Microsoft-Windows-TaskScheduler

EventTitleChannelSampleRule
100Task Scheduler started "UserContext" instance of the "Name" task for user …OperationalYN
101Task Scheduler failed to start "Name" task for user "TaskName".OperationalYN
102Task Scheduler successfully finished "UserContext" instance of the "Name" task …OperationalYN
103Task Scheduler failed to start instance "TaskName" of "Name" task for user …OperationalYN
104Task Scheduler failed to log on "UserName" .OperationalNN
105Task Scheduler failed to impersonate "Context" .OperationalNN
106User "TaskName" registered Task Scheduler task "Name".OperationalYN
107Task Scheduler launched "TaskName" instance of task "Name" due to a time trigger …OperationalYN
108Task Scheduler launched "TaskName" instance of task "Name" according to an event …OperationalYN
109Task Scheduler launched "TaskName" instance of task "Name" according to a …OperationalYN
110Task Scheduler launched "TaskName" instance of task "Name" for user "InstanceId" …OperationalYN
111Task Scheduler terminated "TaskName" instance of the "Name" task.OperationalYN
112Task Scheduler could not start task "TaskName" because the network was …OperationalNN
113Task registered task "TaskName" , but not all specified triggers will start the …OperationalNN
114Task Scheduler could not launch task "Name" as scheduled.OperationalYN
115Task Scheduler failed to roll back a transaction when updating or deleting a …OperationalNN
116Task Scheduler validated the configuration for task "TaskName" , but credentials …OperationalNN
117Task Scheduler launched "InstanceId" instance of task "TaskName" due to an idle …OperationalNN
118Task Scheduler launched "TaskName" instance of task "Name" due to system …OperationalYN
119Task Scheduler launched "UserName" instance of task "Name" due to user …OperationalYN
120Task Scheduler launched "InstanceId" instance of task "TaskName" due to user …OperationalNN
121Task Scheduler launched "InstanceId" instance of task "TaskName" due to user …OperationalNN
122Task Scheduler launched "InstanceId" instance of task "TaskName" due to user …OperationalNN
123Task Scheduler launched "InstanceId" instance of task "TaskName" due to user …OperationalNN
124Task Scheduler launched "InstanceId" instance of task "TaskName" due to user …OperationalNN
125Task Scheduler launched "InstanceId" instance of task "TaskName" due to user …OperationalNN
126Task Scheduler failed to execute task "TaskName" .OperationalNN
127Task Scheduler failed to execute task "TaskName" due to a shutdown race …OperationalNN
128Task Scheduler did not launch task "TaskName" , because current time exceeds the …OperationalNN
129Task Scheduler launch task "Name" , instance "TaskName" with process ID Path.OperationalYY
130Task Scheduler failed to start task "TaskName" due to the service being busy.OperationalNN
131Task Scheduler failed to start task "TaskName" because the number of tasks in …OperationalNN
132Task Scheduler task launching queue quota is approaching its preset limit of …OperationalNN
133Task Scheduler failed to start task TaskName" in TaskEngine "TaskEngineName" for …OperationalNN
134Task Engine "TaskEngineName" for user "UserName" is approaching its preset limit …OperationalNN
135Task Scheduler could not start task "TaskName" because the machine was not idle.OperationalNN
140User "TaskName" updated Task Scheduler task "Name".OperationalYY
141User "TaskName" deleted Task Scheduler task "Name".OperationalYY
142User "TaskName" disabled Task Scheduler task "Name".OperationalYY
145Task Scheduler woke up the computer to run a task.OperationalNN
146Task Scheduler failed to load task "TaskName" at service startup.OperationalYN
147Task Scheduler recovered sucessfully the image of task "TaskName" after a …OperationalNN
148Task Scheduler failed to recover the image of task "TaskName" after a corruption …OperationalNN
149Task "TaskName" is using a combination of properties that is incompatible with …OperationalNN
150Task Scheduler failed to subscribe for the event trigger for task "TaskName".OperationalNN
151Task instantiation failed "TaskName".OperationalYN
152Task "TaskName" was re-directed to legacy scheduling engine.OperationalNN
153Task Scheduler did not launch task "Name" as it missed its schedule.OperationalYN
155Task Scheduler is currently waiting on completion of task "TaskPath".OperationalNN
200Task Scheduler launched action "TaskName" in instance "ActionName" of task …OperationalYY
201Task Scheduler successfully completed task "Name" , instance "TaskInstanceId" , …OperationalYY
202Task Scheduler failed to complete task "Name" , instance "TaskName" , action …OperationalYN
203Task Scheduler failed to launch action "TaskInstanceId" in instance "TaskName" …OperationalYN
204Task Scheduler failed to retrieve the event triggering values for task …OperationalNN
205Task Scheduler failed to match the pattern of events for task "TaskName" .OperationalNN
300Task Scheduler started Task Engine "TaskEngineName" with process ID ProcessID.OperationalNN
301Task Scheduler is shutting down Task Engine "TaskEngineName".OperationalNN
303Task Scheduler is shutting down Task Engine "TaskEngineName" due to an error in …OperationalNN
304Task Scheduler sent "TaskName" task to Task Engine "TaskEngineName" .OperationalNN
305Task Scheduler did not send "TaskName" task to Task Engine "TaskEngineName" .OperationalNN
306For Task Scheduler Task Engine "TaskEngineName" , the thread pool failed to …OperationalNN
307Task Scheduler service failed to connect to the Task Engine "TaskEngineName" …OperationalNN
308Task Scheduler connected to the Task Engine "TaskEngineName" process.OperationalNN
309Task Scheduler TaskCount tasks orphaned during Task Engine "TaskEngineName" …OperationalNN
310Task Scheduler started Task Engine "TaskEngineName" process.OperationalNN
311Task Scheduler failed to start Task Engine "TaskEngineName" process due to an …OperationalNN
312Task Scheduler created the Win32 job object for Task Engine "TaskEngineName" .OperationalNN
313Task Scheduler channel with Task Engine "TaskEngineName" is ready to send and …OperationalNN
314Task Scheduler has no tasks running for Task Engine "TaskEngineName" , and the …OperationalNN
315Task Engine "TaskEngineName" process failed to connect to the Task Scheduler …OperationalNN
316Task Engine "TaskEngineName" failed to send a message to the Task Scheduler …OperationalNN
317Task Scheduler started Task Engine "TaskEngineName" process.OperationalNN
318Task Scheduler shutdown Task Engine "TaskEngineName" process.OperationalNN
319Task Engine "TaskEngineName" received a message from Task Scheduler service …OperationalNN
320Task Engine "TaskEngineName" received a message from Task Scheduler service …OperationalNN
322Task Scheduler did not launch task "Name" because instance "TaskName" of the …OperationalYN
323Task Scheduler stopped instance "StoppedTaskInstanceId" of task "TaskName" in …OperationalNN
324Task Scheduler queued instance "TaskName" of task "Name" and will launch it as …OperationalYN
325Task Scheduler queued instance "TaskName" of task "Name".OperationalYN
326Task Scheduler did not launch task "TaskName" because computer is running on …OperationalNN
327Task Scheduler stopped instance "TaskInstanceId" of task "TaskName" because the …OperationalNN
328Task Scheduler stopped instance "TaskName" of task "Name" because computer is no …OperationalYN
329Task Scheduler terminated "TaskName" instance of the "Name" task due to …OperationalYN
330Task Scheduler stopped instance "TaskName" of task "Name" as request by user …OperationalYN
331Task Scheduler will continue to execute Instance "TaskInstanceId" of task …OperationalNN
332Task Scheduler did not launch task "Name" because user "TaskName" was not logged …OperationalYN
333Task Scheduler did not launch task "TaskName" because target session is …OperationalNN
334Task Scheduler did not launch task "TaskName" because target session is a WORKER …OperationalNN
400Task Scheduler service has started.OperationalYN
401Task Scheduler service failed to start due to an error in "ErrorDescription" .SystemNN
402Task Scheduler service is shutting down.OperationalYN
403Task Scheduler service has encountered an error in "ErrorDescription" .OperationalNN
404Task Scheduler service has encountered RPC initialization error in …SystemNN
405Task Scheduler service has failed to initialize COM.SystemNN
406Task Scheduler service failed to initialize credentials store.SystemNN
407Task Scheduler service failed to initialize LSA.SystemNN
408Task Scheduler service failed to initialize idle state detection module.SystemNN
409Task Scheduler service failed to initialize time change notification.SystemNN
410Task Scheduler service failed to set a wakeup timer.OperationalNN
411Task Scheduler service received a time system change notification.OperationalYN
412Task Scheduler service failed to launch tasks triggered by computer startup.SystemNN
413Task Scheduler service failed to load tasks at service startup.SystemNN
414Task Scheduler service found a misconfiguration in the TaskName definition.SystemNN
500Process ID ProcessId has registered idle task ID IdleTaskId.DiagnosticNN
501Process ID ProcessId has completed idle task ID IdleTaskId.DiagnosticNN
502Execution of idle task ID IdleTaskId has started.DiagnosticNN
503Execution of idle task ID IdleTaskId has ended.DiagnosticNN
504Idle task ID IdleTaskId has been notified that explicit processing has been …DiagnosticNN
505Idle task ID IdleTaskId has returned from its explicit processing notification.DiagnosticNN
506Explicit execution of all idle tasks has been requested.DiagnosticNN
507Explicit execution of all idle tasks has completed.DiagnosticNN
508Explicit execution of all idle tasks is in progress.DiagnosticNN
509Idle Task Power Notification Received: NotificationType (State).DiagnosticNN
510Idle Task PerfTrack Resource ConsumptionDiagnosticNN
511Idle Task PerfTrack Idle ExitDiagnosticNN
512Idle check point: State DetectionResult, Reason Reason.DiagnosticNN
700Task Scheduler service started Task Compatibility module.OperationalYN
701Task Scheduler service failed to start Task Compatibility module.SystemNN
702Task Scheduler failed to initialize the RPC server for starting the Task …SystemNN
703Task Scheduler failed to initialize Net Schedule API for starting the Task …SystemNN
704Task Scheduler failed to initialize LSA for starting the Task Compatibility …SystemNN
705Task Scheduler failed to start directory monitoring for the Task Compatibility …SystemNN
706Task Compatibility module failed to update task "TaskName" to the required …OperationalNN
707Task Compatibility module failed to delete task "TaskName" .OperationalNN
708Task Compatibility module failed to set security descriptor "SecurityDescriptor" …OperationalNN
709Task Compatibility module failed to update task "TaskName" .OperationalNN
710Task Compatibility module failed to upgrade existing tasks.OperationalNN
711Task Compatibility module failed to upgrade NetSchedule account "Account" .OperationalNN
712Task Compatibility module failed to read existing store to upgrade tasks.OperationalNN
713Task Compatibility module failed to load task "TaskName" for upgrade.OperationalNN
714Task Compatibility module failed to register task "TaskName" for upgrade.OperationalNN
715Task Compatibility module failed to delete LSA store for upgrade.OperationalNN
716Task Compatibility module failed to upgrade existing scheduled tasks.SystemNN
717Task Compatibility module failed to determine if upgrade is needed.OperationalNN
718Task scheduler was unable to upgrade the credential store from the Beta 2 …SystemNN
719To help optimize for performance, Task Scheduler has automatically disabled …SystemYN
800Maintenance state changed to Name (Last Run: hc_stateid).MaintenanceYN
801Maintenance launch operation failed.MaintenanceNN
802Maintenance re-configuration failed.MaintenanceNN
803Maintenance Scheduler engine task "Task" cannot be accessed.MaintenanceNN
804Maintenance Scheduler has detected cyclic dependency for the following …MaintenanceNN
805Maintenance Task "Task" is behind deadline.MaintenanceNN
806Maintenance task "Task" processing error.MaintenanceNN
807Maintenance complete (launch type LauncherId).MaintenanceNN
808Maintenance Task "Name" requests computer wakeup during next regular maintenance …MaintenanceYN
809Maintenance Scheduler Group Policy Settings are not properly specified for …SystemNN
998DEBUG!DebugNN
999DEBUG!DebugNN

Event ID 100: Task Scheduler started "UserContext" instance of the "Name" task for user "TaskName".

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
TaskStarted
Opcode
Start

Message #

Task Scheduler started "%3" instance of the "%1" task for user "%2".

Fields #

NameDescription
TaskName UnicodeString
UserContext UnicodeString
InstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 4,
    "task": 100,
    "opcode": 1,
    "keywords": -9223372036854775807,
    "time_created": "2026-06-13T14:08:20.0826406+00:00",
    "event_record_id": 8893,
    "correlation": {
      "ActivityID": "{315D0AE5-E095-4BA8-98CF-B8B7C2E4AD53}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 3336
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join",
    "UserContext": "NT AUTHORITY\\SYSTEM",
    "InstanceId": "{315d0ae5-e095-4ba8-98cf-b8b7c2e4ad53}"
  },
  "message": "Task Scheduler started \"{315d0ae5-e095-4ba8-98cf-b8b7c2e4ad53}\" instance of the \"\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join\" task for user \"NT AUTHORITY\\SYSTEM\"."
}

Event ID 101: Task Scheduler failed to start "Name" task for user "TaskName".

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Yamato Security, others)
Task
TaskStartFailed
Opcode
LaunchFailure

Description

Task Scheduler failed to start "Name" task for user "TaskName". Additional Data: Error Value: UserContext.

Message #

Task Scheduler failed to start "%1" task for user "%2". Additional Data: Error Value: %3.

Fields #

NameDescription
TaskName UnicodeString
UserContext UnicodeString
ResultCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 101,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 101,
    "keywords": -9223372036854775807,
    "time_created": "2026-05-29T01:33:23.8193364+00:00",
    "event_record_id": 6107,
    "correlation": {},
    "execution": {
      "process_id": 2072,
      "thread_id": 2408
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join",
    "UserContext": "(default user)",
    "ResultCode": "2147943568"
  },
  "message": "Task Scheduler failed to start \"\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join\" task for user \"(default user)\". Additional Data: Error Value: 2147943568."
}

Event ID 102: Task Scheduler successfully finished "UserContext" instance of the "Name" task for user "TaskName".

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
Taskcompleted
Opcode
Stop

Message #

Task Scheduler successfully finished "%3" instance of the "%1" task for user "%2".

Fields #

NameDescription
TaskName UnicodeString
UserContext UnicodeString
InstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 102,
    "version": 0,
    "level": 4,
    "task": 102,
    "opcode": 2,
    "keywords": -9223372036854775807,
    "time_created": "2026-06-13T14:08:20.3058652+00:00",
    "event_record_id": 8896,
    "correlation": {
      "ActivityID": "{315D0AE5-E095-4BA8-98CF-B8B7C2E4AD53}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 3336
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join",
    "UserContext": "NT AUTHORITY\\SYSTEM",
    "InstanceId": "{315d0ae5-e095-4ba8-98cf-b8b7c2e4ad53}"
  },
  "message": "Task Scheduler successfully finished \"{315d0ae5-e095-4ba8-98cf-b8b7c2e4ad53}\" instance of the \"\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join\" task for user \"NT AUTHORITY\\SYSTEM\"."
}

Event ID 103: Task Scheduler failed to start instance "TaskName" of "Name" task for user "InstanceId" .

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Yamato Security, others)
Task
Actionstartfailed
Opcode
RunFailure

Description

Task Scheduler failed to start instance "TaskName" of "Name" task for user "InstanceId" . Additional Data: Error Value: UserContext.

Message #

Task Scheduler failed to start instance "%2" of "%1"  task for user "%3" . Additional Data: Error Value: %4.

Fields #

NameDescription
TaskName UnicodeString
InstanceId GUID
UserContext UnicodeString
ResultCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 103,
    "version": 0,
    "level": 2,
    "task": 103,
    "opcode": 102,
    "keywords": -9223372036854775807,
    "time_created": "2026-06-13T05:40:05.7566555+00:00",
    "event_record_id": 7660,
    "correlation": {
      "ActivityID": "{762E45EA-0D91-4E66-8DF4-8CACEE9415D0}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 1432
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\International\\Synchronize Language Settings",
    "InstanceId": "{762e45ea-0d91-4e66-8df4-8cacee9415d0}",
    "UserContext": "cell-a\\domainadmin",
    "ResultCode": "2147746053"
  },
  "message": "Task Scheduler failed to start instance \"{762e45ea-0d91-4e66-8df4-8cacee9415d0}\" of \"\\Microsoft\\Windows\\International\\Synchronize Language Settings\"  task for user \"cell-a\\domainadmin\" . Additional Data: Error Value: 2147746053."
}

Event ID 104: Task Scheduler failed to log on "UserName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Logonfailure

Description

Task Scheduler failed to log on "UserName" . Failure occurred in "ErrorDescription" . User Action: Ensure the credentials for the task are correctly specified. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to log on "%1" . Failure occurred in "%2" . User Action: Ensure the credentials for the task are correctly specified. Additional Data: Error Value: %3.

Fields #

NameDescription
UserName UnicodeString
ErrorDescription UnicodeString
ResultCode UInt32

Event ID 105: Task Scheduler failed to impersonate "Context" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Impersonationfailure

Description

Task Scheduler failed to impersonate "Context" . Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to impersonate "%1" . Additional Data: Error Value: %2.

Fields #

NameDescription
Context UnicodeString
ResultCode UInt32

Event ID 106: User "TaskName" registered Task Scheduler task "Name".

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Microsoft-WEF, others)
Task
Taskregistered

Message #

User "%2"  registered Task Scheduler task "%1"

Fields #

NameDescription
TaskName UnicodeString
UserContext UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 106,
    "version": 0,
    "level": 4,
    "task": 106,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T06:01:41.4530033+00:00",
    "event_record_id": 7743,
    "correlation": {},
    "execution": {
      "process_id": 2100,
      "thread_id": 1676
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Windows Defender\\Windows Defender Scheduled Scan",
    "UserContext": "cell-a\\TELEMETRY-DC-A$"
  },
  "message": "User \"cell-a\\TELEMETRY-DC-A$\"  registered Task Scheduler task \"\\Microsoft\\Windows\\Windows Defender\\Windows Defender Scheduled Scan\""
}

References #

Event ID 107: Task Scheduler launched "TaskName" instance of task "Name" due to a time trigger condition.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredonscheduler

Message #

Task Scheduler launched "%2"  instance of task "%1" due to a time trigger condition.

Fields #

NameDescription
TaskName UnicodeString
InstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 107,
    "version": 0,
    "level": 4,
    "task": 107,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T13:45:14.1073764+00:00",
    "event_record_id": 8838,
    "correlation": {
      "ActivityID": "{4E01546D-F8D7-4F69-8DC9-CAE5178D108B}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 7932
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\MicrosoftEdgeUpdateTaskMachineUA",
    "InstanceId": "{4e01546d-f8d7-4f69-8dc9-cae5178d108b}"
  },
  "message": "Task Scheduler launched \"{4e01546d-f8d7-4f69-8dc9-cae5178d108b}\"  instance of task \"\\MicrosoftEdgeUpdateTaskMachineUA\" due to a time trigger condition."
}

Event ID 108: Task Scheduler launched "TaskName" instance of task "Name" according to an event trigger.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredonevent

Message #

Task Scheduler launched "%2"  instance of task "%1"  according to an event trigger.

Fields #

NameDescription
TaskName UnicodeString
InstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 108,
    "version": 0,
    "level": 4,
    "task": 108,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T14:08:20.0772782+00:00",
    "event_record_id": 8891,
    "correlation": {
      "ActivityID": "{315D0AE5-E095-4BA8-98CF-B8B7C2E4AD53}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 3336
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join",
    "InstanceId": "{315d0ae5-e095-4ba8-98cf-b8b7c2e4ad53}"
  },
  "message": "Task Scheduler launched \"{315d0ae5-e095-4ba8-98cf-b8b7c2e4ad53}\"  instance of task \"\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join\"  according to an event trigger."
}

Event ID 109: Task Scheduler launched "TaskName" instance of task "Name" according to a registration trigger.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredbyregistration

Message #

Task Scheduler launched "%2"  instance of task "%1"  according to a registration trigger.

Fields #

NameDescription
TaskName UnicodeString
InstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "DE7B24EA-73C8-4A09-985D-5BDADCFA9017",
    "event_source_name": "",
    "event_id": 109,
    "version": 0,
    "level": 4,
    "task": 109,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2022-04-07T16:57:17.740121+00:00",
    "event_record_id": 490,
    "correlation": {
      "ActivityID": "D9A56AB9-DA1B-4E8C-ABB6-0297EE74232D"
    },
    "execution": {
      "process_id": 1528,
      "thread_id": 932
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "RegistrationTriggerEvent",
    "TaskName": "\\CreateExplorerShellUnelevatedTask",
    "InstanceId": "D9A56AB9-DA1B-4E8C-ABB6-0297EE74232D"
  },
  "message": ""
}

Example keys not documented in the fields table: Name

References #

Event ID 110: Task Scheduler launched "TaskName" instance of task "Name" for user "InstanceId" .

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredbyuser

Message #

Task Scheduler launched "%2"  instance of task "%1"  for user "%3" .

Fields #

NameDescription
TaskName UnicodeString
InstanceId GUID
UserContext UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 110,
    "version": 0,
    "level": 4,
    "task": 110,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T16:32:57.5043898+00:00",
    "event_record_id": 6772,
    "correlation": {
      "ActivityID": "{B1CABF2C-522F-4352-81FE-E652A989531D}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 2360
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join",
    "InstanceId": "{b1cabf2c-522f-4352-81fe-e652a989531d}",
    "UserContext": "System"
  },
  "message": "Task Scheduler launched \"{b1cabf2c-522f-4352-81fe-e652a989531d}\"  instance of task \"\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join\"  for user \"System\" ."
}

References #

Event ID 111: Task Scheduler terminated "TaskName" instance of the "Name" task.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
Taskterminated
Opcode
Termination

Message #

Task Scheduler terminated "%2"  instance of the "%1"  task.

Fields #

NameDescription
TaskName UnicodeString
InstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 111,
    "version": 0,
    "level": 4,
    "task": 111,
    "opcode": 103,
    "keywords": -9223372036854775807,
    "time_created": "2026-05-29T08:44:12.4454670+00:00",
    "event_record_id": 6328,
    "correlation": {
      "ActivityID": "{9B5A34F6-ABB2-4FCC-83E4-4589AFF754C1}"
    },
    "execution": {
      "process_id": 2072,
      "thread_id": 5376
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Windows Defender\\Windows Defender Scheduled Scan",
    "InstanceId": "{9b5a34f6-abb2-4fcc-83e4-4589aff754c1}"
  },
  "message": "Task Scheduler terminated \"{9b5a34f6-abb2-4fcc-83e4-4589aff754c1}\"  instance of the \"\\Microsoft\\Windows\\Windows Defender\\Windows Defender Scheduled Scan\"  task."
}

Event ID 112: Task Scheduler could not start task "TaskName" because the network was unavailable.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Launchconditionnotmet,networkunavailable

Description

Task Scheduler could not start task "TaskName" because the network was unavailable. User Action: Ensure the computer is connected to the required network as specified in the task. If the task does not require network presence, remove the network condition from the task configuration.

Message #

Task Scheduler could not start task "%1"  because the network was unavailable. User Action: Ensure the computer is connected to the required network as specified in the task. If the task does not require network presence, remove the network condition from the task configuration.

Fields #

NameDescription
TaskName UnicodeString

Event ID 113: Task registered task "TaskName" , but not all specified triggers will start the task.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Taskregisteredwithoutsometriggers

Description

Task registered task "TaskName" , but not all specified triggers will start the task. User Action: Ensure all the task triggers are valid as configured. Additional Data: Error Value: ResultCode.

Message #

Task registered task "%1" , but not all specified triggers will start the task. User Action: Ensure all the task triggers are valid as configured. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 114: Task Scheduler could not launch task "Name" as scheduled.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security, others)
Task
Missedtaskstarted

Description

Task Scheduler could not launch task "Name" as scheduled. Instance "TaskName" is started now as required by the configuration option to start the task when available, if schedule is missed.

Message #

Task Scheduler could not launch task "%1"  as scheduled. Instance "%2"  is started now as required by the configuration option to start the task when available, if schedule is missed.

Fields #

NameDescription
TaskName UnicodeString
InstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 114,
    "version": 0,
    "level": 3,
    "task": 114,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:39:30.9213828+00:00",
    "event_record_id": 7463,
    "correlation": {
      "ActivityID": "{C93EA0EA-CF5F-4E04-A692-49DDD2E1162C}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 1212
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\UpdateOrchestrator\\USO_UxBroker",
    "InstanceId": "{c93ea0ea-cf5f-4e04-a692-49ddd2e1162c}"
  },
  "message": "Task Scheduler could not launch task \"\\Microsoft\\Windows\\UpdateOrchestrator\\USO_UxBroker\"  as scheduled. Instance \"{c93ea0ea-cf5f-4e04-a692-49ddd2e1162c}\"  is started now as required by the configuration option to start the task when available, if schedule is missed."
}

Event ID 115: Task Scheduler failed to roll back a transaction when updating or deleting a task.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Taskupdateordeletionerror

Description

Task Scheduler failed to roll back a transaction when updating or deleting a task. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to roll back a transaction when updating or deleting a task. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 116: Task Scheduler validated the configuration for task "TaskName" , but credentials could not be stored.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Taskregisteredwithoutcredentials

Description

Task Scheduler validated the configuration for task "TaskName" , but credentials could not be stored. User Action: Re-register the task ensuring the credentials are valid. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler validated the configuration for task "%1" , but credentials could not be stored. User Action: Re-register the task ensuring the credentials are valid. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 117: Task Scheduler launched "InstanceId" instance of task "TaskName" due to an idle condition.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
TasktriggeredonIdle

Message #

Task Scheduler launched "%2"  instance of task "%1"  due to an idle condition.

Fields #

NameDescription
TaskName UnicodeString
InstanceId GUID

Event ID 118: Task Scheduler launched "TaskName" instance of task "Name" due to system startup.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredbycomputerstartup

Message #

Task Scheduler launched "%2"  instance of task "%1"  due to system startup.

Fields #

NameDescription
TaskName UnicodeString
InstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 118,
    "version": 0,
    "level": 4,
    "task": 118,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T08:33:04.7625040+00:00",
    "event_record_id": 8112,
    "correlation": {
      "ActivityID": "{C30ADDB7-14CB-40BE-8F19-03A7020A4112}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 5192
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask",
    "InstanceId": "{c30addb7-14cb-40be-8f19-03a7020a4112}"
  },
  "message": "Task Scheduler launched \"{c30addb7-14cb-40be-8f19-03a7020a4112}\"  instance of task \"\\Microsoft\\Windows\\CertificateServicesClient\\SystemTask\"  due to system startup."
}

Event ID 119: Task Scheduler launched "UserName" instance of task "Name" due to user "TaskName" logon.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredonlogon

Message #

Task Scheduler launched "%3"  instance of task "%1" due to user "%2"  logon.

Fields #

NameDescription
TaskName UnicodeString
UserName UnicodeString
InstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 119,
    "version": 0,
    "level": 4,
    "task": 119,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T08:33:57.7322438+00:00",
    "event_record_id": 8120,
    "correlation": {
      "ActivityID": "{70265863-4CD2-41E3-8949-1991D2F4FE4E}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 5192
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\CertificateServicesClient\\UserTask",
    "UserName": "cell-a\\domainadmin",
    "InstanceId": "{70265863-4cd2-41e3-8949-1991d2f4fe4e}"
  },
  "message": "Task Scheduler launched \"{70265863-4cd2-41e3-8949-1991d2f4fe4e}\"  instance of task \"\\Microsoft\\Windows\\CertificateServicesClient\\UserTask\" due to user \"cell-a\\domainadmin\"  logon."
}

Event ID 120: Task Scheduler launched "InstanceId" instance of task "TaskName" due to user "UserName" connecting to the console trigger.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredonlocalconsoleconnect

Message #

Task Scheduler launched "%3"  instance of task "%1"  due to user "%2"  connecting to the console trigger.

Fields #

NameDescription
TaskName UnicodeString
UserName UnicodeString
InstanceId GUID

Event ID 121: Task Scheduler launched "InstanceId" instance of task "TaskName" due to user "UserName" disconnecting from the console trigger.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredonlocalconsoledisconnect

Message #

Task Scheduler launched "%3"  instance of task "%1"  due to user "%2"  disconnecting from the console trigger.

Fields #

NameDescription
TaskName UnicodeString
UserName UnicodeString
InstanceId GUID

Event ID 122: Task Scheduler launched "InstanceId" instance of task "TaskName" due to user "UserName" remotely connecting trigger.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredonremoteconsoleconnect

Message #

Task Scheduler launched "%3"  instance of task "%1"  due to user "%2"  remotely connecting trigger.

Fields #

NameDescription
TaskName UnicodeString
UserName UnicodeString
InstanceId GUID

Event ID 123: Task Scheduler launched "InstanceId" instance of task "TaskName" due to user "UserName" remotely disconnecting trigger.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredonremoteconsoledisconnect

Message #

Task Scheduler launched "%3"  instance of task "%1"  due to user "%2"  remotely disconnecting trigger.

Fields #

NameDescription
TaskName UnicodeString
UserName UnicodeString
InstanceId GUID

Event ID 124: Task Scheduler launched "InstanceId" instance of task "TaskName" due to user "UserName" locking the computer trigger.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredbylockingtheworkstation

Message #

Task Scheduler launched "%3"  instance of task "%1"  due to user "%2"  locking the computer trigger.

Fields #

NameDescription
TaskName UnicodeString
UserName UnicodeString
InstanceId GUID

Event ID 125: Task Scheduler launched "InstanceId" instance of task "TaskName" due to user "UserName" unlocking the computer trigger.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Tasktriggeredbyunlockingtheworkstation

Message #

Task Scheduler launched "%3"  instance of task "%1"  due to user "%2"  unlocking the computer trigger.

Fields #

NameDescription
TaskName UnicodeString
UserName UnicodeString
InstanceId GUID

Event ID 126: Task Scheduler failed to execute task "TaskName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Taskrestartedonfailure

Description

Task Scheduler failed to execute task "TaskName" . Attempting to restart. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to execute task "%1" . Attempting to restart. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 127: Task Scheduler failed to execute task "TaskName" due to a shutdown race condition.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Taskrestartedonfailure_127

Description

Task Scheduler failed to execute task "TaskName" due to a shutdown race condition. Attempting to restart.

Message #

Task Scheduler failed to execute task "%1"  due to a shutdown race condition. Attempting to restart.

Fields #

NameDescription
TaskName UnicodeString

Event ID 128: Task Scheduler did not launch task "TaskName" , because current time exceeds the configured task end time.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Launchconditionnotmet,beyondendtime

Description

Task Scheduler did not launch task "TaskName" , because current time exceeds the configured task end time. User Action: Extend the end time boundary for the task if required.

Message #

Task Scheduler did not launch task "%1" , because current time exceeds the configured task end time. User Action: Extend the end time boundary for the task if required.

Fields #

NameDescription
TaskName UnicodeString

Event ID 129: Task Scheduler launch task "Name" , instance "TaskName" with process ID Path.

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
CreatedTaskProcess

Message #

Task Scheduler launch task "%1" , instance "%2"  with process ID %3.

Fields #

NameDescriptionRules
TaskName UnicodeString20 detection rules
Path UnicodeString13 detection rules
ProcessID UInt32
Priority UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 129,
    "version": 0,
    "level": 4,
    "task": 129,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T14:08:20.0823200+00:00",
    "event_record_id": 8892,
    "correlation": {},
    "execution": {
      "process_id": 2100,
      "thread_id": 3336
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join",
    "Path": "%SystemRoot%\\System32\\dsregcmd.exe",
    "ProcessID": "5708",
    "Priority": "16384"
  },
  "message": "Task Scheduler launch task \"\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join\" , instance \"%SystemRoot%\\System32\\dsregcmd.exe\"  with process ID 5708."
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Pathcontains\desktop\1 rulesigma
Pathcontains\downloads\1 rulesigma
TaskNameeq\defender1 rulesigma
TaskNameeq\microsoft\defenderservice1 rulesigma
TaskNameeq\microsoft\windows\application experience\startupapptaskcheck1 rulesigma
TaskNameeq\microsoft\windows\application experience\startupapptaskckeck1 rulesigma
TaskNameeq\microsoft\windows\atpupd1 rulesigma
TaskNameeq\microsoft\windows\data integrity scan\data integrity update1 rulesigma
TaskNameeq\microsoft\windows\defenderupdservice1 rulesigma
TaskNameeq\microsoft\windows\iisupdateservice1 rulesigma
TaskNameeq\microsoft\windows\speech\speechmodelinstalltask1 rulesigma
TaskNameeq\microsoft\windows\wimsdfs1 rulesigma
TaskNameeq\microsoft\windows\windows defender\defender update service1 rulesigma
TaskNameeq\microsoft\windows\windows defender\service update1 rulesigma
TaskNameeq\microsoft\windows\windows error reporting\checkreporting1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Event ID 130: Task Scheduler failed to start task "TaskName" due to the service being busy.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Launchconditionnotmet,servicebusy

Message #

Task Scheduler failed to start task "%1" due to the service being busy.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 131: Task Scheduler failed to start task "TaskName" because the number of tasks in the task queue exceeding the quota currently configured to CurrentQuota.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Launchconditionnotmet,quotaexceeded

Description

Task Scheduler failed to start task "TaskName" because the number of tasks in the task queue exceeding the quota currently configured to CurrentQuota. User Action: Reduce the number of running tasks or increase the configured queue quota.

Message #

Task Scheduler failed to start task "%1" because the number of tasks in the task queue exceeding the quota currently configured to %2. User Action: Reduce the number of running tasks or increase the configured queue quota.

Fields #

NameDescription
TaskName UnicodeString
CurrentQuota UInt32

Event ID 132: Task Scheduler task launching queue quota is approaching its preset limit of tasks currently configured to CurrentQuota.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Launchconditionwarning,quotaapproaching

Description

Task Scheduler task launching queue quota is approaching its preset limit of tasks currently configured to CurrentQuota. User Action: Reduce the number of running tasks or increase the configured queue quota.

Message #

Task Scheduler task launching queue quota is approaching its preset limit of tasks currently configured to %1. User Action: Reduce the number of running tasks or increase the configured queue quota.

Fields #

NameDescription
CurrentQuota UInt32

Event ID 133: Task Scheduler failed to start task TaskName" in TaskEngine "TaskEngineName" for user "UserName".

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Launchconditionnotmet,quotaexceeded_133

Description

Task Scheduler failed to start task TaskName" in TaskEngine "TaskEngineName" for user "UserName". User Action: Reduce the number of tasks running in the specified user context.

Message #

Task Scheduler failed to start task %1" in TaskEngine "%2"  for user "%3". User Action: Reduce the number of tasks running in the specified user context.

Fields #

NameDescription
TaskName UnicodeString
TaskEngineName UnicodeString
UserName UnicodeString

Event ID 134: Task Engine "TaskEngineName" for user "UserName" is approaching its preset limit of tasks.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Launchconditionwarning,quotaapproaching_134

Description

Task Engine "TaskEngineName" for user "UserName" is approaching its preset limit of tasks. User Action: Reduce the number of tasks running in the specified user context.

Message #

Task Engine "%1"  for user "%2" is approaching its preset limit of tasks. User Action: Reduce the number of tasks running in the specified user context.

Fields #

NameDescription
TaskEngineName UnicodeString
UserName UnicodeString

Event ID 135: Task Scheduler could not start task "TaskName" because the machine was not idle.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Task
Launchconditionnotmet,machinenotidle

Message #

Task Scheduler could not start task "%1"  because the machine was not idle.

Fields #

NameDescription
TaskName UnicodeString

Event ID 140: User "TaskName" updated Task Scheduler task "Name".

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
Taskregistrationupdated

Message #

User "%2"  updated Task Scheduler task "%1"

Fields #

NameDescription
TaskName UnicodeString
UserName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 140,
    "version": 0,
    "level": 4,
    "task": 140,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T13:52:57.3163780+00:00",
    "event_record_id": 8859,
    "correlation": {},
    "execution": {
      "process_id": 2100,
      "thread_id": 2680
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask",
    "UserName": "cell-a\\TELEMETRY-DC-A$"
  },
  "message": "User \"cell-a\\TELEMETRY-DC-A$\"  updated Task Scheduler task \"\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTask\""
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
TaskNameeq\defender1 rulesigma
TaskNameeq\microsoft\defenderservice1 rulesigma
TaskNameeq\microsoft\windows\application experience\startupapptaskcheck1 rulesigma
TaskNameeq\microsoft\windows\application experience\startupapptaskckeck1 rulesigma
TaskNameeq\microsoft\windows\atpupd1 rulesigma
TaskNameeq\microsoft\windows\data integrity scan\data integrity update1 rulesigma
TaskNameeq\microsoft\windows\defenderupdservice1 rulesigma
TaskNameeq\microsoft\windows\iisupdateservice1 rulesigma
TaskNameeq\microsoft\windows\speech\speechmodelinstalltask1 rulesigma
TaskNameeq\microsoft\windows\wimsdfs1 rulesigma
TaskNameeq\microsoft\windows\windows defender\defender update service1 rulesigma
TaskNameeq\microsoft\windows\windows defender\service update1 rulesigma
TaskNameeq\microsoft\windows\windows error reporting\checkreporting1 rulesigma
TaskNameeq\microsoft\windows\windows error reporting\submitreporting1 rulesigma
TaskNameeq\microsoft\windows\windows filtering platform\bfeonservicestart1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Event ID 141: User "TaskName" deleted Task Scheduler task "Name".

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Microsoft-WEF, others)
Task
Taskregistrationdeleted

Message #

User "%2"  deleted Task Scheduler task "%1"

Fields #

NameDescriptionRules
TaskName UnicodeString7 detection rules
UserName UnicodeString2 detection rules

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 141,
    "version": 0,
    "level": 4,
    "task": 141,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:51:19.2705622+00:00",
    "event_record_id": 7711,
    "correlation": {},
    "execution": {
      "process_id": 2100,
      "thread_id": 5492
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Windows Defender\\Windows Defender Scheduled Scan",
    "UserName": "NT AUTHORITY\\System"
  },
  "message": "User \"NT AUTHORITY\\System\"  deleted Task Scheduler task \"\\Microsoft\\Windows\\Windows Defender\\Windows Defender Scheduled Scan\""
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
TaskNamecontains\windows\bitlocker1 rulesigma
TaskNamecontains\windows\exploitguard1 rulesigma
TaskNamecontains\windows\systemrestore\sr1 rulesigma
TaskNamecontains\windows\windows defender\1 rulesigma
TaskNamecontains\windows\windowsbackup\1 rulesigma
TaskNamecontains\windows\windowsupdate\1 rulesigma
TaskNameeq\defender1 rulesigma
TaskNameeq\microsoft\defenderservice1 rulesigma
TaskNameeq\microsoft\windows\application experience\startupapptaskcheck1 rulesigma
TaskNameeq\microsoft\windows\application experience\startupapptaskckeck1 rulesigma
TaskNameeq\microsoft\windows\atpupd1 rulesigma
TaskNameeq\microsoft\windows\data integrity scan\data integrity update1 rulesigma
TaskNameeq\microsoft\windows\defenderupdservice1 rulesigma
TaskNameeq\microsoft\windows\iisupdateservice1 rulesigma
TaskNameeq\microsoft\windows\speech\speechmodelinstalltask1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 142: User "TaskName" disabled Task Scheduler task "Name".

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Microsoft-WEF, others)
Task
Taskdisabled

Message #

User "%2"  disabled Task Scheduler task "%1"

Fields #

NameDescription
TaskName UnicodeString
UserName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "DE7B24EA-73C8-4A09-985D-5BDADCFA9017",
    "event_source_name": "",
    "event_id": 142,
    "version": 0,
    "level": 4,
    "task": 142,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-09T00:56:06.060816+00:00",
    "event_record_id": 31710,
    "correlation": {
      "ActivityID": "973CC99D-202A-4A9A-A6DF-75F5CFD7D7B7"
    },
    "execution": {
      "process_id": 1972,
      "thread_id": 3956
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "TaskDisabled",
    "TaskName": "\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join",
    "UserName": "System"
  },
  "message": ""
}

Example keys not documented in the fields table: Name

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
TaskNamecontains\windows\bitlocker1 rulesigma
TaskNamecontains\windows\exploitguard1 rulesigma
TaskNamecontains\windows\systemrestore\sr1 rulesigma
TaskNamecontains\windows\windows defender\1 rulesigma
TaskNamecontains\windows\windowsbackup\1 rulesigma
TaskNamecontains\windows\windowsupdate\1 rulesigma

Event ID 145: Task Scheduler woke up the computer to run a task.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Tasktriggeredbycomingoutofsuspendmode

Event ID 146: Task Scheduler failed to load task "TaskName" at service startup.

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Yamato Security)
Task
Taskloadingatservicestartupfailed

Description

Task Scheduler failed to load task "TaskName" at service startup. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to load task "%1" at service startup. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "event_id": 146,
    "level": 2,
    "task": 146,
    "opcode": 0,
    "time_created": "2026-05-27T19:31:58.4547923+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-TaskScheduler"
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\UpdateOrchestrator\\StartOobeAppsScanAfterUpdate",
    "ResultCode": "2147942402"
  }
}

Event ID 147: Task Scheduler recovered sucessfully the image of task "TaskName" after a corruption occured during OS upgrade.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
TaskimagerecoveredafterOSmigration

Message #

Task Scheduler recovered sucessfully the image of task "%1" after a corruption occured during OS upgrade.

Fields #

NameDescription
TaskName UnicodeString

Event ID 148: Task Scheduler failed to recover the image of task "TaskName" after a corruption occured during OS upgrade.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
TaskimagerecoveringfailedafterOSmigration

Description

Task Scheduler failed to recover the image of task "TaskName" after a corruption occured during OS upgrade. Additional Data: Error Value: 0xResultCode.

Message #

Task Scheduler failed to recover the image of task "%1" after a corruption occured during OS upgrade. Additional Data: Error Value: 0x%2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode HexInt32

Event ID 149: Task "TaskName" is using a combination of properties that is incompatible with the scheduling engine.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskisusingacombinationofpropertiesthatisincompatiblewiththeschedulingengine

Message #

Task "%1" is using a combination of properties that is incompatible with the scheduling engine.

Fields #

NameDescription
TaskName UnicodeString

Event ID 150: Task Scheduler failed to subscribe for the event trigger for task "TaskName".

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskregistrationoneventfailed

Description

Task Scheduler failed to subscribe for the event trigger for task "TaskName". Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to subscribe for the event trigger for task "%1". Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 151: Task instantiation failed "TaskName".

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Yamato Security)
Task
TaskSchedulerfailedtoinstantiatetaskatservicestartup.

Description

Task instantiation failed "TaskName". Check point: LogPoint. Error Value: ResultCode.

Message #

Task instantiation failed "%1". Check point: %2. Error Value: %3.

Fields #

NameDescription
TaskName UnicodeString
LogPoint UnicodeString
ResultCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "event_id": 151,
    "level": 2,
    "task": 151,
    "opcode": 0,
    "time_created": "2026-05-27T19:31:58.4547605+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-TaskScheduler"
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\UpdateOrchestrator\\StartOobeAppsScanAfterUpdate",
    "ResultCode": "2147942402",
    "LogPoint": "Ubpm-RegisterConsumer"
  }
}

Event ID 152: Task "TaskName" was re-directed to legacy scheduling engine.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskwasredirectedtolegacyengine

Message #

Task "%1" was re-directed to legacy scheduling engine.

Fields #

NameDescription
TaskName UnicodeString

Event ID 153: Task Scheduler did not launch task "Name" as it missed its schedule.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security)
Task
Missedtaskstartrejected

Description

Task Scheduler did not launch task "Name" as it missed its schedule. Consider using the configuration option to start the task when available, if schedule is missed.

Message #

Task Scheduler did not launch task "%1" as it missed its schedule. Consider using the configuration option to start the task when available, if schedule is missed.

Fields #

NameDescription
TaskName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "DE7B24EA-73C8-4A09-985D-5BDADCFA9017",
    "event_source_name": "",
    "event_id": 153,
    "version": 0,
    "level": 3,
    "task": 153,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-08T23:13:40.561331+00:00",
    "event_record_id": 30099,
    "correlation": {},
    "execution": {
      "process_id": 2316,
      "thread_id": 9952
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "MissedTaskRejected",
    "TaskName": "\\Microsoft\\Windows\\Security\\Pwdless\\IntelligentPwdlessTask"
  },
  "message": ""
}

Example keys not documented in the fields table: Name

Event ID 155: Task Scheduler is currently waiting on completion of task "TaskPath".

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
TaskCompletionPending

Message #

Task Scheduler is currently waiting on completion of task "%1".

Fields #

NameDescription
TaskPath UnicodeString

Event ID 200: Task Scheduler launched action "TaskName" in instance "ActionName" of task "Name".

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (NSA, others)
Task
Actionstarted
Opcode
Start

Message #

Task Scheduler launched action "%2" in instance "%3" of task "%1".

Fields #

NameDescription
TaskName UnicodeString
ActionName UnicodeString
TaskInstanceId GUID
EnginePID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 200,
    "version": 1,
    "level": 4,
    "task": 200,
    "opcode": 1,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T14:08:20.0826428+00:00",
    "event_record_id": 8894,
    "correlation": {
      "ActivityID": "{315D0AE5-E095-4BA8-98CF-B8B7C2E4AD53}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 3336
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join",
    "ActionName": "%SystemRoot%\\System32\\dsregcmd.exe",
    "TaskInstanceId": "{315d0ae5-e095-4ba8-98cf-b8b7c2e4ad53}",
    "EnginePID": "5708"
  },
  "message": "Task Scheduler launched action \"%SystemRoot%\\System32\\dsregcmd.exe\" in instance \"{315d0ae5-e095-4ba8-98cf-b8b7c2e4ad53}\" of task \"\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join\"."
}

Detection Patterns #

Event ID 201: Task Scheduler successfully completed task "Name" , instance "TaskInstanceId" , action "TaskName" .

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Task
Actioncompleted
Opcode
Stop

Message #

Task Scheduler successfully completed task "%1" , instance "%3" , action "%2" .

Fields #

NameDescription
TaskName UnicodeString
TaskInstanceId GUID
ActionName UnicodeString
ResultCode UInt32
EnginePID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 201,
    "version": 2,
    "level": 4,
    "task": 201,
    "opcode": 2,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T14:08:20.3056973+00:00",
    "event_record_id": 8895,
    "correlation": {
      "ActivityID": "{315D0AE5-E095-4BA8-98CF-B8B7C2E4AD53}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 3336
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join",
    "TaskInstanceId": "{315d0ae5-e095-4ba8-98cf-b8b7c2e4ad53}",
    "ActionName": "%SystemRoot%\\System32\\dsregcmd.exe",
    "ResultCode": "2147942401",
    "EnginePID": "5708"
  },
  "message": "Task Scheduler successfully completed task \"\\Microsoft\\Windows\\Workplace Join\\Automatic-Device-Join\" , instance \"{315d0ae5-e095-4ba8-98cf-b8b7c2e4ad53}\" , action \"%SystemRoot%\\System32\\dsregcmd.exe\" with return code 2147942401."
}

Detection Patterns #

Event ID 202: Task Scheduler failed to complete task "Name" , instance "TaskName" , action "TaskInstanceId" .

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Yamato Security)
Task
Actionfailed
Opcode
RunFailure

Description

Task Scheduler failed to complete task "Name" , instance "TaskName" , action "TaskInstanceId" . Additional Data: Error Value: ActionName.

Message #

Task Scheduler failed to complete task "%1" , instance "%2" , action "%3" . Additional Data: Error Value: %4.

Fields #

NameDescription
TaskName UnicodeString
TaskInstanceId GUID
ActionName UnicodeString
ResultCode UInt32
EnginePID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 202,
    "version": 1,
    "level": 2,
    "task": 202,
    "opcode": 102,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:40:05.7566532+00:00",
    "event_record_id": 7659,
    "correlation": {
      "ActivityID": "{762E45EA-0D91-4E66-8DF4-8CACEE9415D0}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 1432
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\International\\Synchronize Language Settings",
    "TaskInstanceId": "{762e45ea-0d91-4e66-8df4-8cacee9415d0}",
    "ActionName": "Sync Language Data From Cloud Task",
    "ResultCode": "2147746053",
    "EnginePID": "2384"
  },
  "message": "Task Scheduler failed to complete task \"\\Microsoft\\Windows\\International\\Synchronize Language Settings\" , instance \"{762e45ea-0d91-4e66-8df4-8cacee9415d0}\" , action \"Sync Language Data From Cloud Task\" . Additional Data: Error Value: 2147746053."
}

Event ID 203: Task Scheduler failed to launch action "TaskInstanceId" in instance "TaskName" of task "Name".

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Yamato Security)
Task
Actionfailedtostart
Opcode
LaunchFailure

Description

Task Scheduler failed to launch action "TaskInstanceId" in instance "TaskName" of task "Name". Additional Data: Error Value: ActionName.

Message #

Task Scheduler failed to launch action "%3" in instance "%2" of task "%1". Additional Data: Error Value: %4.

Fields #

NameDescription
TaskName UnicodeString
TaskInstanceId GUID
ActionName UnicodeString
ResultCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "DE7B24EA-73C8-4A09-985D-5BDADCFA9017",
    "event_source_name": "",
    "event_id": 203,
    "version": 0,
    "level": 2,
    "task": 203,
    "opcode": 101,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-06T01:06:15.745198+00:00",
    "event_record_id": 928,
    "correlation": {
      "ActivityID": "0EBFF706-5D1E-403C-8FEB-AA1502A28BF9"
    },
    "execution": {
      "process_id": 1392,
      "thread_id": 16668
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "ActionLaunchFailure",
    "TaskName": "\\Microsoft\\Windows\\UpdateOrchestrator\\USO_UxBroker",
    "TaskInstanceId": "0EBFF706-5D1E-403C-8FEB-AA1502A28BF9",
    "ActionName": "%systemroot%\\system32\\MusNotification.exe",
    "ResultCode": 2147942402
  },
  "message": ""
}

Example keys not documented in the fields table: Name

References #

Event ID 204: Task Scheduler failed to retrieve the event triggering values for task "TaskName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskfailedtostartonevent

Description

Task Scheduler failed to retrieve the event triggering values for task "TaskName" . The event will be ignored. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to retrieve the event triggering values for task "%1" . The event will be ignored. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 205: Task Scheduler failed to match the pattern of events for task "TaskName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskfailedtostartoneventpatternmatch

Description

Task Scheduler failed to match the pattern of events for task "TaskName" . The events will be ignored. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to match the pattern of events for task "%1" . The events will be ignored. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 300: Task Scheduler started Task Engine "TaskEngineName" with process ID ProcessID.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskenginelaunched
Opcode
Start

Message #

Task Scheduler started Task Engine "%1"  with process ID %2.

Fields #

NameDescription
TaskEngineName UnicodeString
ProcessID UInt32

Event ID 301: Task Scheduler is shutting down Task Engine "TaskEngineName".

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskengineproperlyshutdown
Opcode
Stop

Message #

Task Scheduler is shutting down Task Engine "%1"

Fields #

NameDescription
TaskEngineName UnicodeString

Event ID 303: Task Scheduler is shutting down Task Engine "TaskEngineName" due to an error in "ErrorDescription" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskengineshutdownduetoerror
Opcode
Failure

Description

Task Scheduler is shutting down Task Engine "TaskEngineName" due to an error in "ErrorDescription" . Additional Data: Error Value: ResultCode.

Message #

Task Scheduler is shutting down Task Engine "%1"  due to an error in "%2" .  Additional Data: Error Value: %3.

Fields #

NameDescription
TaskEngineName UnicodeString
ErrorDescription UnicodeString
ResultCode UInt32

Event ID 304: Task Scheduler sent "TaskName" task to Task Engine "TaskEngineName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Tasksenttoengine

Description

Task Scheduler sent "TaskName" task to Task Engine "TaskEngineName" . The task instance Id is "TaskInstanceId" .

Message #

Task Scheduler sent "%1"  task to Task Engine "%2" . The task instance Id is "%3" .

Fields #

NameDescription
TaskName UnicodeString
TaskEngineName UnicodeString
TaskInstanceId GUID

Event ID 305: Task Scheduler did not send "TaskName" task to Task Engine "TaskEngineName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskfailedtobesenttoengine
Opcode
Failure

Description

Task Scheduler did not send "TaskName" task to Task Engine "TaskEngineName" . Additional Data: Error Value: ResultCode.

Message #

Task Scheduler did not send "%1"  task to Task Engine "%2" . Additional Data: Error Value: %3.

Fields #

NameDescription
TaskName UnicodeString
TaskEngineName UnicodeString
ResultCode UInt32

Event ID 306: For Task Scheduler Task Engine "TaskEngineName" , the thread pool failed to process the message.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Enginefailedtoreceivethetask
Opcode
Failure

Description

For Task Scheduler Task Engine "TaskEngineName" , the thread pool failed to process the message. Additional Data: Error Value: ResultCode.

Message #

For Task Scheduler Task Engine "%1" , the thread pool failed to process the message. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskEngineName UnicodeString
ResultCode UInt32

Event ID 307: Task Scheduler service failed to connect to the Task Engine "TaskEngineName" process.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
ServiceEngineconnectionfailure
Opcode
Failure

Description

Task Scheduler service failed to connect to the Task Engine "TaskEngineName" process. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service failed to connect to the Task Engine "%1"  process. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskEngineName UnicodeString
ResultCode UInt32

Event ID 308: Task Scheduler connected to the Task Engine "TaskEngineName" process.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
ServiceEngineconnected

Message #

Task Scheduler connected to the Task Engine "%1"  process.

Fields #

NameDescription
TaskEngineName UnicodeString

Event ID 309: Task Scheduler TaskCount tasks orphaned during Task Engine "TaskEngineName" shutdown.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Engineorphaned

Description

Task Scheduler TaskCount tasks orphaned during Task Engine "TaskEngineName" shutdown. User Action: Find the process run by this task in the Task Manager and kill it manually.

Message #

Task Scheduler %1 tasks orphaned during Task Engine "%2"  shutdown. User Action: Find the process run by this task in the Task Manager and kill it manually.

Fields #

NameDescription
TaskCount UInt32
TaskEngineName UnicodeString

Event ID 310: Task Scheduler started Task Engine "TaskEngineName" process.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
TaskEnginestarted

Description

Task Scheduler started Task Engine "TaskEngineName" process. Command="Command" , ProcessID=ProcessID, ThreadID=ThreadID.

Message #

Task Scheduler started Task Engine "%1"  process. Command="%2" , ProcessID=%3, ThreadID=%4

Fields #

NameDescription
TaskEngineName UnicodeString
Command UnicodeString
ProcessID UInt32
ThreadID UInt32

Event ID 311: Task Scheduler failed to start Task Engine "TaskEngineName" process due to an error occurring in "ErrorDescription" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
TaskEnginefailedtostart
Opcode
LaunchFailure

Description

Task Scheduler failed to start Task Engine "TaskEngineName" process due to an error occurring in "ErrorDescription" . Command="Command" . Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to start Task Engine "%1"  process due to an error occurring in "%3" . Command="%2" . Additional Data: Error Value: %4.

Fields #

NameDescription
TaskEngineName UnicodeString
Command UnicodeString
ErrorDescription UnicodeString
ResultCode UInt32

Event ID 312: Task Scheduler created the Win32 job object for Task Engine "TaskEngineName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
TaskEnginejobobjectcreated

Message #

Task Scheduler created the Win32 job object for Task Engine "%1" .

Fields #

NameDescription
TaskEngineName UnicodeString

Event ID 313: Task Scheduler channel with Task Engine "TaskEngineName" is ready to send and receive messages.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
ServiceEnginechannelready

Message #

Task Scheduler channel with Task Engine "%1"  is ready to send and receive messages.

Fields #

NameDescription
TaskEngineName UnicodeString

Event ID 314: Task Scheduler has no tasks running for Task Engine "TaskEngineName" , and the idle timer has started.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
TaskEngineidle

Message #

Task Scheduler has no tasks running for Task Engine "%1" , and the idle timer has started.

Fields #

NameDescription
TaskEngineName UnicodeString

Event ID 315: Task Engine "TaskEngineName" process failed to connect to the Task Scheduler service.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
ServiceEngineconnectionfailure_315
Opcode
Failure

Description

Task Engine "TaskEngineName" process failed to connect to the Task Scheduler service. Additional Data: Error Value: ResultCode.

Message #

Task Engine "%1"  process failed to connect to the Task Scheduler service. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskEngineName UnicodeString
ResultCode UInt32

Event ID 316: Task Engine "TaskEngineName" failed to send a message to the Task Scheduler service.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Enginefailedtosendmessagetoservice
Opcode
Failure

Description

Task Engine "TaskEngineName" failed to send a message to the Task Scheduler service. Additional Data: Error Value: ResultCode.

Message #

Task Engine "%1"  failed to send a message to the Task Scheduler service. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskEngineName UnicodeString
ResultCode UInt32

Event ID 317: Task Scheduler started Task Engine "TaskEngineName" process.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
TaskEnginestarted_317
Opcode
Start

Message #

Task Scheduler started Task Engine "%1"  process.

Fields #

NameDescription
TaskEngineName UnicodeString

Event ID 318: Task Scheduler shutdown Task Engine "TaskEngineName" process.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskengineproperlyshutdown_318
Opcode
Stop

Message #

Task Scheduler shutdown Task Engine "%1"  process.

Fields #

NameDescription
TaskEngineName UnicodeString

Event ID 319: Task Engine "TaskEngineName" received a message from Task Scheduler service requesting to launch task "TaskName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
TaskEnginereceivedmessagetostarttask
Opcode
Start

Message #

Task Engine "%1"  received a message from Task Scheduler service requesting to launch task "%2" .

Fields #

NameDescription
TaskEngineName UnicodeString
TaskName UnicodeString

Event ID 320: Task Engine "TaskEngineName" received a message from Task Scheduler service requesting to stop task instance "TaskInstanceId" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
TaskEnginereceivedmessagetostoptask
Opcode
Stop

Message #

Task Engine "%1"  received a message from Task Scheduler service requesting to stop task instance "%2" .

Fields #

NameDescription
TaskEngineName UnicodeString
TaskInstanceId GUID

Event ID 322: Task Scheduler did not launch task "Name" because instance "TaskName" of the same task is already running.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security)
Task
Launchrequestignored,instancealreadyrunning

Message #

Task Scheduler did not launch task "%1"  because instance "%2"  of the same task is already running.

Fields #

NameDescription
TaskName UnicodeString
TaskInstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 322,
    "version": 0,
    "level": 3,
    "task": 322,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T14:11:36.9378051+00:00",
    "event_record_id": 8903,
    "correlation": {
      "ActivityID": "{1BECE11B-517E-4ED5-80AD-D07D523F886F}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 6220
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Input\\LocalUserSyncDataAvailable",
    "TaskInstanceId": "{1bece11b-517e-4ed5-80ad-d07d523f886f}"
  },
  "message": "Task Scheduler did not launch task \"\\Microsoft\\Windows\\Input\\LocalUserSyncDataAvailable\"  because instance \"{1bece11b-517e-4ed5-80ad-d07d523f886f}\"  of the same task is already running."
}

Event ID 323: Task Scheduler stopped instance "StoppedTaskInstanceId" of task "TaskName" in order to launch new instance "NewTaskInstanceId" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Launchrequestacknowledged,currentinstancestopped

Message #

Task Scheduler stopped instance "%2"  of task "%1"  in order to launch new instance "%3" .

Fields #

NameDescription
TaskName UnicodeString
StoppedTaskInstanceId GUID
NewTaskInstanceId GUID

Event ID 324: Task Scheduler queued instance "TaskName" of task "Name" and will launch it as soon as instance "QueuedTaskInstanceId" completes.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security)
Task
Launchrequestqueued,instancealreadyrunning

Message #

Task Scheduler queued instance "%2"  of task "%1"  and will launch it as soon as instance "%3"  completes.

Fields #

NameDescription
TaskName UnicodeString
QueuedTaskInstanceId GUID
RunningTaskInstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 324,
    "version": 0,
    "level": 3,
    "task": 324,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T08:36:45.2235251+00:00",
    "event_record_id": 11252,
    "correlation": {
      "ActivityID": "{4D83D61D-8031-40E8-B178-CEFD3C1682A7}"
    },
    "execution": {
      "process_id": 1608,
      "thread_id": 728
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-b.cell-b.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting",
    "QueuedTaskInstanceId": "{4d83d61d-8031-40e8-b178-cefd3c1682a7}",
    "RunningTaskInstanceId": "{ea30723f-4a36-4ca9-aa48-a8b23cfc4dcb}"
  },
  "message": "Task Scheduler queued instance \"{4d83d61d-8031-40e8-b178-cefd3c1682a7}\"  of task \"\\Microsoft\\Windows\\Windows Error Reporting\\QueueReporting\"  and will launch it as soon as instance \"{ea30723f-4a36-4ca9-aa48-a8b23cfc4dcb}\"  completes."
}

Event ID 325: Task Scheduler queued instance "TaskName" of task "Name".

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security)
Task
Launchrequestqueued

Message #

Task Scheduler queued instance "%2"  of task "%1".

Fields #

NameDescription
TaskName UnicodeString
QueuedTaskInstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 325,
    "version": 0,
    "level": 3,
    "task": 325,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T06:04:36.7624198+00:00",
    "event_record_id": 7755,
    "correlation": {
      "ActivityID": "{0F4AC548-8C6F-4BFB-A090-4BB457F739FE}"
    },
    "execution": {
      "process_id": 2100,
      "thread_id": 5196
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem",
    "QueuedTaskInstanceId": "{0f4ac548-8c6f-4bfb-a090-4bb457f739fe}"
  },
  "message": "Task Scheduler queued instance \"{0f4ac548-8c6f-4bfb-a090-4bb457f739fe}\"  of task \"\\Microsoft\\Windows\\Power Efficiency Diagnostics\\AnalyzeSystem\"."
}

Event ID 326: Task Scheduler did not launch task "TaskName" because computer is running on batteries.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Launchconditionnotmet,computeronbatteries

Description

Task Scheduler did not launch task "TaskName" because computer is running on batteries. User Action: If launching the task on batteries is required, change the respective flag in the task configuration.

Message #

Task Scheduler did not launch task "%1"  because computer is running on batteries. User Action: If launching the task on batteries is required, change the respective flag in the task configuration.

Fields #

NameDescription
TaskName UnicodeString

Event ID 327: Task Scheduler stopped instance "TaskInstanceId" of task "TaskName" because the computer is switching to battery power.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskstoppingduetoswitchingtobatteries

Message #

Task Scheduler stopped instance "%2"  of task "%1"  because the computer is switching to battery power.

Fields #

NameDescription
TaskName UnicodeString
TaskInstanceId GUID

Event ID 328: Task Scheduler stopped instance "TaskName" of task "Name" because computer is no longer idle.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
Taskstoppingduetocomputernotidle

Message #

Task Scheduler stopped instance "%2"  of task "%1"  because computer is no longer idle.

Fields #

NameDescription
TaskName UnicodeString
TaskInstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "DE7B24EA-73C8-4A09-985D-5BDADCFA9017",
    "event_source_name": "",
    "event_id": 328,
    "version": 0,
    "level": 4,
    "task": 328,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-09T00:55:21.200143+00:00",
    "event_record_id": 31697,
    "correlation": {
      "ActivityID": "1D9CAE68-87E2-4B98-9413-7A44D523E01F"
    },
    "execution": {
      "process_id": 1972,
      "thread_id": 1088
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "StoppingOnIdleEnd",
    "TaskName": "\\Microsoft\\Windows\\MemoryDiagnostic\\RunFullMemoryDiagnostic",
    "TaskInstanceId": "1D9CAE68-87E2-4B98-9413-7A44D523E01F"
  },
  "message": ""
}

Example keys not documented in the fields table: Name

Event ID 329: Task Scheduler terminated "TaskName" instance of the "Name" task due to exceeding the time allocated for execution, as configured in the task definition.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
Taskstoppingduetotimeoutreached

Description

Task Scheduler terminated "TaskInstanceId" instance of the "TaskName" task due to exceeding the time allocated for execution, as configured in the task definition. User Action: Increase the configured task timeout or investigate external reasons for the delay.

Message #

Task Scheduler terminated "%2"  instance of the "%1"  task due to exceeding the time allocated for execution, as configured in the task definition. User Action: Increase the configured task timeout or investigate external reasons for the delay.

Fields #

NameDescription
TaskName UnicodeString
TaskInstanceId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 329,
    "version": 0,
    "level": 4,
    "task": 329,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-28T11:14:38.1504371+00:00",
    "event_record_id": 497,
    "correlation": {
      "ActivityID": "{917B25A3-2CF9-4FD1-9CB2-7DB19852FF8A}"
    },
    "execution": {
      "process_id": 1756,
      "thread_id": 2876
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Shell\\CreateObjectTask",
    "TaskInstanceId": "{917b25a3-2cf9-4fd1-9cb2-7db19852ff8a}"
  },
  "message": "Task Scheduler terminated \"{917b25a3-2cf9-4fd1-9cb2-7db19852ff8a}\"  instance of the \"\\Microsoft\\Windows\\Shell\\CreateObjectTask\"  task due to exceeding the time allocated for execution, as configured in the task definition. User Action: Increase the configured task timeout or investigate external reasons for the delay."
}

Event ID 330: Task Scheduler stopped instance "TaskName" of task "Name" as request by user "TaskInstanceId" .

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
Taskstoppingduetouserrequest

Message #

Task Scheduler stopped instance "%2"  of task "%1"  as request by user "%3" .

Fields #

NameDescription
TaskName UnicodeString
TaskInstanceId GUID
UserContext UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 330,
    "version": 0,
    "level": 4,
    "task": 330,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T08:44:12.4364330+00:00",
    "event_record_id": 6324,
    "correlation": {
      "ActivityID": "{9B5A34F6-ABB2-4FCC-83E4-4589AFF754C1}"
    },
    "execution": {
      "process_id": 2072,
      "thread_id": 5376
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TaskName": "\\Microsoft\\Windows\\Windows Defender\\Windows Defender Scheduled Scan",
    "TaskInstanceId": "{9b5a34f6-abb2-4fcc-83e4-4589aff754c1}",
    "UserContext": "NT AUTHORITY\\SYSTEM"
  },
  "message": "Task Scheduler stopped instance \"{9b5a34f6-abb2-4fcc-83e4-4589aff754c1}\"  of task \"\\Microsoft\\Windows\\Windows Defender\\Windows Defender Scheduled Scan\"  as request by user \"NT AUTHORITY\\SYSTEM\" ."
}

Event ID 331: Task Scheduler will continue to execute Instance "TaskInstanceId" of task "TaskName" even after the designated timeout, due to a failure to create the timeout mechan...

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Taskfailedtostopontimeout

Description

Task Scheduler will continue to execute Instance "TaskInstanceId" of task "TaskName" even after the designated timeout, due to a failure to create the timeout mechanism. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler will continue to execute Instance "%2"  of task "%1"  even after the designated timeout, due to a failure to create the timeout mechanism. Additional Data: Error Value: %3.

Fields #

NameDescription
TaskName UnicodeString
TaskInstanceId GUID
ResultCode UInt32

Event ID 332: Task Scheduler did not launch task "Name" because user "TaskName" was not logged on when the launching conditions were met.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security)
Task
Launchconditionnotmet,usernotlogged_on

Description

Task Scheduler did not launch task "TaskName" because user "UserName" was not logged on when the launching conditions were met. User Action: Ensure user is logged on or change the task definition to allow launching when user is logged off.

Message #

Task Scheduler did not launch task "%1"  because user "%2" was not logged on when the launching conditions were met. User Action: Ensure user is logged on or change the task definition to allow launching when user is logged off.

Fields #

NameDescription
TaskName UnicodeString
UserName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "DE7B24EA-73C8-4A09-985D-5BDADCFA9017",
    "event_source_name": "",
    "event_id": 332,
    "version": 0,
    "level": 3,
    "task": 332,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-06T01:13:11.824978+00:00",
    "event_record_id": 956,
    "correlation": {},
    "execution": {
      "process_id": 1392,
      "thread_id": 14508
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "NoStartUserNotLogged",
    "TaskName": "\\Microsoft\\VisualStudio\\Updates\\BackgroundDownload",
    "UserName": "WINDEV2310EVAL\\Administrator"
  },
  "message": ""
}

Example keys not documented in the fields table: Name

References #

Event ID 333: Task Scheduler did not launch task "TaskName" because target session is RemoteApp session.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Launchconditionnotmet,sessionisRemoteAppSession

Description

Task Scheduler did not launch task "TaskName" because target session is RemoteApp session. User Action: If launching the task on RemoteApp sessions is required, change the respective flag in the task configuration.

Message #

Task Scheduler did not launch task "%1"  because target session is RemoteApp session. User Action: If launching the task on RemoteApp sessions is required, change the respective flag in the task configuration.

Fields #

NameDescription
TaskName UnicodeString

Event ID 334: Task Scheduler did not launch task "TaskName" because target session is a WORKER session.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Launchconditionnotmet,sessionisaWorkerSession

Message #

Task Scheduler did not launch task "%1"  because target session is a WORKER session.

Fields #

NameDescription
TaskName UnicodeString

Event ID 400: Task Scheduler service has started.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
Servicestarted
Opcode
Start

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 400,
    "version": 0,
    "level": 4,
    "task": 400,
    "opcode": 1,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T16:32:54.2209119+00:00",
    "event_record_id": 6743,
    "correlation": {},
    "execution": {
      "process_id": 2100,
      "thread_id": 2324
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "Task Scheduler service has started."
}

Event ID 401: Task Scheduler service failed to start due to an error in "ErrorDescription" .

#
Channel
System
Task
Servicefailedtostart
Opcode
LaunchFailure

Description

Task Scheduler service failed to start due to an error in "ErrorDescription" . Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service failed to start due to an error in "%1" . Additional Data: Error Value: %2.

Fields #

NameDescription
ErrorDescription UnicodeString
ResultCode UInt32

Event ID 402: Task Scheduler service is shutting down.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
Serviceisshuttingdown
Opcode
Stop

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 402,
    "version": 0,
    "level": 4,
    "task": 402,
    "opcode": 2,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:22:34.5284921+00:00",
    "event_record_id": 14560,
    "correlation": {},
    "execution": {
      "process_id": 1680,
      "thread_id": 2100
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "Task Scheduler service is shutting down."
}

Event ID 403: Task Scheduler service has encountered an error in "ErrorDescription" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Servicecriticalerror
Opcode
Failure

Description

Task Scheduler service has encountered an error in "ErrorDescription" . Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service has encountered an error in "%1" . Additional Data: Error Value: %2.

Fields #

NameDescription
ErrorDescription UnicodeString
ResultCode UInt32

Event ID 404: Task Scheduler service has encountered RPC initialization error in "ErrorDescription".

#
Channel
System
Task
ServiceRPCerror

Description

Task Scheduler service has encountered RPC initialization error in "ErrorDescription". Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service has encountered RPC initialization error in "%1". Additional Data: Error Value: %2.

Fields #

NameDescription
ErrorDescription UnicodeString
ResultCode UInt32

Event ID 405: Task Scheduler service has failed to initialize COM.

#
Channel
System
Task
ServiceCOMerror

Description

Task Scheduler service has failed to initialize COM. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service has failed to initialize COM. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 406: Task Scheduler service failed to initialize credentials store.

#
Channel
System
Task
Credstoreinitializationerror

Description

Task Scheduler service failed to initialize credentials store. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service failed to initialize credentials store. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 407: Task Scheduler service failed to initialize LSA.

#
Channel
System
Task
LSAinitializationerror

Description

Task Scheduler service failed to initialize LSA. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service failed to initialize LSA. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 408: Task Scheduler service failed to initialize idle state detection module.

#
Channel
System
Task
Idledetectionerror

Description

Task Scheduler service failed to initialize idle state detection module. Idle tasks may not be started as required. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service failed to initialize idle state detection module. Idle tasks may not be started as required. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 409: Task Scheduler service failed to initialize time change notification.

#
Channel
System
Task
Timechangenotificationerror

Description

Task Scheduler service failed to initialize time change notification. System time updates may not be picked by the service and task schedules may not be updated. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service failed to initialize time change notification. System time updates may not be picked by the service and task schedules may not be updated. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 410: Task Scheduler service failed to set a wakeup timer.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Wakeuptimererror

Description

Task Scheduler service failed to set a wakeup timer. As a result, some scheduled tasks may not run while the system is suspended. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service failed to set a wakeup timer. As a result, some scheduled tasks may not run while the system is suspended. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 411: Task Scheduler service received a time system change notification.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
Servicesignaledtimechange

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "DE7B24EA-73C8-4A09-985D-5BDADCFA9017",
    "event_source_name": "",
    "event_id": 411,
    "version": 0,
    "level": 4,
    "task": 411,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-08T23:13:40.513605+00:00",
    "event_record_id": 30045,
    "correlation": {},
    "execution": {
      "process_id": 2316,
      "thread_id": 2468
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "TimeChangeSignaled"
  },
  "message": ""
}

Event ID 412: Task Scheduler service failed to launch tasks triggered by computer startup.

#
Channel
System
Task
Servicecriticalerror

Description

Task Scheduler service failed to launch tasks triggered by computer startup. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service failed to launch tasks triggered by computer startup. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 413: Task Scheduler service failed to load tasks at service startup.

#
Channel
System
Task
Servicecriticalerror

Description

Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 414: Task Scheduler service found a misconfiguration in the TaskName definition.

#
Channel
System
Task
TaskMisconfiguration

Description

Task Scheduler service found a misconfiguration in the TaskName definition. Additional Data: Error Value: Parameter.

Message #

Task Scheduler service found a misconfiguration in the %1 definition. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
Parameter UnicodeString

Event ID 500: Process ID ProcessId has registered idle task ID IdleTaskId.

#
Channel
Diagnostic
Task
IdleTaskRegister

Message #

Process ID %2 has registered idle task ID %1.

Fields #

NameDescription
IdleTaskId UInt32
ProcessId UInt32

Event ID 501: Process ID ProcessId has completed idle task ID IdleTaskId.

#
Channel
Diagnostic
Task
IdleTaskUnregister

Message #

Process ID %2 has completed idle task ID %1.

Fields #

NameDescription
IdleTaskId UInt32
ProcessId UInt32

Event ID 502: Execution of idle task ID IdleTaskId has started.

#
Channel
Diagnostic
Task
IdleTaskExecute
Opcode
Start

Message #

Execution of idle task ID %1 has started.

Fields #

NameDescription
IdleTaskId UInt32
ProcessId UInt32

Event ID 503: Execution of idle task ID IdleTaskId has ended.

#
Channel
Diagnostic
Task
IdleTaskExecute
Opcode
Stop

Message #

Execution of idle task ID %1 has ended.

Fields #

NameDescription
IdleTaskId UInt32
ProcessId UInt32

Event ID 504: Idle task ID IdleTaskId has been notified that explicit processing has been requested.

#
Channel
Diagnostic
Task
IdleTaskNotify
Opcode
Start

Message #

Idle task ID %1 has been notified that explicit processing has been requested.

Fields #

NameDescription
IdleTaskId UInt32
ProcessId UInt32

Event ID 505: Idle task ID IdleTaskId has returned from its explicit processing notification.

#
Channel
Diagnostic
Task
IdleTaskNotify
Opcode
Stop

Message #

Idle task ID %1 has returned from its explicit processing notification.

Fields #

NameDescription
IdleTaskId UInt32
ProcessId UInt32

Event ID 506: Explicit execution of all idle tasks has been requested.

#
Channel
Diagnostic
Task
IdleTaskExplicitProcessing
Opcode
Start

Event ID 507: Explicit execution of all idle tasks has completed.

#
Channel
Diagnostic
Task
IdleTaskExplicitProcessing
Opcode
Stop

Event ID 508: Explicit execution of all idle tasks is in progress.

#
Channel
Diagnostic
Task
IdleTaskExplicitProcessingActive

Event ID 509: Idle Task Power Notification Received: NotificationType (State).

#
Channel
Diagnostic
Task
IdleTaskPowerNotificationReceived

Message #

Idle Task Power Notification Received: %1 (%2)

Fields #

NameDescription
NotificationType UnicodeString
State UInt32

Event ID 510: Idle Task PerfTrack Resource Consumption

#
Channel
Diagnostic
Task
IdleTaskPerfTrackResourceConsumption

Fields #

NameDescription
NoIdleReason UInt32
DATA1 UInt32
DATA2 UInt32

Event ID 511: Idle Task PerfTrack Idle Exit

#
Channel
Diagnostic
Task
IdleTaskPerfTrackIdleExit

Fields #

NameDescription
TimeSinceUserNotPresent UInt32
DATA UInt32

Event ID 512: Idle check point: State DetectionResult, Reason Reason.

#
Channel
Diagnostic
Task
IdleCheckPoint

Message #

Idle check point: State %1, Reason %2.

Fields #

NameDescription
DetectionResult UInt32
Reason UInt32

Event ID 700: Task Scheduler service started Task Compatibility module.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymodulestarted

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 700,
    "version": 0,
    "level": 4,
    "task": 700,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T16:32:54.1752737+00:00",
    "event_record_id": 6742,
    "correlation": {},
    "execution": {
      "process_id": 2100,
      "thread_id": 2324
    },
    "channel": "Microsoft-Windows-TaskScheduler/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "Task Scheduler service started Task Compatibility module."
}

Event ID 701: Task Scheduler service failed to start Task Compatibility module.

#
Channel
System
Task
Compatibilitymodulefailedtostart

Description

Task Scheduler service failed to start Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler service failed to start Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 702: Task Scheduler failed to initialize the RPC server for starting the Task Compatibility module.

#
Channel
System
Task
CompatibilitymoduleRPCfailed

Description

Task Scheduler failed to initialize the RPC server for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to initialize the RPC server for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 703: Task Scheduler failed to initialize Net Schedule API for starting the Task Compatibility module.

#
Channel
System
Task
CompatibilitymoduleNetScheduleAPIfailed

Description

Task Scheduler failed to initialize Net Schedule API for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to initialize Net Schedule API for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 704: Task Scheduler failed to initialize LSA for starting the Task Compatibility module.

#
Channel
System
Task
CompatibilitymoduleLSAfailed

Description

Task Scheduler failed to initialize LSA for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to initialize LSA for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 705: Task Scheduler failed to start directory monitoring for the Task Compatibility module.

#
Channel
System
Task
Compatibilitymoduledirectorymonitoringfailed

Description

Task Scheduler failed to start directory monitoring for the Task Compatibility module. Additional Data: Error Value: ResultCode.

Message #

Task Scheduler failed to start directory monitoring for the Task Compatibility module. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 706: Task Compatibility module failed to update task "TaskName" to the required status TaskStatus.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymoduletaskstatusupdatefailed

Description

Task Compatibility module failed to update task "TaskName" to the required status TaskStatus. Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to update task "%1"  to the required status %2. Additional Data: Error Value: %3.

Fields #

NameDescription
TaskName UnicodeString
TaskStatus UInt32
ResultCode UInt32

Event ID 707: Task Compatibility module failed to delete task "TaskName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymoduletaskdeletionfailed

Description

Task Compatibility module failed to delete task "TaskName" . Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to delete task "%1" . Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 708: Task Compatibility module failed to set security descriptor "SecurityDescriptor" for task "TaskName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymodulesecuritydescriptorfailed

Description

Task Compatibility module failed to set security descriptor "SecurityDescriptor" for task "TaskName" . Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to set security descriptor "%1"  for task "%2" . Additional Data: Error Value: %3.

Fields #

NameDescription
SecurityDescriptor UnicodeString
TaskName UnicodeString
ResultCode UInt32

Event ID 709: Task Compatibility module failed to update task "TaskName" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymoduletaskupdatefailed

Description

Task Compatibility module failed to update task "TaskName" . Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to update task "%1" . Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 710: Task Compatibility module failed to upgrade existing tasks.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymoduletasksupgradefailed

Description

Task Compatibility module failed to upgrade existing tasks. Upgrade will be attempted again next time 'Task Scheduler' service starts. Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to upgrade existing tasks. Upgrade will be attempted again next time 'Task Scheduler' service starts. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 711: Task Compatibility module failed to upgrade NetSchedule account "Account" .

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymoduletasksupgradefailed

Description

Task Compatibility module failed to upgrade NetSchedule account "Account" . Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to upgrade NetSchedule account "%1" . Additional Data: Error Value: %2.

Fields #

NameDescription
Account UnicodeString
ResultCode UInt32

Event ID 712: Task Compatibility module failed to read existing store to upgrade tasks.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymoduletasksupgradefailed

Description

Task Compatibility module failed to read existing store to upgrade tasks. Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to read  existing store to upgrade tasks. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 713: Task Compatibility module failed to load task "TaskName" for upgrade.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymoduletasksupgradefailed

Description

Task Compatibility module failed to load task "TaskName" for upgrade. Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to load task  "%1" for upgrade. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 714: Task Compatibility module failed to register task "TaskName" for upgrade.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymoduletasksupgradefailed

Description

Task Compatibility module failed to register task "TaskName" for upgrade. Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to register  task  "%1" for upgrade. Additional Data: Error Value: %2.

Fields #

NameDescription
TaskName UnicodeString
ResultCode UInt32

Event ID 715: Task Compatibility module failed to delete LSA store for upgrade.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymoduletasksupgradefailed

Description

Task Compatibility module failed to delete LSA store for upgrade. Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to delete  LSA store for upgrade. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 716: Task Compatibility module failed to upgrade existing scheduled tasks.

#
Channel
System
Task
Compatibilitymoduletasksupgradefailed

Description

Task Compatibility module failed to upgrade existing scheduled tasks. Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to upgrade existing scheduled tasks. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 717: Task Compatibility module failed to determine if upgrade is needed.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
Compatibilitymoduletasksupgradeundetermined

Description

Task Compatibility module failed to determine if upgrade is needed. Additional Data: Error Value: ResultCode.

Message #

Task Compatibility module failed to determine if upgrade is needed. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 718: Task scheduler was unable to upgrade the credential store from the Beta 2 version.

#
Channel
System
Task
Credentialstoreupgradefailed

Description

Task scheduler was unable to upgrade the credential store from the Beta 2 version. You may need to re-register any tasks that require passwords. Additional Data: Error Value: ResultCode.

Message #

Task scheduler was unable to upgrade the credential store from the Beta 2 version.  You may need to re-register any tasks that require passwords. Additional Data: Error Value: %1.

Fields #

NameDescription
ResultCode UInt32

Event ID 719: To help optimize for performance, Task Scheduler has automatically disabled logging.

#
Channel
System
Level
Informational
Task
TaskSchedulerOperationallogwasdisabled

Description

To help optimize for performance, Task Scheduler has automatically disabled logging. To re-enable logging, please use Event Viewer.

Message #

To help optimize for performance, Task Scheduler has automatically disabled logging. To re-enable logging, please use Event Viewer.

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "DE7B24EA-73C8-4A09-985D-5BDADCFA9017",
    "event_source_name": "",
    "event_id": 719,
    "version": 0,
    "level": 4,
    "task": 719,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-09T00:56:48.593820+00:00",
    "event_record_id": 2099,
    "correlation": {},
    "execution": {
      "process_id": 1780,
      "thread_id": 2060
    },
    "channel": "System",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "OpChannelDisabled"
  },
  "message": ""
}

Event ID 800: Maintenance state changed to Name (Last Run: hc_stateid).

#
Channel
Maintenance
Level
Informational
Task
Maintenancestatehaschanged

Message #

Maintenance state changed to %1 (Last Run: %2).

Fields #

NameDescription
hc_stateid UInt32
LastRunDateTime UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}",
    "event_source_name": "",
    "event_id": 800,
    "version": 0,
    "level": 4,
    "task": 800,
    "opcode": 0,
    "keywords": 576460752303423488,
    "time_created": "2026-06-13T06:05:42.6248982+00:00",
    "event_record_id": 69,
    "correlation": {},
    "execution": {
      "process_id": 2100,
      "thread_id": 6392
    },
    "channel": "Microsoft-Windows-TaskScheduler/Maintenance",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "hc_stateid": "1",
    "LastRunDateTime": "‎6/‎13/‎2026 6:05 AM"
  },
  "message": "Maintenance state changed to 1 (Last Run: ‎6/‎13/‎2026 6:05 AM)."
}

Event ID 801: Maintenance launch operation failed.

#
Channel
Maintenance
Task
Maintenancelaunchfailed

Description

Maintenance launch operation failed. Additional error info: ErrorCode.

Message #

Maintenance launch operation failed. Additional error info: %1.

Fields #

NameDescription
ErrorCode UInt32

Event ID 802: Maintenance re-configuration failed.

#
Channel
Maintenance
Task
Maintenancere_configurationfailed

Description

Maintenance re-configuration failed. Additional error info: ErrorCode.

Message #

Maintenance re-configuration failed. Additional error info: %1.

Fields #

NameDescription
ErrorCode UInt32

Event ID 803: Maintenance Scheduler engine task "Task" cannot be accessed.

#
Channel
Maintenance
Task
MaintenanceSchedulerenginetaskerror

Description

Maintenance Scheduler engine task "Task" cannot be accessed. Additional error info: ErrorCode.

Message #

Maintenance Scheduler engine task "%1" cannot be accessed. Additional error info: %2.

Fields #

NameDescription
Task UnicodeString
ErrorCode UInt32

Event ID 804: Maintenance Scheduler has detected cyclic dependency for the following maintenance tasks: Task.

#
Channel
Maintenance
Task
Maintenancetaskcycledependencydetected

Message #

Maintenance Scheduler has detected cyclic dependency for the following maintenance tasks: %1.

Fields #

NameDescription
Task UnicodeString

Event ID 805: Maintenance Task "Task" is behind deadline.

#
Channel
Maintenance
Task
Maintenancetaskisbehinddeadline

Message #

Maintenance Task "%1" is behind deadline.

Fields #

NameDescription
Task UnicodeString

Event ID 806: Maintenance task "Task" processing error.

#
Channel
Maintenance
Task
Maintenancetaskprocessingerror

Description

Maintenance task "Task" processing error. Additional error info InfoCode.

Message #

Maintenance task "%1" processing error. Additional error info %2.

Fields #

NameDescription
Task UnicodeString
InfoCode UInt32

Event ID 807: Maintenance complete (launch type LauncherId).

#
Channel
Maintenance
Task
Maintenancecomplete

Message #

Maintenance complete (launch type %1).

Fields #

NameDescription
LauncherId UInt32

Event ID 808: Maintenance Task "Name" requests computer wakeup during next regular maintenance run.

#
Channel
Maintenance
Level
Warning
Task
Maintenancewakeuprequested

Message #

Maintenance Task "%1" requests computer wakeup during next regular maintenance run.

Fields #

NameDescription
Task UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TaskScheduler",
    "guid": "DE7B24EA-73C8-4A09-985D-5BDADCFA9017",
    "event_source_name": "",
    "event_id": 808,
    "version": 0,
    "level": 3,
    "task": 808,
    "opcode": 0,
    "keywords": 576460752303423488,
    "time_created": "2023-10-26T04:22:01.225790+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 1860,
      "thread_id": 2172
    },
    "channel": "Microsoft-Windows-TaskScheduler/Maintenance",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "MaintenanceTaskWakeupRequested",
    "Task": "NT TASK\\Microsoft\\Windows\\.NET Framework\\.NET Framework NGEN v4.0.30319 Critical"
  },
  "message": ""
}

Example keys not documented in the fields table: Name

References #

Event ID 809: Maintenance Scheduler Group Policy Settings are not properly specified for "FailureReason".

#
Channel
System
Task
MaintenanceSchedulerconfigurationerror

Description

Maintenance Scheduler Group Policy Settings are not properly specified for "FailureReason". Default settings are being used.

Message #

Maintenance Scheduler Group Policy Settings are not properly specified for "%1". Default settings are being used.

Fields #

NameDescription
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 998: DEBUG!

#
Channel
Debug
Task
MethodFailure
Opcode
Failure

Description

DEBUG! (File:Line) "Name" failed. (HRESULT).

Message #

DEBUG! (%3:%4) "%1" failed. (%2).

Fields #

NameDescription
Name UnicodeString
HRESULT UInt32
File UnicodeString
Line UInt32

Event ID 999: DEBUG!

#
Channel
Debug
Task
Debug

Description

DEBUG! "String".

Message #

DEBUG! "%1".

Fields #

NameDescription
String UnicodeString

Provenance

ETW provider GUID {DE7B24EA-73C8-4A09-985D-5BDADCFA9017}

Defined in schedsvc.dll, which carries the event manifest.

  • Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB