Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess

102 events across 2 channels

EventTitleChannelSample
1Provisioning Secure Process createdDebugN
1Event ID 1OperationalN
2Provisioning Secure Process could not initialize based on the command line …DebugN
2Event ID 2OperationalN
3Provisioning Secure Process is closingDebugN
3Event ID 3OperationalN
4Provisioning Secure Process argument was TemplateNameFound.DebugN
4Event ID 4OperationalN
5Provisioning Secure Process was not provided the expected argument and will exitDebugN
5Event ID 5OperationalN
6Provisioning Secure Process was not provided the expected argument and will exitDebugN
6Event ID 6OperationalN
7Provisioning Secure Process parsed the command line arguments as MachineID.DebugN
7Event ID 7OperationalN
8Provisioning Secure Process could not set the trustlet identity and must exitDebugN
8Event ID 8OperationalN
9Provisioning Secure Process could not initialize the remote TPM assets and must …DebugN
9Event ID 9OperationalN
10Provisioning Secure Process could not initialize the RPC serverDebugN
10Event ID 10OperationalN
11Provisioning Secure Process could not register with the RPC serverDebugN
11Event ID 11OperationalN
12Provisioning Secure Process transitioned to state EndState.DebugN
12Event ID 12OperationalN
13Provisioning Secure Process transitioned to state EndState.DebugN
13Event ID 13OperationalN
14Provisioning Secure Process is not running within IUM.DebugN
14Event ID 14OperationalN
15Provisioning Secure Process received a message from source SourceGroup of length …DebugN
15Event ID 15OperationalN
16Provisioning Secure Process received a request for the PDK.DebugN
16Event ID 16OperationalN
17Provisioning Secure Process is sending the PDK to the provisioning agent.DebugN
17Event ID 17OperationalN
18Provisioning Secure Process has sent the encrypted PDK to the virtual machine.DebugN
18Event ID 18OperationalN
19Provisioning Secure Process received a PDK that was invalid or could not be …DebugN
19Event ID 19OperationalN
20Provisioning Secure Process encountered an error while processing the EFI …DebugN
20Event ID 20OperationalN
21Provisioning Secure Process encountered an error while generating the server key …DebugN
21Event ID 21OperationalN
22Provisioning Secure Process encountered an error while extending the Secure Boot …DebugN
22Event ID 22OperationalN
23Provisioning Secure Process encountered an error while extending the Boot Lock …DebugN
23Event ID 23OperationalN
24Provisioning Secure Process encountered an error while accessing secure storage …DebugN
24Event ID 24OperationalN
25Provisioning Secure Process encountered an error while working with the remote …DebugN
25Event ID 25OperationalN
26Provisioning Secure Process encountered an error while working with the remote …DebugN
26Event ID 26OperationalN
27Provisioning Secure Process encountered an error while attempting miniature …DebugN
27Event ID 27OperationalN
28Provisioning Secure Process encountered an error while creating and sending the …DebugN
28Event ID 28OperationalN
29Provisioning Secure Process could not collect necessary security info from the …DebugN
29Event ID 29OperationalN
30Provisioning Secure Process is populating the boot authority information from …DebugN
30Event ID 30OperationalN
31Provisioning Secure Process will allow the UEFI certificate authority for this …DebugN
31Event ID 31OperationalN
32Provisioning Secure Process attestation error - PCR PcrIndex, error …DebugN
32Event ID 32OperationalN
33Provisioning Secure Process received a PDK that was invalid or could not be …DebugN
33Event ID 33OperationalN
34Provisioning Secure Process received a message from NMPS that was invalid or …DebugN
34Event ID 34OperationalN
35Provisioning Secure Process received a message from NMPS that was invalid or …DebugN
35Event ID 35OperationalN
36Provisioning Secure Process received a message that was invalid or could not be …DebugN
36Event ID 36OperationalN
37Provisioning Secure Process received a message that was invalid or could not be …DebugN
37Event ID 37OperationalN
38Provisioning Secure Process is starting the version negotiation with the …DebugN
38Event ID 38OperationalN
39Provisioning Secure Process received version information from the provisioning …DebugN
39Event ID 39OperationalN
40Provisioning Secure Process declared version informationDebugN
40Event ID 40OperationalN
41Provisioning Secure Process finished negotiating the protocol versionDebugN
41Event ID 41OperationalN
42Provisioning Secure Process accepted a protocol version for communicationDebugN
42Event ID 42OperationalN
43Provisioning Secuity Process failed to predict the UEFI Secure Boot variables …DebugN
43Event ID 43OperationalN
44Provisioning Secuity Process detected a mismatched UEFI db variable on the …DebugN
44Event ID 44OperationalN
45Provisioning Secuity Process detected a mismatched UEFI dbx variable on the …DebugN
45Event ID 45OperationalN
46Provisioning Secuity Process failed to match the target machine UEFI Secure Boot …DebugN
46Event ID 46OperationalN
47Provisioning Secuity Process failed to validate the target BootOS Provisioning …DebugN
47Event ID 47OperationalN
48Provisioning Secuity Process has failed to verify the target machine so no …DebugN
48Event ID 48OperationalN
49The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be …DebugN
49Event ID 49OperationalN
50The PDK decypted by PSP contains an RRK and a VMRK has been generatedDebugN
50Event ID 50OperationalN
51Processing the RRK failedDebugN
51Event ID 51OperationalN

Event ID 1: Provisioning Secure Process created

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process created.

Message #

Provisioning Secure Process created

Fields #

NameDescription
NtStatus UInt32

Event ID 1

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process created.

Fields #

NameDescription
NtStatus UInt32

Event ID 2: Provisioning Secure Process could not initialize based on the command line arguments

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not initialize based on the command line arguments.

Message #

Provisioning Secure Process could not initialize based on the command line arguments

Fields #

NameDescription
NtStatus UInt32

Event ID 2

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not initialize based on the command line arguments.

Fields #

NameDescription
NtStatus UInt32

Event ID 3: Provisioning Secure Process is closing

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process is closing.

Message #

Provisioning Secure Process is closing

Fields #

NameDescription
NtStatus UInt32

Event ID 3

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process is closing.

Fields #

NameDescription
NtStatus UInt32

Event ID 4: Provisioning Secure Process argument was TemplateNameFound.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process argument was TemplateNameFound.

Message #

Provisioning Secure Process argument was %1

Fields #

NameDescription
TemplateNameFound UnicodeString

Event ID 4

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process argument was.

Fields #

NameDescription
TemplateNameFound UnicodeString

Event ID 5: Provisioning Secure Process was not provided the expected argument and will exit

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process was not provided the expected argument and will exit.

Message #

Provisioning Secure Process was not provided the expected argument and will exit

Fields #

NameDescription
NtStatus UInt32

Event ID 5

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process was not provided the expected argument and will exit.

Fields #

NameDescription
NtStatus UInt32

Event ID 6: Provisioning Secure Process was not provided the expected argument and will exit

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process was not provided the expected argument and will exit.

Message #

Provisioning Secure Process was not provided the expected argument and will exit

Fields #

NameDescription
TemplateNameFound UnicodeString

Event ID 6

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process was not provided the expected argument and will exit.

Fields #

NameDescription
TemplateNameFound UnicodeString

Event ID 7: Provisioning Secure Process parsed the command line arguments as MachineID.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process parsed the command line arguments as MachineID.

Message #

Provisioning Secure Process parsed the command line arguments as %1

Fields #

NameDescription
MachineID GUID

Event ID 7

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process parsed the command line arguments as.

Fields #

NameDescription
MachineID GUID

Event ID 8: Provisioning Secure Process could not set the trustlet identity and must exit

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not set the trustlet identity and must exit.

Message #

Provisioning Secure Process could not set the trustlet identity and must exit

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 8

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not set the trustlet identity and must exit.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 9: Provisioning Secure Process could not initialize the remote TPM assets and must exit

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not initialize the remote TPM assets and must exit.

Message #

Provisioning Secure Process could not initialize the remote TPM assets and must exit

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 9

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not initialize the remote TPM assets and must exit.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 10: Provisioning Secure Process could not initialize the RPC server

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not initialize the RPC server.

Message #

Provisioning Secure Process could not initialize the RPC server

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 10

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not initialize the RPC server.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 11: Provisioning Secure Process could not register with the RPC server

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not register with the RPC server.

Message #

Provisioning Secure Process could not register with the RPC server

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 11

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not register with the RPC server.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 12: Provisioning Secure Process transitioned to state EndState.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process transitioned to state EndState.

Message #

Provisioning Secure Process transitioned to state %5

Fields #

NameDescription
MachineID GUID
TransitionTime FILETIME
ValidStartState Boolean
StartState UInt8
EndState UInt8

Event ID 12

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process transitioned to state.

Fields #

NameDescription
MachineID GUID
TransitionTime FILETIME
ValidStartState Boolean
StartState UInt8
EndState UInt8

Event ID 13: Provisioning Secure Process transitioned to state EndState.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process transitioned to state EndState.

Message #

Provisioning Secure Process transitioned to state %5

Fields #

NameDescription
MachineID GUID
TransitionTime FILETIME
ValidStartState Boolean
StartState UInt8
EndState UInt8
ActionPriority UInt32
ActionStartingState UInt8
ActionNewState UInt8
ActionType UInt8

Event ID 13

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process transitioned to state.

Fields #

NameDescription
MachineID GUID
TransitionTime FILETIME
ValidStartState Boolean
StartState UInt8
EndState UInt8
ActionPriority UInt32
ActionStartingState UInt8
ActionNewState UInt8
ActionType UInt8

Event ID 14: Provisioning Secure Process is not running within IUM.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process is not running within IUM. This degrades security.

Message #

Provisioning Secure Process is not running within IUM. This degrades security.

Fields #

NameDescription
MachineID GUID

Event ID 14

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process is not running within IUM. This degrades security.

Fields #

NameDescription
MachineID GUID

Event ID 15: Provisioning Secure Process received a message from source SourceGroup of length Length.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a message from source SourceGroup of length Length.

Message #

Provisioning Secure Process received a message from source %2 of length %3.

Fields #

NameDescription
MachineID GUID
SourceGroup UInt8
Length UInt32

Event ID 15

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a message from source of length .

Fields #

NameDescription
MachineID GUID
SourceGroup UInt8
Length UInt32

Event ID 16: Provisioning Secure Process received a request for the PDK.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a request for the PDK.

Message #

Provisioning Secure Process received a request for the PDK.

Fields #

NameDescription
MachineID GUID

Event ID 16

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a request for the PDK.

Fields #

NameDescription
MachineID GUID

Event ID 17: Provisioning Secure Process is sending the PDK to the provisioning agent.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process is sending the PDK to the provisioning agent.

Message #

Provisioning Secure Process is sending the PDK to the provisioning agent.

Fields #

NameDescription
MachineID GUID

Event ID 17

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process is sending the PDK to the provisioning agent.

Fields #

NameDescription
MachineID GUID

Event ID 18: Provisioning Secure Process has sent the encrypted PDK to the virtual machine.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process has sent the encrypted PDK to the virtual machine.

Message #

Provisioning Secure Process has sent the encrypted PDK to the virtual machine.

Fields #

NameDescription
MachineID GUID

Event ID 18

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process has sent the encrypted PDK to the virtual machine.

Fields #

NameDescription
MachineID GUID

Event ID 19: Provisioning Secure Process received a PDK that was invalid or could not be decrypted.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a PDK that was invalid or could not be decrypted.

Message #

Provisioning Secure Process received a PDK that was invalid or could not be decrypted.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 19

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a PDK that was invalid or could not be decrypted.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 20: Provisioning Secure Process encountered an error while processing the EFI database.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while processing the EFI database.

Message #

Provisioning Secure Process encountered an error while processing the EFI database.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 20

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while processing the EFI database.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 21: Provisioning Secure Process encountered an error while generating the server key and cannot continue.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while generating the server key and cannot continue.

Message #

Provisioning Secure Process encountered an error while generating the server key and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 21

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while generating the server key and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 22: Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.

Message #

Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 22

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while extending the Secure Boot PCR and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 23: Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.

Message #

Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 23

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while extending the Boot Lock PCR and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 24: Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.

Message #

Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 24

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while accessing secure storage and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 25: Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.

Message #

Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 25

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while working with the remote TPM and cannot continue.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 26: Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.

Message #

Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 26

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while working with the remote RTPM key and cannot authenticate the PDK.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 27: Provisioning Secure Process encountered an error while attempting miniature attestation.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while attempting miniature attestation.

Message #

Provisioning Secure Process encountered an error while attempting miniature attestation.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 27

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while attempting miniature attestation.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 28: Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.

Message #

Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 28

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process encountered an error while creating and sending the provisioning message to the provisioning agent.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 29: Provisioning Secure Process could not collect necessary security info from the secure kernel.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process could not collect necessary security info from the secure kernel.

Message #

Provisioning Secure Process could not collect necessary security info from the secure kernel.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 29

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process could not collect necessary security info from the secure kernel.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 30: Provisioning Secure Process is populating the boot authority information from the template.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process is populating the boot authority information from the template.

Message #

Provisioning Secure Process is populating the boot authority information from the template.

Fields #

NameDescription
MachineID GUID

Event ID 30

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process is populating the boot authority information from the template.

Fields #

NameDescription
MachineID GUID

Event ID 31: Provisioning Secure Process will allow the UEFI certificate authority for this boot.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process will allow the UEFI certificate authority for this boot.

Message #

Provisioning Secure Process will allow the UEFI certificate authority for this boot.

Fields #

NameDescription
MachineID GUID

Event ID 31

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process will allow the UEFI certificate authority for this boot.

Fields #

NameDescription
MachineID GUID

Event ID 32: Provisioning Secure Process attestation error - PCR PcrIndex, error DiagnosticEventId.

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process attestation error - PCR PcrIndex, error DiagnosticEventId.

Message #

Provisioning Secure Process attestation error - PCR %2, error %3

Fields #

NameDescription
MachineID GUID
PcrIndex UInt32
DiagnosticEventId UInt32
Name UnicodeString
AuthoritativeEventOrder UInt32
AuthoritativeEventLength UInt32
AuthoritativeEvent Binary
AttestationEventOrder UInt32
AttestationEventLength UInt32
AttestationEvent Binary

Event ID 32

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process attestation error - PCR , error.

Fields #

NameDescription
MachineID GUID
PcrIndex UInt32
DiagnosticEventId UInt32
Name UnicodeString
AuthoritativeEventOrder UInt32
AuthoritativeEventLength UInt32
AuthoritativeEvent Binary
AttestationEventOrder UInt32
AttestationEventLength UInt32
AttestationEvent Binary

Event ID 33: Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included)

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included).

Message #

Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included)

Fields #

NameDescription
MachineID GUID
NtStatus UInt32
BlobSize UInt32
Blob Binary

Event ID 33

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a PDK that was invalid or could not be decrypted (payload included).

Fields #

NameDescription
MachineID GUID
NtStatus UInt32
BlobSize UInt32
Blob Binary

Event ID 34: Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted.

Message #

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted

Fields #

NameDescription
MachineID GUID

Event ID 34

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted.

Fields #

NameDescription
MachineID GUID

Event ID 35: Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included)

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included).

Message #

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included)

Fields #

NameDescription
MachineID GUID
BlobSize UInt32
Blob Binary

Event ID 35

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a message from NMPS that was invalid or could not be interpreted (payload included).

Fields #

NameDescription
MachineID GUID
BlobSize UInt32
Blob Binary

Event ID 36: Provisioning Secure Process received a message that was invalid or could not be interpreted

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a message that was invalid or could not be interpreted.

Message #

Provisioning Secure Process received a message that was invalid or could not be interpreted

Fields #

NameDescription
MachineID GUID

Event ID 36

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a message that was invalid or could not be interpreted.

Fields #

NameDescription
MachineID GUID

Event ID 37: Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included)

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included).

Message #

Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included)

Fields #

NameDescription
MachineID GUID
BlobSize UInt32
Blob Binary

Event ID 37

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received a message that was invalid or could not be interpreted (payload included).

Fields #

NameDescription
MachineID GUID
BlobSize UInt32
Blob Binary

Event ID 38: Provisioning Secure Process is starting the version negotiation with the provisioning agent

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process is starting the version negotiation with the provisioning agent.

Message #

Provisioning Secure Process is starting the version negotiation with the provisioning agent

Fields #

NameDescription
MachineID GUID

Event ID 38

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process is starting the version negotiation with the provisioning agent.

Fields #

NameDescription
MachineID GUID

Event ID 39: Provisioning Secure Process received version information from the provisioning agent

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process received version information from the provisioning agent.

Message #

Provisioning Secure Process received version information from the provisioning agent

Fields #

NameDescription
MachineID GUID
VersionNegotiationVersion UInt8
DeclaredVersionMajor UInt16
DeclaredVersionMinor UInt16
DeclaredVersionBuild UInt16
DeclaredVersionRelease UInt16
DeclaredVersionLogicalMajor UInt8
DeclaredVersionLogicalMinor UInt8
AcceptableVersionStartMajor UInt8
AcceptableVersionStartMinor UInt8

Event ID 39

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process received version information from the provisioning agent.

Fields #

NameDescription
MachineID GUID
VersionNegotiationVersion UInt8
DeclaredVersionMajor UInt16
DeclaredVersionMinor UInt16
DeclaredVersionBuild UInt16
DeclaredVersionRelease UInt16
DeclaredVersionLogicalMajor UInt8
DeclaredVersionLogicalMinor UInt8
AcceptableVersionStartMajor UInt8
AcceptableVersionStartMinor UInt8

Event ID 40: Provisioning Secure Process declared version information

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process declared version information.

Message #

Provisioning Secure Process declared version information

Fields #

NameDescription
MachineID GUID
DeclaredVersionMajor UInt16
DeclaredVersionMinor UInt16
DeclaredVersionBuild UInt16
DeclaredVersionRelease UInt16
DeclaredVersionLogicalMajor UInt8
DeclaredVersionLogicalMinor UInt8

Event ID 40

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process declared version information.

Fields #

NameDescription
MachineID GUID
DeclaredVersionMajor UInt16
DeclaredVersionMinor UInt16
DeclaredVersionBuild UInt16
DeclaredVersionRelease UInt16
DeclaredVersionLogicalMajor UInt8
DeclaredVersionLogicalMinor UInt8

Event ID 41: Provisioning Secure Process finished negotiating the protocol version

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process finished negotiating the protocol version.

Message #

Provisioning Secure Process finished negotiating the protocol version

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 41

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process finished negotiating the protocol version.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 42: Provisioning Secure Process accepted a protocol version for communication

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secure Process accepted a protocol version for communication.

Message #

Provisioning Secure Process accepted a protocol version for communication

Fields #

NameDescription
MachineID GUID
AcceptedVersionStartMajor UInt8
AcceptedVersionStartMinor UInt8

Event ID 42

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secure Process accepted a protocol version for communication.

Fields #

NameDescription
MachineID GUID
AcceptedVersionStartMajor UInt8
AcceptedVersionStartMinor UInt8

Event ID 43: Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation.

Message #

Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 43

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process failed to predict the UEFI Secure Boot variables from the launch authority returned from attestation.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 44: Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy.

Message #

Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy

Fields #

NameDescription
MachineID GUID

Event ID 44

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process detected a mismatched UEFI db variable on the target and is prevented from adopting this value by policy.

Fields #

NameDescription
MachineID GUID

Event ID 45: Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy.

Message #

Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy

Fields #

NameDescription
MachineID GUID

Event ID 45

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process detected a mismatched UEFI dbx variable on the target and is prevented from adopting this value by policy.

Fields #

NameDescription
MachineID GUID

Event ID 46: Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration.

Message #

Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 46

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process failed to match the target machine UEFI Secure Boot configuration.

Fields #

NameDescription
MachineID GUID
NtStatus UInt32

Event ID 47: Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version.

Message #

Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version

Fields #

NameDescription
MachineID GUID

Event ID 47

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process failed to validate the target BootOS Provisioning Agent scenario ID and version.

Fields #

NameDescription
MachineID GUID

Event ID 48: Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail.

Message #

Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail

Fields #

NameDescription
MachineID GUID

Event ID 48

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Provisioning Secuity Process has failed to verify the target machine so no Machine Key will be produced, provisioning will fail.

Fields #

NameDescription
MachineID GUID

Event ID 49: The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated.

Message #

The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated

Fields #

NameDescription
MachineID GUID

Event ID 49

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

The PDK decypted by PSP does not contain an RRK and therefore no VMRK will be generated.

Fields #

NameDescription
MachineID GUID

Event ID 50: The PDK decypted by PSP contains an RRK and a VMRK has been generated

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

The PDK decypted by PSP contains an RRK and a VMRK has been generated.

Message #

The PDK decypted by PSP contains an RRK and a VMRK has been generated

Fields #

NameDescription
MachineID GUID

Event ID 50

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

The PDK decypted by PSP contains an RRK and a VMRK has been generated.

Fields #

NameDescription
MachineID GUID

Event ID 51: Processing the RRK failed

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Debug

Description

Processing the RRK failed.

Message #

Processing the RRK failed

Fields #

NameDescription
MachineID GUID

Event ID 51

#
Provider
Microsoft-Windows-ShieldedVM-ProvisioningSecureProcess
Channel
Operational

Description

Processing the RRK failed.

Fields #

NameDescription
MachineID GUID