Microsoft-Windows-ShieldedVM-ProvisioningService
181 events across 2 channels
Event ID 0: Cannot continue because a failure occurred while provisioning.
#Event ID 1: A general error occurred while provisioning the machine.
#Event ID 2: Cannot provision because the Shielded VM provisioning data cannot be decrypted.
#Event ID 3: Cannot provision because the data from the remote TPM reflects an insecure state.
#Event ID 4: Cannot provision because an error was detected while communicating with the target machine.
#Event ID 5: Cannot continue because the target machine detected a TPM failure.
#Event ID 6: Cannot continue because the provisioning agent was unable to retrieve the provisioning data due to a key error.
#Event ID 7: Cannot provision because the template disk attached to the machine is invalid.
#Event ID 8: Cannot provision because the volume signature catalog from the template disk is not properly signed.
#Event ID 9: Cannot provision because the provided Shielded VM provisioning data is not applicable to the template disk.
#Description
Cannot provision because the provided Shielded VM provisioning data is not applicable to the template disk. Retry with an applicable template disk or update your provisioning data.
Message #
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
NtStatus UInt32 | |
TemplateNameFound UnicodeString | |
TemplateVersionFound HexInt64 |
Event ID 10: The template manager has determined that the template disk signature is invalid.
#Event ID 11: Unable to continue because a failure occurred while attempting to rekey the encryption on the operating system volume in the template disk.
#Event ID 12: An error occurred while processing the Shielded VM provisioning data content.
#Event ID 13: Cannot provision because the Shielded VM provisioning data failed to write to disk.
#Event ID 14: The target machine?
#Event ID 15: Cannot continue because the provided Shielded VM provisioning data failed to load due to invalid content.
#Event ID 16: Cannot continue because the remote machine disconnected unexpectedly.
#Event ID 17: Cannot continue because a failure occurred when accessing the secure storage.
#Event ID 18: Cannot provision because the volume signature catalog from the template disk is not properly signed.
#Event ID 19: Unable to create the Unattend.
#Event ID 20: An error occurred while processing the Shielded VM provisioning data content.
#Event ID 21: Cannot continue because Virtual Machine attestation failed during provisioning from template.
#Event ID 22: Cannot continue because a failure occurred while calculating a hash of the template disk.
#Event ID 23: Cannot continue because the signature file in the template disk is missing.
#Event ID 24: Cannot continue because the TPM is missing the SRK.
#Event ID 25: Provisioning cannot continue because the provisioning security process could not be launched.
#Event ID 26: Provisioning cannot continue because the template disk does not have an expected volume signature catalog file and this has not been authorized by ...
#Event ID 27: Provisioning cannot continue because the template disk has an unexpected volume signature catalog file and the provisioning data does not authorize...
#Event ID 28: Provisioning cannot continue because the disk associated with the provisioned VM could not be protected.
#Event ID 29: Provisioning cannot continue because the operating system associated with the provisioned VM could not be updated to support appropriate security m...
#Event ID 30: Provisioning cannot continue because the sealing values associated with the current boot configuration could not be properly predicted.
#Event ID 31: Provisioning cannot continue because the initialization data required by the boot configuration process could not be updated.
#Event ID 32: Provisioning may not continue because the UEFI database could not be loaded.
#Event ID 33: Provisioning may not continue because a launch authority could not be calculated.
#Event ID 34: Provisioning failed to extend the secure boot PCR.
#Event ID 35: Provisioning failed to extend the boot lock PCR.
#Event ID 36: Provisioning could not generate the server key or TPM operations.
#Event ID 37: The version of communication required by Provisioning was not understood by the template disk.
#Event ID 38: The template disk uses a version of communication not allowed by Provisioning.
#Event ID 39: Msps_ProvisioningService: Timeout detected.
#Event ID 40: An error was provided to the provisioning service of behalf of another component: MachineGuid.
#Event ID 41: The attempt to prepare the specialized machine failed.
#Event ID 42: Provisioning agent reported a failure to unwrap the protected data.
#Event ID 43: The target has been deemed unhealthy or not secure by attestation, provisioning will not complete.
#Event ID 44: Due to prior health assessment operations the provisioning security process has determined that it is not safe to generate a machine key.
#Event ID 45: The provisioning service received a connection request from an unknown machine.
#Event ID 46: The provisioning service received a connection request from a machine in an invalid state.
#Event ID 47: The virtual machine cannot be shielded because its virtual disk identifier appears to be the same as the virtual disk identifier used by the shield...
#Event ID 48: The VM boot disk is a differencing disk which is not supported by the preparation process for security reasons
#Event ID 301: WMI call failed.
#Event ID 301
#Description
WMI call failed. Failure to execute : MI_Result.
Fields #
| Name | Description |
|---|---|
String AnsiString | |
ErrorCode UInt32 |
Event ID 302: WMI call failed.
#Event ID 302
#Description
WMI call failed. Failure to execute : Win32_Result.
Fields #
| Name | Description |
|---|---|
String AnsiString | |
ErrorCode UInt32 |
Event ID 303: Msps_ProvisioningService: Shielded VM provisioning session started.
#Event ID 304: Msps_ProvisioningService: Failed to start Shielded VM provisioning session.
#Event ID 305: Msps_ProvisioningService: Failed to start Shielded VM provisioning session.
#Event ID 306: Msps_ProvisioningService: Shielded VM provisioning session opened.
#Event ID 307: Msps_ProvisioningService: Shielded VM provisioning session closed.
#Event ID 308: Msps_ProvisioningJob removed.
#Event ID 309: Msps_ProvisioningService service activated.
#Description
Msps_ProvisioningService service activated.
Message #
Event ID 309
#Description
Msps_ProvisioningService service activated.
Event ID 310: Msps_ProvisioningService service completed.
#Description
Msps_ProvisioningService service completed.
Message #
Event ID 310
#Description
Msps_ProvisioningService service completed.
Event ID 311: Msps_ProvisioningJob: Received request to retrieve job.
#Event ID 311
#Description
Msps_ProvisioningJob: Received request to retrieve job.
Fields #
| Name | Description |
|---|---|
MachineID UnicodeString |
Event ID 312: Msps_ProvisioningJob: Received request to delete job.
#Event ID 312
#Description
Msps_ProvisioningJob: Received request to delete job.
Fields #
| Name | Description |
|---|---|
MachineID UnicodeString |
Event ID 313: Msps_ProvisioningJob found Uint instances.
#Event ID 400: The provisioning process logged an unknown event.
#Event ID 401: The provisioning data has been received over the secure channel.
#Event ID 402: The fabric data has been received over the secure channel.
#Event ID 403: The provisioning data was successfully transferred over the secure channel.
#Event ID 404: The secure inputs are being processed by the provisioning service.
#Event ID 405: The VM being provisioned is communicating with the remote TPM.
#Event ID 406: Provisioning started.
#Event ID 407: The Shielded VM was successfully provisioned.
#Event ID 408: The template manager is analyzing the template disk.
#Event ID 409: The template manager finished analyzing the template disk.
#Event ID 410: The template manager is sealing the template disk.
#Event ID 411: The template manager has sealed the template disk.
#Event ID 412: The specialization agent is applying the fabric data to the template disk.
#Event ID 413: The specialization agent has finished applying the fabric data to the template disk.
#Event ID 414: The provisioning agent has started executing the plugins for the Shielded VM.
#Event ID 415: The provisioning agent has finished executing the plugins for the Shielded VM.
#Event ID 416: A specialization value was replaced in the Shielded VM's unattend file.
#Event ID 417: The provisioning agent was started and is communicating with the host machine.
#Event ID 418: The provisioning process was started within the Shielded VM and is communicating with the host machine.
#Event ID 419: The UEFI variables were received by the provisioning process.
#Event ID 420: An attestation event was received from the provisioning process.
#Event ID 421: A diagnostic attestation event was received from the provisioning process.
#Event ID 422: No instance of Name was found in the unattend file included in the provisioning data.
#Event ID 423: The template manager is skipping verification of the signature catalog on disk because it does not exist and the provisioning data allows this Mach...
#Event ID 424: The template manager is skipping verification of the signature catalog on disk because it does not exist and the provisioning data allows this Mach...
#Event ID 425: The template manager has updated the factory policy of the provisioned VM Machine ID.
#Event ID 426: The template manager has set the sealing values of the provisioned VM Machine ID.
#Event ID 427: The provisioning agent is starting the Execute pass on the provisioned VM Machine ID.
#Event ID 428: The provisioning agent has finished the Execute pass on the provisioned VM Machine ID.
#Event ID 429: The provisioning agent has finished the platform update on the provisioned VM Machine ID.
#Event ID 430: The provisioning agent is starting to predict the sealing values of the provisioned VM Machine ID.
#Event ID 431: The provisioning agent is starting the Finalize pass on the provisioned VM Machine ID.
#Event ID 432: The provisioning agent has finished the Finalize pass on the provisioned VM Machine ID.
#Event ID 433: The provisioning agent is allowed to use the UEFI CA per current policy Machine ID.
#Event ID 434: The provisioning service is selecting a launch authority Machine ID.
#Event ID 434
#Description
The provisioning service is selecting a launch authority.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 435: The template disk has declared its current version for the purposes of negotiation.
#Description
The template disk has declared its current version for the purposes of negotiation.
Message #
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
VersionNegotiationVersion UInt8 | |
DeclaredVersionMajor UInt16 | |
DeclaredVersionMinor UInt16 | |
DeclaredVersionBuild UInt16 | |
DeclaredVersionRelease UInt16 | |
DeclaredVersionLogicalMajor UInt8 | |
DeclaredVersionLogicalMinor UInt8 | |
AcceptableVersionStartMajor UInt8 | |
AcceptableVersionStartMinor UInt8 |
Event ID 436: The provisioning service has accepted a communications version supported by the template disk
#Event ID 437: Received status update from the template manager.
#Event ID 437
#Description
Received status update from the template manager.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
uint UInt32 | |
uint2 UInt32 |
Event ID 438: The template manager successfully validated the image hash.
#Event ID 439: The template manager completed rolling the FVEK.
#Event ID 440: The template manager successfully protected the volume.
#Event ID 441: The provisioning Agent encountered an unknown data section.
#Event ID 441
#Description
The provisioning Agent encountered an unknown data section.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
PDKDestinationID GUID | |
PDKSectionID GUID |
Event ID 442: An external BitLocker key was created for a template volume.
#Event ID 443: An encrypted BitLocker external key for a template volume was written to disk.
#Event ID 500: Ptp Session Event.
#Event ID 500
#Description
Ptp Session Event.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
Source UInt32 | |
DiagnosticID UInt32 | |
FailureID UInt32 |
Event ID 501: Ptp Session Event.
#Event ID 501
#Description
Ptp Session Event.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
Source UInt32 | |
DiagnosticID UInt32 | |
FailureID UInt32 |
Event ID 502: Invalid payload in error notification.
#Event ID 502
#Description
Invalid payload in error notification.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
uint UInt32 |
Event ID 503: Invalid attestation payload in notification.
#Event ID 503
#Description
Invalid attestation payload in notification.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
uint UInt32 |
Event ID 504: uint attestation items received from the attestation diagnostics log.
#Event ID 504
#Description
attestation items received from the attestation diagnostics log.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
uint UInt32 |
Event ID 505: An attestation log item was too short to be valid (uint bytes).
#Event ID 505
#Description
An attestation log item was too short to be valid ( bytes).
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
uint UInt32 |
Event ID 506: The authoritative event log was deemed invalid.
#Event ID 506
#Description
The authoritative event log was deemed invalid.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 507: The authoritative event log is missing an event.
#Event ID 507
#Description
The authoritative event log is missing an event.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 508: The attestation log is missing an event.
#Event ID 508
#Description
The attestation log is missing an event.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 509: The data in the attestation event is incorrect.
#Event ID 509
#Description
The data in the attestation event is incorrect.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 510: The attestation log is invalid.
#Event ID 511: An unexpected attestation event was encountered.
#Event ID 511
#Description
An unexpected attestation event was encountered.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 512: The attestation log contained an event which was incorrect.
#Event ID 512
#Description
The attestation log contained an event which was incorrect.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 513: The attestation event log contains an unknown event.
#Event ID 513
#Description
The attestation event log contains an unknown event. The event ID was .
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
uint UInt32 |
Event ID 514: An attestation event log item is corrupt.
#Event ID 514
#Description
An attestation event log item is corrupt.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 515: The name of the attestation event log item is Name.
#Event ID 515
#Description
The name of the attestation event log item is .
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | |
Name UnicodeString |
Event ID 516: The attestation event log item name has no name information.
#Event ID 516
#Description
The attestation event log item name has no name information.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 517: The attestation event log item WCBL payload appears corrupt.
#Event ID 517
#Description
The attestation event log item WCBL payload appears corrupt.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 518: PCR Index: PCRIndex, Zero-based order relative to PCR: RelativeOrderToPCR, Event: Event, Length: Length.
#Event ID 518
#Description
PCR Index: , Zero-based order relative to PCR: , Event: , Length.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
PCRIndex UInt32 | |
RelativeOrderToPCR UInt32 | |
Event UInt32 | |
Length UInt32 |
Event ID 519: The event data is too short or otherwise corrupt and does not contain a TrEE variable.
#Event ID 519
#Description
The event data is too short or otherwise corrupt and does not contain a TrEE variable.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |
Event ID 520: TrEE authoritative variable data payload found.
#Event ID 520
#Description
TrEE authoritative variable data payload found.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
Namespace GUID | |
UnicodeName UnicodeString | |
DataLength UInt32 | |
Data Binary |
Event ID 521: TrEE attestation variable data payload found.
#Event ID 521
#Description
TrEE attestation variable data payload found.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
Namespace GUID | |
UnicodeName UnicodeString | |
DataLength UInt32 | |
Data Binary |
Event ID 522: The process of converting an existing VM has started.
#Event ID 522
#Description
The process of converting an existing VM has started.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID | |
Name UnicodeString |
Event ID 523: A call has failed during the conversion process.
#Event ID 523
#Description
A call has failed during the conversion process.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
Name UnicodeString | |
Win32ErrorCode UInt32 |
Event ID 524: The temporary VM will be named Name.
#Event ID 524
#Description
The temporary VM will be named .
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
Name UnicodeString |
Event ID 525: The original VM's boot disk is at Name.
#Event ID 525
#Description
The original VM's boot disk is at .
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
Name UnicodeString |
Event ID 526: The temporary VM has been created with identifier Name.
#Event ID 526
#Description
The temporary VM has been created with identifier .
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
Name UnicodeString |
Event ID 527: The disk at Name has been added to the temporary VM.
#Event ID 527
#Description
The disk at has been added to the temporary VM.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
Name UnicodeString |
Event ID 528: A KVP value has been retrieved from the temporary VM: Name / Value.
#Event ID 528
#Description
A KVP value has been retrieved from the temporary VM: /.
Fields #
| Name | Description |
|---|---|
MachineID GUID | |
Name UnicodeString | |
Value UnicodeString |
Event ID 529: The target UEFI db variable does not match the expected value and adoption is blocked by policy.
#Event ID 530: The target UEFI dbx variable does not match the expected value and adoption is blocked by policy.
#Event ID 531: Provisioning is unable to verify the Provisioning Agent stack version in the target.
#Event ID 532: The grandfathering utility disk and the boot disk of the original VM appear to be unique.
#Event ID 532
#Description
The grandfathering utility disk and the boot disk of the original VM appear to be unique.
Fields #
| Name | Description |
|---|---|
MachineGuid GUID |