Microsoft-Windows-SecurityMitigationsBroker

30 events across 3 channels

EventTitleChannelSample
1001SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdateStartPerfN
1002SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdateStopPerfN
1003Failed to get the COM call context.OperationalN
1004Failed to get the calling process information.OperationalN
1005Failed to get the DX adapter driver capabilities.OperationalN
1006ACG status of the DX adapter driver, AdapterId=DriverId, capability=ACGState.AdminN
1007Failed to get the mitigation status of the calling proces.OperationalN
1008Failed to set the mitigation status of the calling proces.OperationalN
1009Calling process ACG status, AdapterId=DriverId, ProcessId=ProcessId, ACG …AdminN
1010Calling process is in ACG telemetry mode.AdminN
1011Calling process is not in an AppContainer.AdminN
1012Failed to adjust the calling process ACG status for the reported DX adapter …OperationalN
1013Finished applying the security protection policies for the reported DX adapter …AdminN
1014Calling process does not have ACG turned on.AdminN
1015ACG will be turned off for the calling process due to unsupportive DX adapter …AdminN
1016Failed to create the DX object factory.OperationalN
1017Failed to enumerate the DX adapters.OperationalN
1018Failed to query the descriptor for the adapter id.OperationalN
1019Enumerated a DX adapter.AdminN
1020Calling process uses the software rendering adapter.AdminN
1021Failed to query the IDXGIAdapter2 interface from the enumerated adapter.OperationalN
1022Encountered a DX adapter that does not support ACG.AdminN
1023Forced ACG on the DX Adapter which uses a WDDM 2.AdminN
1024Calling process does not allow remote ACG downgrade.AdminN
1025Remote downgrade is disabled through settings.AdminN
1026Non-primary adapter ID is supplied.AdminN
1027Remote downgrade is rejected since software rendering only policy is set.AdminN
1028SecurityMitigationsBroker.Task.DisableAcgEnforcementStartPerfN
1029SecurityMitigationsBroker.Task.DisableAcgEnforcementStopPerfN
1030DisableAcgEnforcement is not enabled on current architecture.AdminN

Event ID 1001: SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdateStart

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Perf
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate
Opcode
Start

Event ID 1002: SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdateStop

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Perf
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate
Opcode
Stop

Event ID 1003: Failed to get the COM call context.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Operational
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Failed to get the COM call context. AdapterId=DriverId, ErrorCode=ErrorCode.

Message #

Failed to get the COM call context. AdapterId=%1, ErrorCode=%2

Fields #

NameDescription
DriverId UInt64
ErrorCode UInt32

Event ID 1004: Failed to get the calling process information.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Operational
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Failed to get the calling process information. AdapterId=DriverId, ErrorCode=ErrorCode.

Message #

Failed to get the calling process information. AdapterId=%1, ErrorCode=%2

Fields #

NameDescription
DriverId UInt64
ErrorCode UInt32

Event ID 1005: Failed to get the DX adapter driver capabilities.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Operational
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Failed to get the DX adapter driver capabilities. AdapterId=DriverId, ErrorCode=ErrorCode.

Message #

Failed to get the DX adapter driver capabilities. AdapterId=%1, ErrorCode=%2

Fields #

NameDescription
DriverId UInt64
ErrorCode UInt32

Event ID 1006: ACG status of the DX adapter driver, AdapterId=DriverId, capability=ACGState.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

ACG status of the DX adapter driver, AdapterId=DriverId, capability=ACGState.

Message #

ACG status of the DX adapter driver, AdapterId=%1, capability=%2

Fields #

NameDescription
DriverId UInt64
ACGState UInt32

Event ID 1007: Failed to get the mitigation status of the calling proces.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Operational
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Failed to get the mitigation status of the calling proces. AdapterId=DriverId, ProcessId=ProcessId, ErrorCode=ErrorCode.

Message #

Failed to get the mitigation status of the calling proces. AdapterId=%1, ProcessId=%2, ErrorCode=%3

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32
ErrorCode UInt32

Event ID 1008: Failed to set the mitigation status of the calling proces.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Operational
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Failed to set the mitigation status of the calling proces. AdapterId=DriverId, ProcessId=ProcessId, ErrorCode=ErrorCode.

Message #

Failed to set the mitigation status of the calling proces. AdapterId=%1, ProcessId=%2, ErrorCode=%3

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32
ErrorCode UInt32

Event ID 1009: Calling process ACG status, AdapterId=DriverId, ProcessId=ProcessId, ACG status=ACGState.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Calling process ACG status, AdapterId=DriverId, ProcessId=ProcessId, ACG status=ACGState.

Message #

Calling process ACG status, AdapterId=%1, ProcessId=%2, ACG status=%3

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32
ACGState UInt32

Event ID 1010: Calling process is in ACG telemetry mode.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Calling process is in ACG telemetry mode. AdapterId=DriverId, ProcessId=ProcessId.

Message #

Calling process is in ACG telemetry mode. AdapterId=%1, ProcessId=%2

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32

Event ID 1011: Calling process is not in an AppContainer.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Calling process is not in an AppContainer. Driver=DriverId, ProcessId=ProcessId.

Message #

Calling process is not in an AppContainer. Driver=%1, ProcessId=%2

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32

Event ID 1012: Failed to adjust the calling process ACG status for the reported DX adapter change event.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Operational
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Failed to adjust the calling process ACG status for the reported DX adapter change event. AdapterId=DriverId, ProcessId=ProcessId, ErrorCode=ErrorCode.

Message #

Failed to adjust the calling process ACG status for the reported DX adapter change event. AdapterId=%1, ProcessId=%2, ErrorCode=%3

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32
ErrorCode UInt32

Event ID 1013: Finished applying the security protection policies for the reported DX adapter change event.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Finished applying the security protection policies for the reported DX adapter change event. AdapterId=DriverId, ProcessId=ProcessId.

Message #

Finished applying the security protection policies for the reported DX adapter change event. AdapterId=%1, ProcessId=%2

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32

Event ID 1014: Calling process does not have ACG turned on.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Calling process does not have ACG turned on. AdapterId=DriverId, ProcessId=ProcessId.

Message #

Calling process does not have ACG turned on. AdapterId=%1, ProcessId=%2

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32

Event ID 1015: ACG will be turned off for the calling process due to unsupportive DX adapter driver.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

ACG will be turned off for the calling process due to unsupportive DX adapter driver. AdapterId=DriverId, ProcessId=ProcessId.

Message #

ACG will be turned off for the calling process due to unsupportive DX adapter driver. AdapterId=%1, ProcessId=%2

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32

Event ID 1016: Failed to create the DX object factory.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Operational
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Failed to create the DX object factory. AdapterId=DriverId, ProcessId=ProcessId, ErrorCode=ErrorCode.

Message #

Failed to create the DX object factory. AdapterId=%1, ProcessId=%2, ErrorCode=%3

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32
ErrorCode UInt32

Event ID 1017: Failed to enumerate the DX adapters.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Operational
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Failed to enumerate the DX adapters. AdapterId=DriverId, ProcessId=ProcessId, ErrorCode=ErrorCode.

Message #

Failed to enumerate the DX adapters. AdapterId=%1, ProcessId=%2, ErrorCode=%3

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32
ErrorCode UInt32

Event ID 1018: Failed to query the descriptor for the adapter id.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Operational
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Failed to query the descriptor for the adapter id. AdapterId=DriverId, ProcessId=ProcessId, ErrorCode=ErrorCode.

Message #

Failed to query the descriptor for the adapter id. AdapterId=%1, ProcessId=%2, ErrorCode=%3

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32
ErrorCode UInt32

Event ID 1019: Enumerated a DX adapter.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Enumerated a DX adapter. AdapterId=DriverId1, enumerated AdapterId=DriverId2, ProcessId=ProcessId.

Message #

Enumerated a DX adapter. AdapterId=%1, enumerated AdapterId=%2, ProcessId=%3

Fields #

NameDescription
DriverId1 UInt64
DriverId2 UInt64
ProcessId UInt32

Event ID 1020: Calling process uses the software rendering adapter.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Calling process uses the software rendering adapter. Driver=DriverId, ProcessId=ProcessId.

Message #

Calling process uses the software rendering adapter. Driver=%1, ProcessId=%2

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32

Event ID 1021: Failed to query the IDXGIAdapter2 interface from the enumerated adapter.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Operational
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Failed to query the IDXGIAdapter2 interface from the enumerated adapter. AdapterId=DriverId, ProcessId=ProcessId, ErrorCode=ErrorCode.

Message #

Failed to query the IDXGIAdapter2 interface from the enumerated adapter. AdapterId=%1, ProcessId=%2, ErrorCode=%3

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32
ErrorCode UInt32

Event ID 1022: Encountered a DX adapter that does not support ACG.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Encountered a DX adapter that does not support ACG. Description:Description, VendorId:VendorId, DeviceId:DeviceId, AdapterId=DriverId, ProcessId=ProcessId.

Message #

Encountered a DX adapter that does not support ACG. Description:%1, VendorId:%2, DeviceId:%3, AdapterId=%4, ProcessId=%5

Fields #

NameDescription
Description UnicodeString
VendorId UInt32
DeviceId UInt32
DriverId UInt64
ProcessId UInt32

Event ID 1023: Forced ACG on the DX Adapter which uses a WDDM 2.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Forced ACG on the DX Adapter which uses a WDDM 2.0 and above driver from a supported vendor. Description:Description, VendorId:VendorId, DeviceId:DeviceId, AdapterId=DriverId, ProcessId=ProcessId.

Message #

Forced ACG on the DX Adapter which uses a WDDM 2.0 and above driver from a supported vendor. Description:%1, VendorId:%2, DeviceId:%3, AdapterId=%4, ProcessId=%5

Fields #

NameDescription
Description UnicodeString
VendorId UInt32
DeviceId UInt32
DriverId UInt64
ProcessId UInt32

Event ID 1024: Calling process does not allow remote ACG downgrade.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Calling process does not allow remote ACG downgrade. AdapterId=DriverId, ProcessId=ProcessId.

Message #

Calling process does not allow remote ACG downgrade. AdapterId=%1, ProcessId=%2

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32

Event ID 1025: Remote downgrade is disabled through settings.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Remote downgrade is disabled through settings. AdapterId=DriverId, ProcessId=ProcessId.

Message #

Remote downgrade is disabled through settings. AdapterId=%1, ProcessId=%2

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32

Event ID 1026: Non-primary adapter ID is supplied.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Non-primary adapter ID is supplied. Description:Description, VendorId:VendorId, DeviceId:DeviceId, AdapterId=DriverId, ProcessId=ProcessId.

Message #

Non-primary adapter ID is supplied. Description:%1, VendorId:%2, DeviceId:%3, AdapterId=%4, ProcessId=%5

Fields #

NameDescription
Description UnicodeString
VendorId UInt32
DeviceId UInt32
DriverId UInt64
ProcessId UInt32

Event ID 1027: Remote downgrade is rejected since software rendering only policy is set.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.NotifyDisplayDriverUpdate

Description

Remote downgrade is rejected since software rendering only policy is set. AdapterId=DriverId, ProcessId=ProcessId.

Message #

Remote downgrade is rejected since software rendering only policy is set. AdapterId=%1, ProcessId=%2

Fields #

NameDescription
DriverId UInt64
ProcessId UInt32

Event ID 1028: SecurityMitigationsBroker.Task.DisableAcgEnforcementStart

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Perf
Task
SecurityMitigationsBroker.Task.DisableAcgEnforcement
Opcode
Start

Event ID 1029: SecurityMitigationsBroker.Task.DisableAcgEnforcementStop

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Perf
Task
SecurityMitigationsBroker.Task.DisableAcgEnforcement
Opcode
Stop

Event ID 1030: DisableAcgEnforcement is not enabled on current architecture.

#
Provider
Microsoft-Windows-SecurityMitigationsBroker
Channel
Admin
Task
SecurityMitigationsBroker.Task.DisableAcgEnforcement

Description

DisableAcgEnforcement is not enabled on current architecture. ModuleName=ModuleName.

Message #

DisableAcgEnforcement is not enabled on current architecture. ModuleName=%1

Fields #

NameDescription
ModuleName UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID ea8cd8a5-78ff-4418-b292-aadc6a7181df

Defined in Windows.Internal.SecurityMitigationsBroker.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads