEXrCwf2Xlcu5nGRUlrYDafthyuy5khxEGnYHvuekWneVsC2b0SaI2rv3WM7yHdgVbz+DL8d0GOmLLyCkvetPAJCYr+ddUxqly0FX2oHxbcPMiQG6YaJa78BFk8Q03T2kbfbnDzYYkxQlMliL4mud/KPyRiuPiGLVCm6xMgjqy8xGuiHAalnunTZn4I5MzRyT0EtopKmI/+WXWsxL6Hb997SPKQycwUMETQNurOGt0jxxMQvukKZzTZN4TAD5wt0RNklM+lKCKuc3fALFOPaSdcSOMO1Xjddtf0yDRc5ht3WkIobKBzD5fpx0siRyEiUQogQb5WxGaT/CYk9RpG4h5UyG4HLQ3WFC6/i29NMCkxxlT33OYXdzxVphj6U/VISSMqoCZmB9+fNvXjeo1WHTG0GbhwsDyb10pG7E8u9oagVm7rniKUrVYZCj1waWwpOeWB/P317L5Yc3mk8CuiI8/7dlIK9o62WbXfD+02qMWikEkDoAhqK6QWnLkyyjvDd1amS5ateFzTl/TPZOLPyHrByiOPKRXUKiiCiNR+5+DpTGv13KP15vdUCJiZejX3Ykl+G7otCp3mfBouTp0X5wcz3Z2EmqFyW3WW+kT/S5p9EWFU4X3kKuXHzqpInFipTS+jr4qYOVlinuSkI8rFaCwQ4Sr2zHnPaCKuLwbyjlku7eV6rTceHKhhMjcgk6pnBu+iB8RSyhDpcownMtT1XPIV7hG5VYkvH5+1bceuXa5muYyslPhP+y6fTMPHt1wKqZjZSwmmw/a4dEZaeKzTT/HCF1VQH3I39Sq1Xj41pZ/RBWfjPr/4QLdts3WuWE+ALmvpvfWC+BVL2me5IVk5UWA1oyWAvs4+gSH1XDUXTTmlm7SxfeuXAYTvKJbWMNmSPzoMwzb4jZpQ9FV+DqSDpgjkMkti9BFsymB7nnbMcd/RaPUI7eTqcic61Gmv8SiKODr91+jR47NMbr6relAgtu8LP/NthFBKGeidtsXzrB2XKYAMu3DbL/vVPdn9cvNJI4I0o1XuuqKaOqlLFIOCpgdKBadA2Rh+1OjSPlxjpl4tIpT/JzGxjJ7UKA0+p1kuHazuJxSMUBMHw6YSPhcaY7NPkjyeeK8UknvJUEO15ihIFDDsiTXbk4SJV9B2KtAlEcYCCHQcQLIx5jlo+3LY646p1AcabaHcaJWX7yDPAwJzW22QU8+eVdnJKcF0OCisWecZf+1U5U0GPYUrlMEjju7MP/Au7aYDwLY/G8wmPePPVVgZXa8j+SL3d0mF0ErGmedo3KQ+dSq8Qz+e2D8QOmb/vPbN1MrSfYWc6Se21CTNuRoXrkgNQ4zC60ZvsxXSjdwm/kMr+uKutSttrpXlgAbAcNBh6rYE/n0NOP8g4Pd1Z1PXKyOvlpIZL+qd1ucKMGSZf8LGk2kxMTHz1r6LrKfQMaZrUOkCD7E+8IBJfM6td1k1yef2xMz5FtOoiFA0Fddf8R3KjcHFo3FjG9WF2Q75kO2JwoFC+3qTZFfUgAU7i8gOdT/lIjU1YE3/hruJW670zDouZE5T39F+x/y5w5s0HmkTSANqOf8rLbJCjCvD256rVk+xD6QIxF2eWi75Shnip0IFUmZbf2EibedjfrpGIXG5mReY0ymiA2dXGE/V4KxgIkFnHLvuVdfGR8OjWrSeU3e7yHvhOqwaU1p819oqgoe1tXPyX+WKMA9aU+cwmR7Xp20OztoF+CWFjCHsArW6T4GjAxW9IN2RZm/0rwt3RpdkRjCKc0/W6rZvDzASYbqS/SE7i5qP1tdA0KYjU3hZNngVWXubNOOoNrgNtKGq2Kk/pEbGe9f8W1KYrOHX4i0tox31HwpD4cH+G4Bp47PYrrzFRQONUUY5iaSGY8E5QlL8tbrTy1IDOgKkoDIeLExpDb2r/hXv33EydaLeWUGw7AE3zRioxXqcpA67KxSYQF9TMP+EWOBVuNGOn3aSVpwi+bOmEfgkMdOTMgh0f/GCqtiP1Rn+z2NtQPY7LeV+HbxiDblB4IShF3ADe+ZaWgctUD2OkVN2woiErizbVX3VvEGYbKGuUScFMYln5k12xrXTzPaC2CiJugy5FZarCKfc5bMYGxr4qJNjkwbyMjr/fY0T8lNPvGNwmwyVIFBKGJwE/3RPXL+Pq8s1/F6Ny5h5/OovNSUL3RT7NyC7i4kO0Xn16c6RzEPpGxdwN8EZE2Gp+2p3RX6OeNAv4YWpuxKgv+2eu2rg2kubcvdQYkkM4OBK1iVDCrvZfSXmC5+EuX16uEAd5Eu5wpFc9dkXQODO6hAUXOmkZOE1EP+rRwISkRwVXDNTbVjcabqAT03Xoqpm9E7RIf98k+tyhjgB6bHI+qOMLSN4TEMOCrgUYdzWVGhPhbI2jVS1GrRusJlah/ynU1eVLLC9t9k6ATuGNaBbFiB8d34e0JYRr24yPcP+LFcCcOIxTSg7rP58k4iuc412x0kpMR1mDISUX4SSd1HNn9C0xGkUD5mSNMUTs8QmI8ZZbxWPzLbyIqXpV8yU0HOh2rHPHcI+J/47YoCH8Z7kbv1u06KvcgOZqKMKeUKc5PcxUXcXKBxVaXum6xenP6GaOGMeJdP4Y6cNMPBLX8S3ClQmGNLhz9DGGC2+Wy8cElX3tYsHl9zchedccU1OjGbmDd0CuliNm2VMax01yKQrSDlFBDXPfdzimujSsjtmgSUwcfwagBAacw7dqwxFFgAZg4V2oUHJL8ZbdnnYp9MOFsPjguaqltICdhdP09g1BJUkerfIhSa8U94VJEwPZIqlkK1xHzFrNLQR/dlGlUeV770Mx5zSBTOsDRTjx5bpEjBlfz6z78bEd2K9algmRwZEOi+qbiPlf/gHr/cUInmqAlnzFUBtJ50J4iczj8mMCbD8NaH2IX2i3vVwEeDlIjCp0RryUY5GpShNj1OUP5D2Mx/1uPM0PjmPJVyrF01XE9rGOHEcnHcWpiTdmOkD6wE3ROdhFg+wmL+gAONFt+Hq0vVsOWMi4vvC5QDzx3fJNXw2fzWJBKV6alb1+5IKBfzA47PcHiBP80mbhyeFHc6F7xCmyS7LNCz6+Gfe1NK1MtkCsPxCqSg7SrymFi5XKRwc4grJM/VmWJkf+1gVmx/QQgAYJp+IPf6nWpdB4SDpjtXbsqV/QIoYaKv5zkOuIKvYXSCGkybPcNpeOsz93rGZj9n54a9QND+T7yVNn0Hvmq3xRYMAySe36PxEwWmZutryuK79Oi76C61FM1GbbzQPZTzl6Xkfqup8sTmNm2cv1d1mBFPDfpGiTlONo7ZuDzyXpdsUZR4mtRVJ987cvl2vJzGO2MhHidOIW9BVI75s9uJiIrC+/dS6w3m3msbQF0vyk6uIgwlZ35VnmM90KaYN9pnC1ypLOIlYyFX/e2NH2xGKqieYIMj3GWbDmvj1Mzw1UU3QhYY0fZXYgOob77cuvujE8Pv+GZwll775ttmDiUNuhemHdGmepTFLW7dCGq692rFKQzsmHH5EFOvCp+uWZY39fW64eubHHVrp5z9HrnoZQd+gpghWFOFIJmohvXYhFx6vLqeE0B9ZUkxU0wbiQRXfMOz93B5SARCxb1coZ6pcDZLVsNBHFmMOxQTOutdqB/DLd7Egia21b3YcF/nncTjsjFHpukFB1OPdRzUL80o8/8PHbXz4ZBws2yzQ5G7Au06Me4SnV3MtfIbIQQgBVhP/kGc/tXDAzl9hLr3pitVtIIo00aqbCac771ggKLgYwkcXTdK7r+LzuAWZXSHGRK6P4y6GHuW1B8BlkMqoF8PdbY2B44kaq0crLHUAODtHedBluFQldaxhLHSyz7tWCMeSsBBiqXkdYZt+OzhW0vAEU1duvzbBmrp3sHM6MXhH2QXI7LjK52Ddyz6v/QMR0SrnsDoWKRqaWkKpr9xovHPqzgBhte2fwhfZOIjOssx+dZWY0bflX+BE6P/Zkja4nROs2p+zLbOMvLIjs4nfYC8TMXK2H7FtH5dSOcR6nrKlN09WJV1sjGCo8+kamT0VjEdmXTUGAeZGcR3dv+TCFhoKRK7Egb2McqYssg46LMQLBsAp9VWa9kbNExhEDHo2KxjwqUltleCG/yOncNwSpfeEI4Kn9YPyWIeqsRfPatdwN5X/QX693g512jthlsuZR2YslXqjmORD5U2lv1PlgG8rdBPwOTOGMs8s2MwpE+mhp2O4vybu/CtxZBslURCot5GIoWA5vv2crF+w+RjMxVvO/+Bj2N5U0cicYvd7D5x83/nYlqzCGnstByKu5BIOB63ZYHPBAs528JpktcAh4nnoluTgJNbxaQQhVxDaXvN1DWEA70K8Qt+uPXRsui768CFuvFNxGY2WMAU14+77/lTK3BOfVzjjfFMNhQGNkeuvj3IQk42nDKfGq9DGb+S1V31KXNqNqFw2xkJHlE3TcfCUc248qA3+Lq3rK8+CqohjnLs+YXLT9bUs/0t/XjJ9/X5/BYPE+kFFdWo8ItcoWDVW+WHp2ffhDDcu0c8RMogfAVsa+xWpOW7IzKtU3CzbsBJfcJZal8z/2BzR+HznjNzF4K+cdpB+UNZDNI5NgZoktb0ucUahOnpXR7LJGt38YmDlRxduaZWO4ui7U/N3i7cX4K6n9mDSK9L2Ohf2ewj8BTtwe2pIfLewEHnnt9b+ZcDNsBgryXVotbKbTf4rUTbPl++KJ2IFrp0qB+tA5mEmOV7LTdP0irPSmKqu0ERpbXuh/FzO09mjCJvkGq7c+PplKOlMuGSrMXeIvTNKBTfo5v3yC3x780LMAnBkn8WEeTGJeQibluWR/XpW7mGfeFtSPwkUhpj/SKN+9zXXVu62nmPrL/FStcrad6M4AmGnsG4rZplBmFgq/egPuZB6PrUHnh1EJXzJkhFYedJMCwelVG/DKMwMNLEwTpEE6G4dwnYuKoB031U0yVYZveUQLdEYmIaHte4weSyiXQEML+hBwvh0rmqiZhbfWmQAbb8Tt+Eb6pnKvW2pOcg/Qa5ZdKkQ9Hr2XbDkbwVzNJMwDiQOOKK/ZRoBeNY0rAgNHRMgAfZFzRZuwewe8d+YOYjkOXLGxrkJQVAMIwHXVDlAZVsJybf42M++/iIYXy1J2bW7s4OjAcS6OrWA3OCmj2zQ5NWxWpccKks/ia0lVD5hqUskMfgS5IFX7ZqJq6kNSYWGfBqzifFe44zluWmiC10Y+UMTzK9b2OVgrPK3OmXC7XguJwPLYKWuijfQoI144z58SasWSQl8Fjm6NWPszKtU4zRh6xRuLOkTB6gLxNLLgk3tKt1Wf4wCS1PJotoSBASggRCAkP3ZFFlRG+OUHP/ii+yiTOnG99hd1Xi10EYuvaoZdupxLY43UejyF06LVAzRVBTkqvroCpzxgWtO3j+R6pnk6fWCeFSXntaduplQRXnCJDekfrst58TP5SoAsNNEmYEl6tA6O0s67aatBsSUWipOCY2fCthumRdbxYRpaBWP1OvGYMYsWsbWJiPDBkI5z3nza7NSaB9ZWF00ujCEyxeaEE97thxIPjUicqcLHI0s8+jv46FBxtvHQxnKunadwBL45bUsAyaabSCBrIalOxyq+7mN/CniX1VKEjxy4d5bmnR58S2ayzu0fvF3nEoPUKJSMtqNhGS2ZInb7uj8MBGgY3TCYm+2aGjAf6tjSnmkdTZVyXE9P6rE4Kn32AJ8dOLAMUYkcq+PbfKJvRq5F2Tetjpg2WBQ2OgDTRFkX8c5Ut2cIHAx+n8Q3GT5Yt+omBUaf2sQw==</Value></TokenEntry></Values></UseKey><Claims><Values xmlns:q1=\"http://schemas.xmlsoap.org/ws/2004/04/security/trust\" soapenc:arrayType=\"q1:TokenEntry[17]\"><TokenEntry><Name>SessionKey</Name><Value>uHBj7mNfx54QXwSlx29X4BV0QHs+WQjOTt3/bC1Y35fnSWpMAEx0UWjuEAe8W99gkEdyVZJtDwvnjdZjt/1H1E6HY8OyHBnVgME+eJx5WKEO8GqKASmBGRl2TwJy4g17yvDsN5Fs4RfLxF5INsPu3s88qeJrAUOyYb5YA60I0f/N971irOAZE4WyjZXKJzozk4w+7FfhfephTfZojLOGMNp06KTJlnVqtQkE3fhfsZB+GLeRizhO5tFMODZllFjjsBKrFsMKpoFxHst6EvRvrgMPnz1laaZG7KJt4ncaCaXW/tWspdjzUUZKS5hUEpbwGEazQMA4q7NzENGqK1trfg==</Value></TokenEntry><TokenEntry><Name>BindingType</Name><Value>KPANBekX5ZqfaES093W068d41ru7Afy35FwJwS9EgS4=</Value></TokenEntry><TokenEntry><Name>Binding</Name><Value>u5isq6QfbLfcVglX2yG8unxJDyooJJILridy3f5AmxbMdGIENMOFTTDqojWJUcj1zeDyDY2z8ECDRKspPGltKeZCyESt2uk+jmpRPOiH3Q8=</Value></TokenEntry><TokenEntry><Name>ProductKey</Name><Value>gIVMS4BtYFTjFI8Fj4//in1CFVTxGUAIbuevy4zC+5M=</Value></TokenEntry><TokenEntry><Name>ProductKeyType</Name><Value>KPANBekX5ZqfaES093W064XICt0sbhcAdyEe49DzAh8=</Value></TokenEntry><TokenEntry><Name>ProductKeyActConfigId</Name><Value>cL1TFfsO04qoucXxpvCjZgAHDxNzKjBPbSLO56hhWSGNKfKgpefIGZq3m8W7HfkKeuqfFin7qFUKE/VAXcgQhfHcymcKVNZwqi+aWRN+mF4=</Value></TokenEntry><TokenEntry><Name>SppSvcVersion</Name><Value>VijVCeJDeAgyLBxU8RhzPQ==</Value></TokenEntry><TokenEntry><Name>otherInfoPublic.licenseCategory</Name><Value>2WicPaigFS+gMNKWQUVldN42uNVsVc/TNlB/i1pl288=</Value></TokenEntry><TokenEntry><Name>otherInfoPrivate.licenseCategory</Name><Value>2WicPaigFS+gMNKWQUVldLNjvZxg+ltMeb2ZhfB6TOE=</Value></TokenEntry><TokenEntry><Name>otherInfoPublic.sysprepAction</Name><Value>XZQaWleVvueSqSND+f8e1Q==</Value></TokenEntry><TokenEntry><Name>otherInfoPrivate.sysprepAction</Name><Value>XZQaWleVvueSqSND+f8e1Q==</Value></TokenEntry><TokenEntry><Name>ClientInformation</Name><Value>/f3yo96P+FJcw8TzvFc4+bgG2bRRMCMamxrF188eYYW4QICavdiEcsqW4qGPxkEPD8YIRMyCugad/uOy152Zdw==</Value></TokenEntry><TokenEntry><Name>ReferralInformation</Name><Value>DzaLfpCiDEgpdBmSHkR1WembpQ6n2ZbUKCRGnyjiNsiTFAZHqj5n3N6Syo/KLdnDX2tCYobSFiZk6SIe9EwqEg==</Value></TokenEntry><TokenEntry><Name>ClientSystemTime</Name><Value>SQx02I0rvwVE63YKuGmWGO5OByrr5xz5ZWnVvrO+2Qg=</Value></TokenEntry><TokenEntry><Name>ClientSystemTimeUtc</Name><Value>SQx02I0rvwVE63YKuGmWGO5OByrr5xz5ZWnVvrO+2Qg=</Value></TokenEntry><TokenEntry><Name>otherInfoPublic.secureStoreId</Name><Value>idUbrZox6cCjUQ4THgEVckaOXyaI1Y9dBPdfycohwCFGYgJbfgOVwqcVd3sq1QfF</Value></TokenEntry><TokenEntry><Name>otherInfoPrivate.secureStoreId</Name><Value>idUbrZox6cCjUQ4THgEVckaOXyaI1Y9dBPdfycohwCFGYgJbfgOVwqcVd3sq1QfF</Value></TokenEntry></Values></Claims></RequestSecurityToken></soap:Body></soap:Envelope>)\r\n00010002(0x80072EE7, 09:48:32:181 - <NULL>)\r\n00010003(0x80072EE7, 09:48:32:181)\r\n"
    ]
  },
  "message": "License acquisition failure details. \nhr=0x80072EE7"
}

Event ID 8200: License acquisition failure details

#
Channel
Operational
Level
2

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 8200,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T17:06:29.4813457+00:00",
    "event_record_id": 210,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-MEM-c.cell-c.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "hr=0x80072EFE",
    "Data_1": "00010001(0x00000000, 17:06:29:340 - https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx)\n00020001(0x00000000, 17:06:29:340)\n00030001(0x00000000, 17:06:29:340 - https://validation-v2.sls.microsoft.com)\n00030002(0x00000000, 17:06:29:340 - 0)\n00040001(0x00000000, 17:06:29:340 - https://validation-v2.sls.microsoft.com)\n00040002(0x00000000, 17:06:29:340 - 1, <NULL>, <NULL>, <NULL>)\n00050002(0x80072F94, 17:06:29:340 - 0, 1)\n00040006(0x00000001, 17:06:29:340 - 0, https://validation-v2.sls.microsoft.com, <N/A>, <N/A>)\n00020005(0x00000000, 17:06:29:340 - 0)\n00020009(0x80072EFE, 17:06:29:481)\n00010002(0x80072EFE, 17:06:29:481 - <NULL>)\n00010003(0x80072EFE, 17:06:29:481)\n"
  },
  "message": "License acquisition failure details. \r\nhr=0x80072EFE"
}

Event ID 8205: Token Store found to be corrupt

#
Channel
Operational

Event ID 8206: Token Store not found

#
Channel
Operational

Event ID 8208: Acquisition of genuine ticket failed (%1) for template Id

#
Channel
Operational

Event ID 8209: Genuine state set to non-genuine (%1) for application Id

#
Channel
Operational

Event ID 8210: Update current edition product key id failed with

#
Channel
Operational

Event ID 8211: Update Windows license and product key tokens failed with

#
Channel
Operational

Event ID 8212: Rearm failed for AppId = %2, SkuId = %3 - %4 Rearms Remaining

#
Channel
Operational

Event ID 8213: Activation Object cannot be retrieved from Active Directory

#
Channel
Operational

Event ID 8214: Active Directory Activation Object is not usable

#
Channel
Operational

Event ID 8215: Active Directory Activation has failed

#
Channel
Operational

Event ID 8216: HCI Marker has failed verification

#
Channel
Operational

Event ID 8217: HCI Marker has bad data

#
Channel
Operational

Event ID 8218: Failed ot retrieve HCI Marker

#
Channel
Operational

Event ID 8219: OEM OA Binding failed

#
Channel
Operational

Event ID 8220: OEM OA Binding extraction failed

#
Channel
Operational

Event ID 8221: OEM OA Binding decode failed

#
Channel
Operational

Event ID 8224: Existing scheduler data could not be found

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 8224,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-17T19:23:13.3319555+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 8225: The existing scheduler data does not match the expected data

#
Channel
Operational

Event ID 8226: The existing scheduler data is incomplete

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 8226,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-17T18:18:11.7914315+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 8227: The existing schedule data is expired

#
Channel
Operational

Event ID 8228: The rules engine failed to evaluate the rules

#
Channel
Operational

Event ID 8229: The rules engine failed to perform one or more scheduled actions

#
Channel
Operational

Event ID 8230: The rules engine successfully re-evaluated the schedule.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 8230,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:08.097968+00:00",
    "event_record_id": 1580,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2024/02/03:22:33:07;LastConsumptionReason=0x4004fc04;LastNotificationId=Cleanup;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=YG9R6;ProductKeyType=Retail:TB:Eval;SkuId=3f4c0546-36c6-46a8-a37f-be13cdd0cf25;ruleId=379cccfb-d4e0-48fe-b0f2-0136097be147;uxDifferentiator=TIMEBASED_EVAL"
    ]
  },
  "message": "The rules engine successfully re-evaluated the schedule.\nKernel policies:\nSecurity-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2024/02/03:22:33:07;LastConsumptionReason=0x4004fc04;LastNotificationId=Cleanup;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=YG9R6;ProductKeyType=Retail:TB:Eval;SkuId=3f4c0546-36c6-46a8-a37f-be13cdd0cf25;ruleId=379cccfb-d4e0-48fe-b0f2-0136097be147;uxDifferentiator=TIMEBASED_EVAL"
}

Event ID 8230: The rules engine successfully re-evaluated the schedule

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 8230,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T05:39:31.8594469+00:00",
    "event_record_id": 762,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2026/06/29:19:33:31;LastConsumptionReason=0x4004fc04;LastNotificationId=TBLExpiring;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=W8JDY;ProductKeyType=Retail:TB:Eval;SkuId=c1a197b6-ba5e-4394-b9bf-b659a6c1b873;ruleId=17fd3d63-7be4-49b1-8d16-2e0fe9fddbc2;uxDifferentiator=TIMEBASED_EVAL"
  },
  "message": "The rules engine successfully re-evaluated the schedule.\r\nKernel policies:\r\nSecurity-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2026/06/29:19:33:31;LastConsumptionReason=0x4004fc04;LastNotificationId=TBLExpiring;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=W8JDY;ProductKeyType=Retail:TB:Eval;SkuId=c1a197b6-ba5e-4394-b9bf-b659a6c1b873;ruleId=17fd3d63-7be4-49b1-8d16-2e0fe9fddbc2;uxDifferentiator=TIMEBASED_EVAL"
}

Event ID 8231: The rules engine gathered the following context data:

#
Channel
Operational

Event ID 8232: The rules engine failed while trying to update the task triggers with code

#
Channel
Operational

Event ID 8233: The rules engine reported a failed VL activation attempt

#
Channel
Application
Level
Warning

Fields #

NameDescription
Data_0
Data_1
Data_2
Data_3
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 8233,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-14T16:35:02.726112+00:00",
    "event_record_id": 37618,
    "correlation": {},
    "execution": {
      "process_id": 4876,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "0x8007232B",
    "Data_1": "0ff1ce15-a989-479d-af46-f275c6370663",
    "Data_2": "8d368fc1-9470-4be2-8d66-90e836cbb051",
    "Data_3": "TimerEvent",
    "Binary": ""
  },
  "message": ""
}

Event ID 8233: The rules engine reported a failed VL activation attempt

#
Channel
Operational
Level
3

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 8233,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:09:09.4521862+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "TimerEvent"
  }
}

Example keys not documented in the fields table: Data

Event ID 12288: The client has sent an activation request to the key management service machine

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 12288,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-14T18:35:26.643586+00:00",
    "event_record_id": 37766,
    "correlation": {},
    "execution": {
      "process_id": 4876,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "0xC0020017, 0x00000000, 10.20.24.1:1688, de742801-ad82-4fd6-b3a9-902fc671156d, 2026/03/14 18:35, 0, 2, 43080, 8d368fc1-9470-4be2-8d66-90e836cbb051, 5",
    "Binary": "00000600E74197F2BB2CFC7793C7F21C8A4B574088A8A9517480442EDB2FBBC33D6C70F959A1FE7F742DC82A2E72C2D45007877239A0AB652E09D813E51E0C2178CF69959CBBD70D91AD06B18034FB251AEDDD4A5CC91CD0D47C9A4D009FCBC65D5720CA8A6F052236A1CD6C0E2008DE1DF8B04AAF41A0A3925751E70F8C8DD9F3EBCFF51DF2371358838DD58E57B0865917325242738ECF89B3A83057A1E69D68928F074AFDF6EF36C00B90C78B1D3CB2F169BE4F70B8100682485ED43BC128B68D231A15E6D72F4F9878E44B084E26AC97EE5A999946E2AD109D53B3600CD43E246F9604EF53743342F7A632BF4D701E452643539A4B207D675623F9F868581DC50A63"
  },
  "message": ""
}

Event ID 12288: The client has sent an activation request to the key management service machine

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 12288,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-30T01:23:50.3899408+00:00",
    "event_record_id": 210762,
    "correlation": {},
    "execution": {
      "process_id": 5672,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "0xC0020017, 0x00000000, 10.20.24.1:1688, e5291a3a-66ad-4616-bc3a-65d56e7ed9b6, 2026/05/30 01:23, 0, 5, 0, fa187091-8246-47b1-964f-80a0b1e5d69a, 5"
  },
  "message": "The client has sent an activation request to the key management service machine.\r\nInfo:\r\n0xC0020017, 0x00000000, 10.20.24.1:1688, e5291a3a-66ad-4616-bc3a-65d56e7ed9b6, 2026/05/30 01:23, 0, 5, 0, fa187091-8246-47b1-964f-80a0b1e5d69a, 5"
}

Event ID 12289: The client has processed an activation response from the key management service machine

#
Channel
Operational

Event ID 12290: An activation request has been processed

#
Channel
Operational

Event ID 12291: Key Management Service (KMS) failed to start

#
Channel
Operational

Event ID 12293: Publishing the Key Management Service (KMS) to DNS in the '%2' domain failed

#
Channel
Operational

Event ID 12294: Publishing the Key Management Service (KMS) to DNS in the '%1' domain is successful

#
Channel
Operational

Event ID 12295: Secure KMS initialization failed with code %1 at stage

#
Channel
Operational

Event ID 12296: Secure KMS initialization succeeded

#
Channel
Operational

Event ID 12304: Successfully acquired genuine ticket for template Id {99d92734-d682-4d71-983e-d6ec3f16059f}

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 12304,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:05.418976+00:00",
    "event_record_id": 1570,
    "correlation": {},
    "execution": {
      "process_id": 5592,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "{99d92734-d682-4d71-983e-d6ec3f16059f}"
    ]
  },
  "message": "Successfully acquired genuine ticket for template Id {99d92734-d682-4d71-983e-d6ec3f16059f}"
}

Event ID 12304: Successfully acquired genuine ticket for template Id

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 12304,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:15.6747598+00:00",
    "event_record_id": 221,
    "correlation": {},
    "execution": {
      "process_id": 4256,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "{99d92734-d682-4d71-983e-d6ec3f16059f}"
  },
  "message": "Successfully acquired genuine ticket for template Id {99d92734-d682-4d71-983e-d6ec3f16059f}"
}

Event ID 12305: Genuine state set to genuine for application Id 55c92734-d682-4d71-983e-d6ec3f16059f

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 12305,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:05.415418+00:00",
    "event_record_id": 1569,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "55c92734-d682-4d71-983e-d6ec3f16059f"
    ]
  },
  "message": "Genuine state set to genuine for application Id 55c92734-d682-4d71-983e-d6ec3f16059f"
}

Event ID 12305: Genuine state set to genuine for application Id

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 12305,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:15.6716780+00:00",
    "event_record_id": 220,
    "correlation": {},
    "execution": {
      "process_id": 3904,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "55c92734-d682-4d71-983e-d6ec3f16059f"
  },
  "message": "Genuine state set to genuine for application Id 55c92734-d682-4d71-983e-d6ec3f16059f"
}

Event ID 12306: Rearm successful for AppId = 55c92734-d682-4d71-983e-d6ec3f16059f, SkuId = (null) - 1 Rearms Remaining.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 12306,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-10-25T22:55:35.790597+00:00",
    "event_record_id": 1424,
    "correlation": {},
    "execution": {
      "process_id": 4244,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDevEval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "55c92734-d682-4d71-983e-d6ec3f16059f",
      "(null)",
      "1"
    ]
  },
  "message": "Rearm successful for AppId = 55c92734-d682-4d71-983e-d6ec3f16059f, SkuId = (null) - 1 Rearms Remaining."
}

Event ID 12306: Rearm successful for AppId = Data_0, SkuId = Data_1 - Data_2 Rearms Remaining

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1
Data_2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 12306,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T17:00:42.5993490+00:00",
    "event_record_id": 187,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-MEM-c",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "55c92734-d682-4d71-983e-d6ec3f16059f",
    "Data_1": "(null)",
    "Data_2": "5"
  },
  "message": "Rearm successful for AppId = 55c92734-d682-4d71-983e-d6ec3f16059f, SkuId = (null) - 5 Rearms Remaining."
}

Event ID 12307: Skipped Rearm for AppId = 55c92734-d682-4d71-983e-d6ec3f16059f, SkuId = (null).

#
Channel
Application
Level
4

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 12307,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 21:09:27.309595+00:00",
    "event_record_id": 143,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "EX-SUBCA",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>55c92734-d682-4d71-983e-d6ec3f16059f</string>\n<string>(null)</string>\n",
    "Binary": ""
  },
  "message": "Skipped Rearm for AppId = 55c92734-d682-4d71-983e-d6ec3f16059f, SkuId = (null)."
}

Event ID 12307: Skipped Rearm for AppId = %1, SkuId =

#
Channel
Operational

Event ID 12308: Active Directory Activation has succeeded

#
Channel
Operational

Event ID 12309: The client has processed an Automatic VM activation response from the parent partition

#
Channel
Operational

Event ID 12310: An Automatic VM activation request has been processed

#
Channel
Operational

Event ID 12311: The MSA client has been successfully triggered to update the Device License

#
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 12311,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:06.265666+00:00",
    "event_record_id": 1571,
    "correlation": {},
    "execution": {
      "process_id": 5592,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The MSA client has been successfully triggered to update the Device License"
}

Event ID 12311: The MSA client has been successfully triggered to update the Device License

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 12311,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:16.1459583+00:00",
    "event_record_id": 222,
    "correlation": {},
    "execution": {
      "process_id": 4256,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The MSA client has been successfully triggered to update the Device License"
}

Event ID 12320: Token-based Activation has succeeded

#
Channel
Operational

Event ID 12322: Failed to deposit Token-based Activation response

#
Channel
Operational

Event ID 16384: Successfully scheduled Software Protection service for re-start at 2024-01-04T22:32:56Z.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 16384,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T23:02:57.838854+00:00",
    "event_record_id": 1612,
    "correlation": {},
    "execution": {
      "process_id": 6932,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "2024-01-04T22:32:56Z",
      "RulesEngine"
    ]
  },
  "message": "Successfully scheduled Software Protection service for re-start at 2024-01-04T22:32:56Z. Reason: RulesEngine."
}

Event ID 16384: Successfully scheduled Software Protection service for re-start at

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 16384,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T13:52:57.3101421+00:00",
    "event_record_id": 812,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "2026-06-14T05:38:57Z",
    "Data_1": "RulesEngine"
  },
  "message": "Successfully scheduled Software Protection service for re-start at 2026-06-14T05:38:57Z. Reason: RulesEngine."
}

Event ID 16385: Failed to schedule Software Protection service for re-start at

#
Channel
Operational

Event ID 16386: Successfully started task %1\

#
Channel
Operational

Event ID 16387: Failed to run task %2\

#
Channel
Operational

Event ID 16388: The current time is 2023-11-05T22:33:07Z : 2023-11-05T22:33:07Z.

#
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 16388,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:07.912565+00:00",
    "event_record_id": 1579,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "2023-11-05T22:33:07Z",
      "2023-11-05T22:33:07Z"
    ]
  },
  "message": "The current time is 2023-11-05T22:33:07Z : 2023-11-05T22:33:07Z."
}

Event ID 16388: The current time is Data_0 :

#
Channel
Operational
Level
4

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 16388,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T05:39:31.6250721+00:00",
    "event_record_id": 761,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "2026-06-13T05:39:31Z",
    "Data_1": "2026-06-13T05:39:31Z"
  },
  "message": "The current time is 2026-06-13T05:39:31Z : 2026-06-13T05:39:31Z."
}

Event ID 16389: Grace timer has expired

#
Channel
Operational

Event ID 16390: Updated policy %1 with value of %2 from Clip

#
Channel
Operational

Event ID 16391: Downlevel Genuine Ticket deposit failed

#
Channel
Operational

Event ID 16392: Downlevel consumption failed

#
Channel
Operational

Event ID 16393: Downlevel Migration failed

#
Channel
Operational

Event ID 16394: Offline downlevel migration succeeded.

#
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 16394,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T23:02:25.593242+00:00",
    "event_record_id": 1611,
    "correlation": {},
    "execution": {
      "process_id": 6932,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Offline downlevel migration succeeded."
}

Event ID 16394: Offline downlevel migration succeeded

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 16394,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T13:52:27.1695356+00:00",
    "event_record_id": 811,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Offline downlevel migration succeeded."
}

Event ID 16395: Operation status %2 with return code

#
Channel
Operational

Event ID 16396: You are on an inactivated device

#
Channel
Operational

Event ID 16397: Device is in grace period for %1 minutes more

#
Channel
Operational

Event ID 16398: Error occured during grace period %1 at

#
Channel
Operational

Event ID 20481: Health check initiated.

#
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 20481,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:52.695891+00:00",
    "event_record_id": 1565,
    "correlation": {},
    "execution": {
      "process_id": 7784,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Health check initiated. \n"
}

Event ID 20481: Health check initiated

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 20481,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:14.1131451+00:00",
    "event_record_id": 217,
    "correlation": {},
    "execution": {
      "process_id": 5936,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Health check initiated. \r\n"
}

Event ID 20482: Health check passed.

#
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 20482,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:02.718805+00:00",
    "event_record_id": 1566,
    "correlation": {},
    "execution": {
      "process_id": 7784,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Health check passed. \n"
}

Event ID 20482: Health check passed

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 20482,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:14.7031236+00:00",
    "event_record_id": 218,
    "correlation": {},
    "execution": {
      "process_id": 5936,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Health check passed. \r\n"
}

Event ID 20483: Tamper detected:

#
Channel
Operational

Event ID 20484: Error occurred during Health check:

#
Channel
Operational

Event ID 20485: Genuine validation initiated

#
Channel
Operational

Event ID 20486: Genuine validation result:

#
Channel
Operational

Event ID 20487: Genuine validation failure:

#
Channel
Operational

Event ID 20488: Genuine validation data collection started.

#
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 20488,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:50.825426+00:00",
    "event_record_id": 1564,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Genuine validation data collection started. \n"
}

Event ID 20488: Genuine validation data collection started

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 20488,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:13.3027321+00:00",
    "event_record_id": 216,
    "correlation": {},
    "execution": {
      "process_id": 3904,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Genuine validation data collection started. \r\n"
}

Event ID 20489: Genuine validation data collection ended.

#
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "Software Protection Platform Service",
    "event_id": 20489,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:33:03.750560+00:00",
    "event_record_id": 1568,
    "correlation": {},
    "execution": {
      "process_id": 3740,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Genuine validation data collection ended. \n"
}

Event ID 20489: Genuine validation data collection ended

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "guid": "{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}",
    "event_source_name": "",
    "event_id": 20489,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T20:24:14.9938908+00:00",
    "event_record_id": 219,
    "correlation": {},
    "execution": {
      "process_id": 3904,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Genuine validation data collection ended. \r\n"
}

Event ID 20490: Grace timer initialization failed

#
Channel
Operational

Event ID 20491: Grace timer previously created

#
Channel
Operational

Event ID 20492: Grace period terminated with code

#
Channel
Operational

Event ID 1073742724: The Software Protection service is starting.

#
Channel
Operational
Level
4

Message #

The Software Protection service is starting.
Parameters:%1

Fields #

NameDescription
Parameters

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 900,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T19:34:07.6819053+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "<explicit>"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742726: The Software Protection service has started.

#
Channel
Operational

Message #

The Software Protection service has started.
%1

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 902,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T19:32:02.3691230+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "10.0.26100.6584"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742727: The Software Protection service has stopped.

#
Channel
Operational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 903,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T19:32:32.6322917+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1073742827: The Software Protection service has completed licensing status check.

#
Channel
Operational
Level
4

Message #

The Software Protection service has completed licensing status check.
Application Id=%1
Licensing Status=%2

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1003,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T21:12:29.4552747+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "\n1: 2141d341-41aa-4e45-9ca1-201e117d6495, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n2: 29b4d918-8b78-447b-aa14-8b3b1b3742ae, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n3: 33b11b14-91fd-4f7b-b704-e64a055cf601, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n4: 41ec56c3-e5ea-4094-895f-c4a65a5a8fc6, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]\n5: 4ab4d849-aabc-43fb-87ee-3aed02518891, 1, 0 [(0 [0xC0...[truncated]"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742828: The Software Protection service has successfully installed the license.

#
Channel
Operational
Level
4

Message #

The Software Protection service has successfully installed the license.
License Title=%1
License Id=%2

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1004,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T21:11:58.1090174+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "b9a0fce9-5763-becf-7156-45b629753890"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742831: Acquisition of Secure Processor Certificate was successful.

#
Channel
Operational

Event ID 1073742833: Acquisition of Rights Account Certificate was successful.

#
Channel
Operational

Event ID 1073742835: Acquisition of Product Certificate was successful.

#
Channel
Operational

Message #

Acquisition of Product Certificate was successful.
Sku Id=%1

Fields #

NameDescription
param1

Event ID 1073742837: Acquisition of End User License was successful.

#
Channel
Operational

Message #

Acquisition of End User License was successful.
Sku Id=%1

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1013,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:07.7212186+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Data": "3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742840: Proof of Purchase installed successfully.

#
Channel
Operational
Level
4

Message #

Proof of Purchase installed successfully. 
ACID=%1
PKeyId=%2

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1016,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:09:05.4693612+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "a17e0657-a529-04c4-bd76-3672cdefcf22"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742842: Proof of Purchase removed successfully.

#
Channel
Operational
Level
4

Message #

Proof of Purchase removed successfully. 
ACID=%1
PKeyId=%2

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1018,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-17T18:19:51.5906816+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1073742849: Grace period has been started.

#
Channel
Operational
Level
4

Description

Grace period has been started. Grace days=param1 Grace type=param2.

Message #

Grace period has been started. Grace days=%1  Grace type=%2.

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1025,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:09:05.9487786+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "6"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742857: These policies are being excluded since they are only defined with override-only attribute.

#
Channel
Operational
Level
4

Message #

These policies are being excluded since they are only defined with override-only attribute.
Policy Names=%1
App Id=%2
Sku Id=%3

Fields #

NameDescription
param1
param2
param3

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1033,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T21:22:09.5084081+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742858: Duplicate definition of policy found.

#
Channel
Operational
Level
4

Description

Duplicate definition of policy found. Policy name=param1 Priority=param2.

Message #

Duplicate definition of policy found. Policy name=%1  Priority=%2

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1034,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T21:22:09.5039869+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "100"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742859: A higher priority policy without override-only attribute found.

#
Channel
Operational

Description

A higher priority policy without override-only attribute found. Policy name=param1 Current priority=param2 Previous priority=param3.

Message #

A higher priority policy without override-only attribute found. Policy name=%1  Current priority=%2  Previous priority=%3

Fields #

NameDescription
param1
param2
param3

Event ID 1073742860: Validity period has been started.

#
Channel
Operational
Level
4

Description

Validity period has been started. Validity minutes=param1 Grace type=param2.

Message #

Validity period has been started. Validity minutes=%1  Grace type=%2.

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1036,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-18T00:30:29.8360639+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Data": "9"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742864: Hardware has changed from previous boot.

#
Channel
Operational
Level
4

Message #

Hardware has changed from previous boot.
 AppId=%1, SkuId=%2.

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1040,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:03.7447578+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Binary": "5E0000000A00300000000200030001000100010000000000010001000000962B06668A0A018B52C89ED641E06E22241DF9AF3384C0620D0001000101000201000301000401000500000601000700000801000901000A01000B00000C0100280000000000010001000100010000000000010001000000CA4B381A9ED66E22241DF9AF89F13600",
    "Data": "3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
  }
}

Example keys not documented in the fields table: Binary, Data

Event ID 1073742884: Kernel policy cache has not been updated after Windows Right consumption.

#
Channel
Operational

Description

Kernel policy cache has not been updated after Windows Right consumption. This is OK in certain situations.

Message #

Kernel policy cache has not been updated after Windows Right consumption. This is OK in certain situations.

Event ID 1073742885: Edition changed from param1 to param2 after Windows Right consumption.

#
Channel
Operational

Message #

Edition changed from %1 to %2 after Windows Right consumption.

Fields #

NameDescription
param1
param2

Event ID 1073742890: Initialization status for service objects.

#
Channel
Operational
Level
4

Message #

Initialization status for service objects.
%1

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1066,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T19:32:01.5635078+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "C:\\WINDOWS\\system32\\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000\nC:\\WINDOWS\\system32\\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000\nC:\\WINDOWS\\system32\\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000\nC:\\WINDOWS\\system32\\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000\nC:\\WINDOWS\\system32\\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000\nC:\\WINDOWS\\system32\\sppobjs.dll, msft:spp/TaskScheduler...[truncated]"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073742896: Successfully matched deposited Installation ID with Confirmation ID.

#
Channel
Operational

Message #

Successfully matched deposited Installation ID with Confirmation ID.
Sku Id=%1

Fields #

NameDescription
param1

Event ID 1073750030: Token Store not found.

#
Channel
Operational

Description

Token Store not found. Recreating Token Store.

Message #

Token Store not found. Recreating Token Store.

Event ID 1073750048: Existing scheduler data could not be found.

#
Channel
Operational
Level
4

Description

Existing scheduler data could not be found. The schedule will be re-evaluated.

Message #

Existing scheduler data could not be found.  The schedule will be re-evaluated.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 8224,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-17T19:23:13.3319555+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1073750049: The existing scheduler data does not match the expected data.

#
Channel
Operational

Description

The existing scheduler data does not match the expected data. The schedule will be re-evaluated.

Message #

The existing scheduler data does not match the expected data.  The schedule will be re-evaluated.
Reason:%1

Fields #

NameDescription
Reason

Event ID 1073750050: The existing scheduler data is incomplete.

#
Channel
Operational
Level
4

Description

The existing scheduler data is incomplete. The schedule will be re-evaluated.

Message #

The existing scheduler data is incomplete.  The schedule will be re-evaluated.
Reason:%1

Fields #

NameDescription
Reason

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 8226,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-17T18:18:11.7914315+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1073750051: The existing schedule data is expired.

#
Channel
Operational

Description

The existing schedule data is expired. The schedule will be re-evaluated.

Message #

The existing schedule data is expired.  The schedule will be re-evaluated.
Reason:%1

Fields #

NameDescription
Reason

Event ID 1073750052: The rules engine failed to evaluate the rules.

#
Channel
Operational

Message #

The rules engine failed to evaluate the rules.
Reason:%1
Stage:%2
Additional Data:
%3

Fields #

NameDescription
Reason
Stage
Additional_Data

Event ID 1073750053: The rules engine failed to perform one or more scheduled actions.

#
Channel
Operational

Message #

The rules engine failed to perform one or more scheduled actions.
Error Code:%1
Path:%2
Arguments:%3

Fields #

NameDescription
Error_Code
Path
Arguments

Event ID 1073750054: The rules engine successfully re-evaluated the schedule.

#
Channel
Operational
Level
4

Message #

The rules engine successfully re-evaluated the schedule.
Kernel policies:
%1

Fields #

NameDescription
Kernel_policies

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 8230,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:09:09.1616952+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2026/07/17:00:31:08;LastConsumptionReason=0x4004fc04;LastNotificationId=Cleanup;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=YG9R6;ProductKeyType=Retail:TB:Eval;SkuId=3f4c0546-36c6-46a8-a37f-be13cdd0cf25;ruleId=379cccfb-d4e0-48fe-b0f2-0136097be147;uxDifferentiator=TIMEBASED_EVAL"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073750055: The rules engine gathered the following context data.

#
Channel
Operational

Message #

The rules engine gathered the following context data:
%1

Fields #

NameDescription
The_rules_engine_gathered_the_following_context_data

Event ID 1073750056: The rules engine failed while trying to update the task triggers with code param1.

#
Channel
Operational

Description

The rules engine failed while trying to update the task triggers with code param1. Reevaluation will occur again soon.

Message #

The rules engine failed while trying to update the task triggers with code %1.  Reevaluation will occur again soon.

Fields #

NameDescription
param1

Event ID 1073750057: The rules engine reported a failed VL activation attempt.

#
Channel
Operational
Level
3

Message #

The rules engine reported a failed VL activation attempt.
Reason:%1
AppId = %2, SkuId = %3
Trigger=%4

Fields #

NameDescription
Reason

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 8233,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:09:09.4521862+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "TimerEvent"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073754112: The client has sent an activation request to the key management service machine.

#
Channel
Operational

Message #

The client has sent an activation request to the key management service machine.
Info:
%1

Fields #

NameDescription
Info

Event ID 1073754113: The client has processed an activation response from the key management service machine.

#
Channel
Operational

Message #

The client has processed an activation response from the key management service machine.
Info:
%1

Fields #

NameDescription
Info

Event ID 1073754114: An activation request has been processed.

#
Channel
Operational

Message #

An activation request has been processed.
Info:
%1

Fields #

NameDescription
Info

Event ID 1073754115: Key Management Service (KMS) failed to start.

#
Channel
Operational

Message #

Key Management Service (KMS) failed to start.
Info:
%1

Fields #

NameDescription
Info

Event ID 1073754117: Publishing the Key Management Service (KMS) to DNS in the '%2' domain failed.

#
Channel
Operational

Message #

Publishing the Key Management Service (KMS) to DNS in the '%2' domain failed.
Info:
%1

Fields #

NameDescription
Info

Event ID 1073754118: Publishing the Key Management Service (KMS) to DNS in the 'param1' domain is successful.

#
Channel
Operational

Message #

Publishing the Key Management Service (KMS) to DNS in the '%1' domain is successful.

Fields #

NameDescription
param1

Event ID 1073754119: Secure KMS initialization failed with code %1 at stage %2.

#
Channel
Operational

Description

Secure KMS initialization failed with code at stage .

Event ID 1073754120: Secure KMS initialization succeeded.

#
Channel
Operational

Event ID 1073754128: Successfully acquired genuine ticket for template Id param1.

#
Channel
Operational
Level
4

Message #

Successfully acquired genuine ticket for template Id %1

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 12304,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:15.8794878+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Data": "{99d92734-d682-4d71-983e-d6ec3f16059f}"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073754129: Genuine state set to genuine for application Id param1.

#
Channel
Operational
Level
4

Message #

Genuine state set to genuine for application Id %1

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 12305,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:15.8098873+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Data": "55c92734-d682-4d71-983e-d6ec3f16059f"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073754130: Rearm successful for AppId = param1, SkuId = param2 - param3 Rearms Remaining.

#
Channel
Operational
Level
4

Message #

Rearm successful for AppId = %1, SkuId = %2 - %3 Rearms Remaining.

Fields #

NameDescription
param1
param2
param3

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 12306,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-17T18:17:10.1427718+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1073754131: Skipped Rearm for AppId = param1, SkuId = param2.

#
Channel
Operational

Message #

Skipped Rearm for AppId = %1, SkuId = %2.

Fields #

NameDescription
param1
param2

Event ID 1073754132: Active Directory Activation has succeeded.

#
Channel
Operational

Message #

Active Directory Activation has succeeded.
Sku Id = %1
AO name = %2
AO DN = %3

Fields #

NameDescription
param1
param2
param3

Event ID 1073754133: The client has processed an Automatic VM activation response from the parent partition.

#
Channel
Operational

Message #

The client has processed an Automatic VM activation response from the parent partition.
Returned hr=%1
%2

Fields #

NameDescription
param1
param2

Event ID 1073754134: An Automatic VM activation request has been processed.

#
Channel
Operational

Message #

An Automatic VM activation request has been processed.
Returned hr=%1
%2

Fields #

NameDescription
param1
param2

Event ID 1073754135: The MSA client has been successfully triggered to update the Device License

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 12311,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:16.3438932+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1073754144: Token-based Activation has succeeded.

#
Channel
Operational

Message #

Token-based Activation has succeeded.
Sku Id=%1

Fields #

NameDescription
param1

Event ID 1073758208: Successfully scheduled Software Protection service for re-start at %1.

#
Channel
Operational

Description

Successfully scheduled Software Protection service for re-start at . Reason: .

Message #

Successfully scheduled Software Protection service for re-start at %1. Reason: %2.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 16384,
    "level": "Information",
    "task": null,
    "opcode": null,
    "time_created": "2026-05-27T17:31:07.9858399+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "_value": null
  }
}

Example keys not documented in the fields table: _value

Event ID 1073758210: Successfully started task param1\param2.

#
Channel
Operational

Message #

Successfully started task %1\%2.

Fields #

NameDescription
param1
param2

Event ID 1073758212: The current time is 1 : %2.

#
Channel
Operational
Level
4

Message #

The current time is %1 : %2.

Fields #

NameDescription
1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 16388,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:09:08.3692371+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "2026-05-27T20:09:08Z"
  }
}

Example keys not documented in the fields table: Data

Event ID 1073758213: Grace timer has expired.

#
Channel
Operational

Description

Grace timer has expired. Hr =.

Message #

Grace timer has expired. Hr = %1

Event ID 2147484663: Detailed HRESULT.

#
Channel
Operational

Description

Detailed HRESULT. Returned hr=param1, Original hr=param2.

Message #

Detailed HRESULT. Returned hr=%1, Original hr=%2

Fields #

NameDescription
param1
param2

Event ID 2147484664: Grace timer notification failed hr=.

#
Channel
Operational
Level
4

Message #

Grace timer notification failed hr=%1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1016,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:09:05.4693612+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "a17e0657-a529-04c4-bd76-3672cdefcf22"
  }
}

Example keys not documented in the fields table: Data

Event ID 2147484665: Installation of the Proof of Purchase failed.

#
Channel
Operational

Description

Installation of the Proof of Purchase failed. param1.

Message #

Installation of the Proof of Purchase failed. %1
Partial Pkey=%2
ACID=%3
Detailed Error[%4]

Fields #

NameDescription
param1
param2
param3
param4

Event ID 2147484666: Grace timer creation result %1.

#
Channel
Operational
Level
4

Description

Grace timer creation result .

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1018,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-17T18:19:51.5906816+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 2147484667: Removal of the Proof of Purchase failed.

#
Channel
Operational

Description

Removal of the Proof of Purchase failed. param1.

Message #

Removal of the Proof of Purchase failed. %1
ACID=%2
PKeyId=%3

Fields #

NameDescription
param1
param2
param3

Event ID 2147484668: Proxy Execution Key has failed to load.

#
Channel
Operational

Description

Proxy Execution Key has failed to load. param1.

Message #

Proxy Execution Key has failed to load. %1
Proxy Execution Policy=%2

Fields #

NameDescription
param1
param2

Event ID 2147484670: The system has been tampered.

#
Channel
Operational

Description

The system has been tampered. param1.

Message #

The system has been tampered. %1

Fields #

NameDescription
param1

Event ID 2147484672: The hardware has changed.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1024,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:03.9119705+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Binary": "5E0000001300300000000200030001000100010000000000010001000000962B06668A0A018B52C89ED641E06E22241DF9AF3384C0620D0002000101000205000301000402000500000601000700000807000903000A01000B00000C0700"
  }
}

Example keys not documented in the fields table: Binary

Event ID 2147484677: Unable to get detailed error information during license consumption.

#
Channel
Operational
Level
3

Description

Unable to get detailed error information during license consumption. Last error param1.

Message #

Unable to get detailed error information during license consumption. Last error %1.

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1029,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:08:57.3977547+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "0xC004F015"
  }
}

Example keys not documented in the fields table: Data

Event ID 2147484680: Kernel policy cache update failed.

#
Channel
Operational

Description

Kernel policy cache update failed. param1.

Message #

Kernel policy cache update failed. %1.

Fields #

NameDescription
param1

Event ID 2147484685: Time-based license remaining param1 time param2 minutes.

#
Channel
Operational
Level
4

Message #

Time-based license remaining %1 time %2 minutes.

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1037,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T19:32:02.3161629+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "72299"
  }
}

Example keys not documented in the fields table: Data

Event ID 2147484692: The following errors occurred during license evaluation.

#
Channel
Operational

Message #

The following errors occurred during license evaluation:
%1

Fields #

NameDescription
The_following_errors_occurred_during_license_evaluation

Event ID 2147484704: Some data has been reset.

#
Channel
Operational

Description

Some data has been reset. param1 [param2].

Message #

Some data has been reset. %1 [%2].

Fields #

NameDescription
param1
param2

Event ID 2147484705: Unable to update Windows PID information in the registry: Unable_to_update_Windows_PID_information_in_the_registry.

#
Channel
Operational

Message #

Unable to update Windows PID information in the registry: %1

Fields #

NameDescription
Unable_to_update_Windows_PID_information_in_the_registry

Event ID 2147484706: Installation of the Proof of Purchase from the ACPI table failed.

#
Channel
Operational

Description

Installation of the Proof of Purchase from the ACPI table failed. Error code.

Message #

Installation of the Proof of Purchase from the ACPI table failed. Error code:
%1

Fields #

NameDescription
ErrorCode

Event ID 2147484707: Detected OS composition change triggered license re-evaluation.

#
Channel
Operational

Event ID 2147484708: Detected OEM product key change triggered license re-evaluation.

#
Channel
Operational

Event ID 2147484715: Genuine information set for application.

#
Channel
Operational
Level
4

Description

Genuine information set for application. param1, param2, param3.

Message #

Genuine information set for application. %1, %2, %3.

Fields #

NameDescription
param1
param2
param3

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1067,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:07.8116468+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Binary": "01000000",
    "Data": "SL_ACTIVATION_VALIDATION_IN_PROGRESS"
  }
}

Example keys not documented in the fields table: Binary, Data

Event ID 2147484738: The Software Licensing edition check failed.

#
Channel
Operational

Message #

The Software Licensing edition check failed.
Error code:%1

Fields #

NameDescription
Error_code

Event ID 2147484832: Invalid chunk hash detected in migration blob.

#
Channel
Operational

Message #

Invalid chunk hash detected in migration blob.
Uri: %1

Fields #

NameDescription
Uri

Event ID 2147484833: Failed to gather PKEY information for SKU.

#
Channel
Operational

Message #

Failed to gather PKEY information for SKU.
Sku id: %1

Fields #

NameDescription
Sku_id

Event ID 2147484834: Installing migrated PKEY failed with Sku_id.

#
Channel
Operational

Message #

Installing migrated PKEY failed with %1.
Sku id: %2

Fields #

NameDescription
Sku_id

Event ID 2147484835: The Sku associated with the IID/CID is not installed on the local machine.

#
Channel
Operational

Message #

The Sku associated with the IID/CID is not installed on the local machine.
Sku id: %1

Fields #

NameDescription
Sku_id

Event ID 2147484836: The Sku associated with the IID/CID does not have a PKEY installed.

#
Channel
Operational

Message #

The Sku associated with the IID/CID does not have a PKEY installed.
Sku id: %1

Fields #

NameDescription
Sku_id

Event ID 2147484838: Unable to deposit chunk due to HWID mismatch.

#
Channel
Operational

Message #

Unable to deposit chunk due to HWID mismatch.
Uri: %1

Fields #

NameDescription
Uri

Event ID 2147484839: Unable to deposit chunk due to Trusted Store being recreated.

#
Channel
Operational

Message #

Unable to deposit chunk due to Trusted Store being recreated.
Uri: %1

Fields #

NameDescription
Uri

Event ID 2147484840: Failed to gather PKEY information for backup product key.

#
Channel
Operational

Message #

Failed to gather PKEY information for backup product key.
Error: %1
Product key: %2

Fields #

NameDescription
Error
Product_key

Event ID 2147484841: Failed to gather PKEY information for OEM:DM product key.

#
Channel
Operational

Message #

Failed to gather PKEY information for OEM:DM product key.
Error: %1
Product key: %2

Fields #

NameDescription
Error
Product_key

Event ID 2147484842: Failed to gather target OS information for PID.

#
Channel
Operational

Message #

Failed to gather target OS information for PID.
Error: %1
PID: %2

Fields #

NameDescription
Error
PID

Event ID 2147484843: Failed to gather target OS information input key data.

#
Channel
Operational

Message #

Failed to gather target OS information input key data.
Error: %1

Fields #

NameDescription
Error

Event ID 3221226473: The Software Protection service failed to start.

#
Channel
Operational

Description

The Software Protection service failed to start. param1.

Message #

The Software Protection service failed to start. %1
%2

Fields #

NameDescription
param1
param2

Event ID 3221226480: Acquisition of Secure Processor Certificate failed.

#
Channel
Operational

Description

Acquisition of Secure Processor Certificate failed. param1.

Message #

Acquisition of Secure Processor Certificate failed. %1

Fields #

NameDescription
param1

Event ID 3221226482: Acquisition of Rights Account Certificate failed.

#
Channel
Operational

Description

Acquisition of Rights Account Certificate failed. param1.

Message #

Acquisition of Rights Account Certificate failed. %1

Fields #

NameDescription
param1

Event ID 3221226484: Acquisition of Product Certificate failed.

#
Channel
Operational

Description

Acquisition of Product Certificate failed. param1.

Message #

Acquisition of Product Certificate failed. %1
Sku Id=%2

Fields #

NameDescription
param1
param2

Event ID 3221226486: Acquisition of End User License failed.

#
Channel
Operational
Level
2

Description

Acquisition of End User License failed. param1.

Message #

Acquisition of End User License failed. %1
Sku Id=%2

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 1014,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:05.4234986+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Data": "3f4c0546-36c6-46a8-a37f-be13cdd0cf25"
  }
}

Example keys not documented in the fields table: Data

Event ID 3221226500: There are param1 invalid license(s).

#
Channel
Operational

Message #

There are %1 invalid license(s).

Fields #

NameDescription
param1

Event ID 3221226513: Failed to collect hardware data.

#
Channel
Operational

Description

Failed to collect hardware data. Error code param1.

Message #

Failed to collect hardware data. Error code %1.

Fields #

NameDescription
param1

Event ID 3221226534: Deposition of Confirmation ID failed.

#
Channel
Operational

Description

Deposition of Confirmation ID failed. param1.

Message #

Deposition of Confirmation ID failed. %1
Sku Id=%2

Fields #

NameDescription
param1
param2

Event ID 3221226661: Failed to read migration blob - encryption key not recognized.

#
Channel
Operational

Event ID 3221233667: SLSetGenuineInformation in sppcomapi failed with the following error code.

#
Channel
Operational

Message #

SLSetGenuineInformation in sppcomapi failed with the following error code:
%1

Fields #

NameDescription
SLSetGenuineInformation_in_sppcomapi_failed_with_the_following_error_code

Event ID 3221233668: LoadLibrary call for loading Sppcommdlg.

#
Channel
Operational

Description

LoadLibrary call for loading Sppcommdlg.dll from SLUI.exe failed with error code.

Message #

LoadLibrary call for loading Sppcommdlg.dll from SLUI.exe failed with error code:
%1

Fields #

NameDescription
LoadLibrary_call_for_loading_Sppcommdlgdll_from_SLUIexe_failed_with_error_code

Event ID 3221233669: SLUI.

#
Channel
Operational
Level
4

Description

SLUI.exe was launched with the following command-line parameters.

Message #

SLUI.exe was launched with the following command-line parameters:
%1

Fields #

NameDescription
SLUIexe_was_launched_with_the_following_commandline_parameters

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 8197,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:18.9750683+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Data": "RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=3f4c0546-36c6-46a8-a37f-be13cdd0cf25;NotificationInterval=1440;Trigger=NetworkAvailable"
  }
}

Example keys not documented in the fields table: Data

Event ID 3221233670: License Activation.

#
Channel
Operational
Level
2

Description

License Activation (slui.exe) failed with the following error code.

Message #

License Activation (slui.exe) failed with the following error code:
%1
Command-line arguments:
%2

Fields #

NameDescription
License_Activation_sluiexe_failed_with_the_following_error_code
Commandline_arguments

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 8198,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:16.0626623+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Data": "RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=3f4c0546-36c6-46a8-a37f-be13cdd0cf25;NotificationInterval=1440;Trigger=UserLogon;SessionId=1"
  }
}

Example keys not documented in the fields table: Data

Event ID 3221233672: License acquisition failure details.

#
Channel
Operational
Level
2

Message #

License acquisition failure details. 
%1

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 8200,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:05.4114153+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {
    "Data": "00010001(0x00000000, 17:49:05:378 - https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail)\n00020001(0x00000000, 17:49:05:382)\n00030001(0x00000000, 17:49:05:384 - https://activation-v2.sls.microsoft.com)\n00030002(0x00000000, 17:49:05:384 - 0)\n00040001(0x00000000, 17:49:05:384 - https://activation-v2.sls.microsoft.com)\n00040002(0x00000000, 17:49:05:388 - 1, <NULL>, <NULL>, <NULL>)\n00050002(0x80072F94, 17:49:05:390 - 0, 1)\n00040006(0x00000001, 17:49...[truncated]"
  }
}

Example keys not documented in the fields table: Data

Event ID 3221233677: Token Store found to be corrupt.

#
Channel
Operational

Description

Token Store found to be corrupt. Recreating Token Store.

Message #

Token Store found to be corrupt. Recreating Token Store.

Event ID 3221233680: Acquisition of genuine ticket failed (param1) for template Id param2.

#
Channel
Operational

Message #

Acquisition of genuine ticket failed (%1) for template Id %2

Fields #

NameDescription
param1
param2

Event ID 3221233681: Genuine state set to non-genuine (param1) for application Id param2.

#
Channel
Operational

Message #

Genuine state set to non-genuine (%1) for application Id %2

Fields #

NameDescription
param1
param2

Event ID 3221233682: Update current edition product key id failed with param1.

#
Channel
Operational

Message #

Update current edition product key id failed with %1

Fields #

NameDescription
param1

Event ID 3221233683: Update Windows license and product key tokens failed with param1.

#
Channel
Operational

Message #

Update Windows license and product key tokens failed with %1. 
%2

Fields #

NameDescription
param1
param2

Event ID 3221233684: Rearm failed for AppId = %2, SkuId = %3 - %4 Rearms Remaining.

#
Channel
Operational

Description

Rearm failed for AppId = , SkuId = - Rearms Remaining. Error Code.

Message #

Rearm failed for AppId = %2, SkuId = %3 - %4 Rearms Remaining.  Error Code: %1

Event ID 3221233685: Activation Object cannot be retrieved from Active Directory.

#
Channel
Operational

Message #

Activation Object cannot be retrieved from Active Directory.
Error Code = %1
Kms Id = %2

Fields #

NameDescription
param1
param2

Event ID 3221233686: Active Directory Activation Object is not usable.

#
Channel
Operational

Message #

Active Directory Activation Object is not usable.
Error Code = %1
Kms Id = %2
AO Name = %3
AO DN = %4

Fields #

NameDescription
param1
param2
param3
param4

Event ID 3221233687: Active Directory Activation has failed.

#
Channel
Operational

Message #

Active Directory Activation has failed.
Error Code = %1
Sku Id = %2

Fields #

NameDescription
param1
param2

Event ID 3221233688: HCI Marker has failed verification.

#
Channel
Operational

Description

HCI Marker has failed verification. Error Code =.

Message #

HCI Marker has failed verification. Error Code = %1

Event ID 3221233689: HCI Marker has bad data.

#
Channel
Operational

Description

HCI Marker has bad data. Error Code =.

Message #

HCI Marker has bad data. Error Code = %1

Event ID 3221233690: Failed ot retrieve HCI Marker.

#
Channel
Operational

Description

Failed ot retrieve HCI Marker . Error Code =.

Message #

Failed ot retrieve HCI Marker . Error Code = %1

Event ID 3221233691: OEM OA Binding failed.

#
Channel
Operational

Description

OEM OA Binding failed . Error Code =.

Message #

OEM OA Binding failed . Error Code = %1

Event ID 3221233692: OEM OA Binding extraction failed.

#
Channel
Operational

Description

OEM OA Binding extraction failed . Error Code =.

Message #

OEM OA Binding extraction failed . Error Code = %1

Event ID 3221233693: OEM OA Binding decode failed.

#
Channel
Operational

Description

OEM OA Binding decode failed . Error Code =.

Message #

OEM OA Binding decode failed . Error Code = %1

Event ID 3221237794: Failed to deposit Token-based Activation response.

#
Channel
Operational

Description

Failed to deposit Token-based Activation response. param1.

Message #

Failed to deposit Token-based Activation response. %1
Sku Id = %2

Fields #

NameDescription
param1
param2

Event ID 3221241857: Failed to schedule Software Protection service for re-start at %2.

#
Channel
Operational

Description

Failed to schedule Software Protection service for re-start at . Error Code: .

Message #

Failed to schedule Software Protection service for re-start at %2. Error Code: %1.

Event ID 3221241859: Failed to run task %2\%3.

#
Channel
Operational

Description

Failed to run task \. Error Code: .

Message #

Failed to run task %2\%3. Error Code: %1.

Event ID 3221241860: Authorized upgrade for PID: AuthorizedUpgradeForPID.

#
Channel
Operational
Level
4

Message #

Authorized upgrade for PID: %1.

Fields #

NameDescription
AuthorizedUpgradeForPID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 16388,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T20:09:08.3692371+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {
    "Data": "2026-05-27T20:09:08Z"
  }
}

Example keys not documented in the fields table: Data

Event ID 3221241861: Downlevel Genuine Ticket successfully deposited.

#
Channel
Operational

Event ID 3221241862: Updated policy param1 with value of param2 from Clip.

#
Channel
Operational

Message #

Updated policy %1 with value of %2 from Clip.

Fields #

NameDescription
param1
param2

Event ID 3221241863: Downlevel Genuine Ticket deposit failed.

#
Channel
Operational

Event ID 3221241864: Downlevel consumption failed.

#
Channel
Operational

Event ID 3221241865: Downlevel Migration failed.

#
Channel
Operational

Event ID 3221241866: Offline downlevel migration succeeded.

#
Channel
Operational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 16394,
    "level": "Information",
    "task": null,
    "opcode": null,
    "time_created": "2026-05-27T17:30:37.6694344+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 3221241867: Operation status %2 with return code %1.

#
Channel
Operational

Description

Operation status with return code .

Event ID 3221241868: You are on an inactivated device.

#
Channel
Operational

Event ID 3221241869: Device is in grace period for %1 minutes more.

#
Channel
Operational

Description

Device is in grace period for minutes more.

Event ID 3221241870: Error occured during grace period %1 at %2.

#
Channel
Operational

Description

Error occured during grace period at .

Event ID 3221245953: Health check initiated.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 20481,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:10.4025169+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 3221245954: Health check passed.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 20482,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:10.8798105+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 3221245955: Tamper detected.

#
Channel
Operational

Message #

Tamper detected: 
 ScanNeutralFiles = %1, ScanMuiFiles: %2

Event ID 3221245956: Error occurred during Health check.

#
Channel
Operational

Message #

Error occurred during Health check: 
 hr = %1

Fields #

NameDescription
param1

Event ID 3221245957: Genuine validation initiated.

#
Channel
Operational

Event ID 3221245958: Genuine validation result.

#
Channel
Operational

Message #

Genuine validation result: 
 hr = %1

Fields #

NameDescription
param1

Event ID 3221245959: Genuine validation failure.

#
Channel
Operational

Message #

Genuine validation failure: 
 hr = %1

Fields #

NameDescription
param1

Event ID 3221245960: Genuine validation data collection started.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 20488,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:08.5806243+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 3221245961: Genuine validation data collection ended.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Security-SPP",
    "event_id": 20489,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-17T21:49:11.3343257+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 3221245962: Grace timer initialization failed.

#
Channel
Operational

Event ID 3221245963: Grace timer previously created.

#
Channel
Operational

Event ID 3221245964: Grace period terminated with code %1.

#
Channel
Operational

Description

Grace period terminated with code .

Provenance

ETW provider GUID e23b33b0-c8c9-472c-a5f9-f2bdfea0f156

Defined in sppsvc.exe, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4484, captured 2026-06-02 — Manifest XML pack, 2.0 MB