Microsoft-Windows-TerminalServices-Gateway

EventTitleChannelSampleRule
100The RD Gateway service could not be initialized.OperationalNN
101The RD Gateway service has started.OperationalYN
102The Remote Desktop Gateway service requires a valid Secure Sockets Layer (SSL) …OperationalYN
103The Remote Desktop Gateway service does not have sufficient permissions to …OperationalYN
104The UDP Proxy is started.OperationalYN
105The UDP Proxy is shutting down.OperationalNN
106The UDP Proxy is not enabled.OperationalNN
200The user "EventInfo.Username", on client computer "EventInfo.IpAddress", met …OperationalYN
201The user "%1", on client computer "%2", did not meet connection authorization …OperationalNN
202The administrator disconnected the user "%1", on client computer "%2", from the …OperationalNN
203The number of simultaneous connections to the RD Gateway server has reached the …OperationalNN
204The user "%1", on client computer "%2", did not meet the requirements of the …OperationalNN
205The user "%1", on client computer "%2", successfully connected to the remote …OperationalNN
206The user "%1", on client computer "%2", failed connection to the remote server …OperationalNN
207The administrator disconnected the user "%1", on client computer "%2", from the …OperationalNN
208The UDP Proxy disconnected the user "%1" on client computer "%2", from the …OperationalNN
209The RD Gateway client supports HTTP proxy protocol but connected using Legacy …AdminNN
210Http transport: IN channel could not find a corresponding OUT channelAdminNN
300The user "EventInfo.Username", on client computer "EventInfo.IpAddress", met …OperationalYN
301The user "%1", on client computer "%2", did not meet resource authorization …OperationalNN
302The user "EventInfo.Username", on client computer "EventInfo.IpAddress", …OperationalYN
303The user "EventInfo.Username", on client computer "EventInfo.IpAddress", …OperationalYN
304The user "%1", on client computer "%2", met connection authorization policy and …OperationalNN
305The user "%1", on client computer "%2", was not authorized to connect to this RD …OperationalNN
306The user "%1", on client computer "%2", was not authorized to connect to the RD …OperationalNN
307The user "%1", on client computer "%2", disconnected from the following network …OperationalNN
308The user "%1", on client computer "%2", met RD resource authorization policy (RD …OperationalNN
309The user "%1", on client computer "%2", was disconnected from the following …OperationalNN
310The user "%1", connected by using client computer "%2" and "%8" connection …OperationalNN
311The user "%1", on client computer "%2", did not connect to the following network …OperationalNN
312The user "EventInfo.Username", on client computer "EventInfo.IpAddress", has …OperationalYN
313The user "%1", on client computer "%2", has initiated an inbound connection.OperationalNN
400The RD Gateway service is shutting down.OperationalNN
401The RD Gateway service successfully registered with the Service Connection …OperationalYN
402The RD Gateway service failed to register with the Service Connection Point.OperationalNN
403The RD Gateway service successfully unregistered with the Service Connection …OperationalNN
404The RD Gateway service failed to unregister with the Service Connection Point.OperationalNN
504Logging was enabled for the following RD Gateway event: "%1".AdminNN
505Logging could not be enabled for the following RD Gateway event: "%1".AdminNN
506Logging was disabled for the following RD Gateway event: "%1".AdminNN
507Logging could not be disabled for the following RD Gateway event: "%1".AdminNN
508The value for the maximum number of connections allowed to the RD Gateway server …AdminNN
509The value for the maximum number of simultaneous connections allowed to the RD …AdminNN
510The central connection authorization policy was enabled.AdminNN
511The central connection authorization policy store could not be enabled.AdminNN
512The central connection authorization policy was disabled.AdminNN
513The central connection authorization policy store could not be disabled.AdminNN
514The 'Request clients to send a statement of health' (SoH) setting is enabled on …AdminNN
515The 'Request clients to send a statement of health' (SoH) setting could not be …AdminNN
516The 'Request clients to send a statement of health' (SoH) setting is not enabled …AdminNN
517The 'Request clients to send a statement of health' (SoH) setting could not be …AdminNN
518The 'Request clients to send a statement of health' (SoH) setting could not be …AdminNN
519The server certificate is not valid because the public key of the certificate …AdminNN
520The connection authorization policy "%1" was created.AdminNN
521The connection authorization policy "%1" was deleted.AdminNN
522The connection authorization policy "%1" was updated.AdminNN
523The connection authorization policy "%1" could not be created.AdminNN
524The connection authorization policy "%1" could not be deleted.AdminNN
525The connection authorization policy "%1" could not be updated.AdminNN
526The system message was not enabled because a failure occurred.AdminNN
527The system message was successfully enabled.AdminNN
528The system message was not disabled because a failure occurred.AdminNN
529The system message was successfully disabled.AdminNN
530The logon message was not enabled because a failure occurred.AdminNN
531The logon message was successfully enabled.AdminNN
532The current logon message was not disabled because a failure occurred.AdminNN
533The current logon message was successfully disabled.AdminNN
540The resource authorization policy "%1" was created.AdminNN
541The resource authorization policy "%1" was deleted.AdminNN
542The resource authorization policy "%1" was updated.AdminNN
543The resource authorization policy (RAP) "%1" could not be created.AdminNN
544The resource authorization policy (RAP) "%1" could not be deleted.AdminNN
545The resource authorization policy (RAP) "%1" could not be updated.AdminNN
560The resource group "%1" was created.AdminNN
561The resource group "%1" was deleted.AdminNN
562The resource group "%1" was updated.AdminNN
563The resource group "%1" could not be created.AdminNN
564The resource group "%1" could not be deleted.AdminNN
565The resource group "%1" could not be updated.AdminNN
580The Network Policy Server (NPS) "%1" was added to the central connection …AdminNN
581The Network Policy Server (NPS) "%1" was deleted from the central connection …AdminNN
582The central connection authorization policy settings for the Network Policy …AdminNN
583The Network Policy Server (NPS) "%1" could not be added to the central …AdminNN
584The Network Policy Server (NPS) "%1" could not be deleted from the central …AdminNN
585The central connection authorization policy settings for the Network Policy …AdminNN
600Event ID 600TracingNN
601%1, Failed with %2.TracingNN
620The RD Gateway server "%1" was deleted from the list of servers in the RD …AdminNN
621The RD Gateway servers "%1" were added to the RD Gateway managed group.AdminNN
622The RD Gateway server "%1" could not be deleted from the list of servers in the …AdminNN
623The RD Gateway servers "%1" could not be added to the Remote Desktop Gateway …AdminNN
624The RD Gateway server "%1" is not a member of a domain and therefore cannot be …AdminNN
625A Windows Firewall exception for RD Gateway has been configured to allow data …AdminNN
626The Windows Firewall exception for RD Gateway to allow network traffic …AdminNN
627The Windows Firewall exception to allow network traffic through TCP port 3388.AdminNN
628The Windows Firewall exception "RD Gateway Server Farm" that allows network …AdminNN
629The RD Gateway servers "%1" were set to the RD Gateway managed group.AdminNN
630The RD Gateway servers "%1" could not be set to the RD Gateway managed group.AdminNN
640RD Gateway Network access Policy engine failed to contact IAS and the error was …OperationalNN
641RD Gateway Network access Policy engine received failure from IAS and the error …OperationalNN
642The RD Gateway server cannot open the resource authorization policy store on …OperationalNN
643RD Gateway Resource access Policy engine failed to open Azman Application(Remote …OperationalNN
700The following exception code "%2" occured in the RD Gateway server.AdminNN
701The exception code "%2" occurred in the authentication plug-in: "%1" loaded by …AdminNN
702The exception code "%2" occurred in the authorization plug-in: "%1" loaded by …AdminNN
1001The Remote Desktop Gateway service cannot determine the version of Windows that …AdminNN
1002The user authentication plug-in "%1" has been configured.AdminNN
1003RD Gateway native authentication is configured.AdminNN
1004The user authorization plug-in "%1" is enabled.AdminNN
1005The RD Gateway native authorization is enabled.AdminNN
2001The policy and server configuration settings for the RD Gateway server "%1" have …AdminNN
2002The policy and server configuration settings for the RD Gateway server "%1" …AdminNN
2003The policy and server configuration settings for the RD Gateway server "%1" have …AdminNN
2004The policy and server configuration settings for the RD Gateway server "%1" …AdminNN
3000The RD Gateway server certificate was changed.AdminNN
3001The RD Gateway server certificate cannot be changed.AdminNN
4001The Windows Firewall exception to allow network traffic comprising of Remote …AdminNN
4002The Windows Firewall exception to allow network traffic comprising of Remote …AdminNN
4003The Windows Firewall exception to allow network traffic comprising of Remote …AdminNN
4004The Windows Firewall exception to allow network traffic comprising of Remote …AdminNN

Event ID 100: The RD Gateway service could not be initialized.

#
Channel
Operational

Message #

The RD Gateway service could not be initialized. The following error occurred: "%2". To diagnose possible causes for this problem, verify whether the following services are installed and started: (1) World Wide Web Publishing Service (2) Internet Authentication Service (IAS) (3) RPC/HTTP Load Balancing Service. Also, check Event Viewer for Network Policy Server (NPS) and IIS events that might indicate problems with NPS or IIS. Also, check whether HTTP and UDP transport IP address, port pair is in use.

Event ID 101: The RD Gateway service has started.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "{4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B}",
    "event_source_name": "",
    "event_id": 101,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 10,
    "keywords": 4611686018444165120,
    "time_created": "2026-06-13T13:44:14.8043876+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 7104,
      "thread_id": 7080
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The RD Gateway service has started."
}

Event ID 102: The Remote Desktop Gateway service requires a valid Secure Sockets Layer (SSL) certificate to accept connections.

#
Channel
Operational
Level
3

Message #

The Remote Desktop Gateway service requires a valid Secure Sockets Layer (SSL) certificate to accept connections. Ensure that you have obtained a valid SSL certificate, and then bind (map) the certificate by using RD Gateway Manager. For more information, see "Obtain a certificate for the RD Gateway server" in the RD Gateway Help. The following error occurred: "%2"

Fields #

NameDescription
EventInfo.Name
EventInfo.ErrorCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "{4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B}",
    "event_source_name": "",
    "event_id": 102,
    "version": 0,
    "level": 3,
    "task": 1,
    "opcode": 12,
    "keywords": 4611686018477719552,
    "time_created": "2026-06-13T13:44:14.7704496+00:00",
    "event_record_id": 6,
    "correlation": {},
    "execution": {
      "process_id": 7104,
      "thread_id": 7080
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Name": "",
      "ErrorCode": "259"
    }
  },
  "message": "The Remote Desktop Gateway service requires a valid Secure Sockets Layer (SSL) certificate to accept connections. Ensure that you have obtained a valid SSL certificate, and then bind (map) the certificate by using RD Gateway Manager. For more information, see \"Obtain a certificate for the RD Gateway server\" in the RD Gateway Help. The following error occurred: \"259\""
}

Event ID 103: The Remote Desktop Gateway service does not have sufficient permissions to access the Secure Sockets Layer (SSL) certificate that is required to ac...

#
Channel
Operational
Level
1

Message #

The Remote Desktop Gateway service does not have sufficient permissions to access the Secure Sockets Layer (SSL) certificate that is required to accept connections. To resolve this issue, bind (map) a valid SSL certificate by using RD Gateway Manager. For more information, see "Obtain a certificate for the RD Gateway server" in the RD Gateway Help. The following error occurred: "%2".

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 103,
    "version": 0,
    "level": 1,
    "task": 1,
    "opcode": 12,
    "keywords": 4611686018477719552,
    "time_created": "2026-08-01T01:05:29.014277+00:00",
    "event_record_id": 6,
    "correlation": {},
    "execution": {
      "process_id": 2628,
      "thread_id": 5500
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Name": null,
      "ErrorCode": 2148073494
    }
  },
  "message": ""
}

Event ID 104: The UDP Proxy is started.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "{4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B}",
    "event_source_name": "",
    "event_id": 104,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 12,
    "keywords": 4611686018444165120,
    "time_created": "2026-06-13T13:44:14.7734504+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 7104,
      "thread_id": 7080
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The UDP Proxy is started."
}

Event ID 105: The UDP Proxy is shutting down.

#
Channel
Operational

Event ID 106: The UDP Proxy is not enabled.

#
Channel
Operational

Event ID 200: The user "EventInfo.Username", on client computer "EventInfo.IpAddress", met connection authorization policy requirements and was therefore authorized to access the RD Gateway server.

#
Channel
Operational
Level
Informational

Message #

The user "%1", on client computer "%2", met connection authorization policy requirements and was therefore authorized to access the RD Gateway server. The authentication method used was: "%3" and connection protocol used: "%5".

Fields #

NameDescription
EventInfo.Username
EventInfo.IpAddress
EventInfo.AuthType
EventInfo.Resource
EventInfo.ConnectionProtocol
EventInfo.ErrorCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 200,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 30,
    "keywords": 4620693217698906112,
    "time_created": "2024-11-04T13:59:32.400587+00:00",
    "event_record_id": 87,
    "correlation": {
      "ActivityID": "7CF86876-882F-0625-F153-3DEC514DA0B2"
    },
    "execution": {
      "process_id": 1444,
      "thread_id": 2256
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "EC2AMAZ-6C3C9U6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Username": "EC2AMAZ-6C3C9U6\\Administrator",
      "IpAddress": "198.51.100.1",
      "AuthType": "NTLM",
      "Resource": "",
      "ConnectionProtocol": "HTTP",
      "ErrorCode": 0
    }
  },
  "message": ""
}

References #

Event ID 201: The user "%1", on client computer "%2", did not meet connection authorization policy requirements and was therefore not authorized to access the RD...

#
Channel
Operational

Message #

The user "%1", on client computer "%2", did not meet connection authorization policy requirements and was therefore not authorized to access the RD Gateway server. The authentication method used was: "%3" and connection protocol used: "%5". The following error occurred: "%6".

Event ID 202: The administrator disconnected the user "%1", on client computer "%2", from the following network resource: "%4".

#
Channel
Operational

Message #

The administrator disconnected the user "%1", on client computer "%2", from the following network resource: "%4". Before the user was disconnected, the client transferred %6 bytes and received %5 bytes using %8 connection protocol. The client session duration was %7 seconds.

Event ID 203: The number of simultaneous connections to the RD Gateway server has reached the maximum number that was configured by the administrator.

#
Channel
Operational

Message #

The number of simultaneous connections to the RD Gateway server has reached the maximum number that was configured by the administrator. The server is therefore not accepting any new connections. The connection attempt by user "%1" on client computer "%2", using the authentication method "%3" has been denied. For information about how to modify the maximum connection limit, see the "Specify the Maximum Number of Allowable Connections for RD Gateway" topic in the RD Gateway Help.

Event ID 204: The user "%1", on client computer "%2", did not meet the requirements of the Network Access Protection (NAP) policies defined in the Network Policy...

#
Channel
Operational

Message #

The user "%1", on client computer "%2", did not meet the requirements of the Network Access Protection (NAP) policies defined in the Network Policy Server. Therefore, the user was not authorized to connect to the RD Gateway server. The authentication method attempted: "%3" and connection protocol used "%5". The following error occurred: "%6".

Event ID 205: The user "%1", on client computer "%2", successfully connected to the remote server "%4" using UDP proxy.

#
Channel
Operational

Description

The user "%1", on client computer "%2", successfully connected to the remote server "%4" using UDP proxy. The authentication method used was: "%3".

Message #

The user "%1", on client computer "%2", successfully connected to the remote server "%4" using UDP proxy. The authentication method used was: "%3".

Event ID 206: The user "%1", on client computer "%2", failed connection to the remote server "%4" using UDP proxy.

#
Channel
Operational

Description

The user "%1", on client computer "%2", failed connection to the remote server "%4" using UDP proxy. The following error occurred : "%9".

Message #

The user "%1", on client computer "%2", failed connection to the remote server "%4" using UDP proxy. The following error occurred : "%9".

Event ID 207: The administrator disconnected the user "%1", on client computer "%2", from the following network resource: "%4".

#
Channel
Operational

Message #

The administrator disconnected the user "%1", on client computer "%2", from the following network resource: "%4". Before the user was disconnected, the client transferred %6 bytes and received %5 bytes. The client session duration was %7 seconds.

Event ID 208: The UDP Proxy disconnected the user "%1" on client computer "%2", from the following network resource: "%4" because it was unresponsive.

#
Channel
Operational

Message #

The UDP Proxy disconnected the user "%1" on client computer "%2", from the following network resource: "%4" because it was unresponsive. Before the user was disconnected, the client transferred %6 bytes and received %5 bytes. The client session duration was %7 seconds.

Event ID 209: The RD Gateway client supports HTTP proxy protocol but connected using Legacy RPC-HTTP.

#
Channel
Admin

Event ID 210: Http transport: IN channel could not find a corresponding OUT channel

#
Channel
Admin

Event ID 300: The user "EventInfo.Username", on client computer "EventInfo.IpAddress", met resource authorization policy requirements and was therefore authorized to connect to resource "EventInfo.Resource".

#
Channel
Operational
Level
Informational

Message #

The user "%1", on client computer "%2", met resource authorization policy requirements and was therefore authorized to connect to resource "%4".

Fields #

NameDescription
EventInfo.Username
EventInfo.IpAddress
EventInfo.AuthType
EventInfo.Resource
EventInfo.ConnectionProtocol
EventInfo.ErrorCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 300,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 30,
    "keywords": 4620693217698906112,
    "time_created": "2024-11-04T13:59:32.621299+00:00",
    "event_record_id": 88,
    "correlation": {
      "ActivityID": "7CF86876-882F-0625-F153-3DEC514DA0B2"
    },
    "execution": {
      "process_id": 1444,
      "thread_id": 2556
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "EC2AMAZ-6C3C9U6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Username": "EC2AMAZ-6C3C9U6\\Administrator",
      "IpAddress": "198.51.100.1",
      "AuthType": "",
      "Resource": "ec2-18-179-8-103.ap-northeast-1.compute.amazonaws.com",
      "ConnectionProtocol": "",
      "ErrorCode": 0
    }
  },
  "message": ""
}

References #

Event ID 301: The user "%1", on client computer "%2", did not meet resource authorization policy requirements and was therefore not authorized to resource "%4".

#
Channel
Operational

Description

The user "%1", on client computer "%2", did not meet resource authorization policy requirements and was therefore not authorized to resource "%4". The following error occurred: "%6".

Message #

The user "%1", on client computer "%2", did not meet resource authorization policy requirements and was therefore not authorized to resource "%4". The following error occurred: "%6".

Event ID 302: The user "EventInfo.Username", on client computer "EventInfo.IpAddress", connected to resource "EventInfo.Resource".

#
Channel
Operational
Level
Informational

Description

The user "EventInfo.Username", on client computer "EventInfo.IpAddress", connected to resource "EventInfo.Resource". Connection protocol used: "EventInfo.ConnectionProtocol".

Message #

The user "%1", on client computer "%2", connected to resource "%4". Connection protocol used: "%5".

Fields #

NameDescription
EventInfo.Username
EventInfo.IpAddress
EventInfo.AuthType
EventInfo.Resource
EventInfo.ConnectionProtocol
EventInfo.ErrorCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 302,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 30,
    "keywords": 4611686018444165120,
    "time_created": "2024-11-04T13:59:32.624374+00:00",
    "event_record_id": 89,
    "correlation": {
      "ActivityID": "7CF86876-882F-0625-F153-3DEC514DA0B2"
    },
    "execution": {
      "process_id": 1444,
      "thread_id": 2556
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "EC2AMAZ-6C3C9U6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Username": "EC2AMAZ-6C3C9U6\\Administrator",
      "IpAddress": "198.51.100.1",
      "AuthType": "",
      "Resource": "ec2-18-179-8-103.ap-northeast-1.compute.amazonaws.com",
      "ConnectionProtocol": "HTTP",
      "ErrorCode": 0
    }
  },
  "message": ""
}

References #

Event ID 303: The user "EventInfo.Username", on client computer "EventInfo.IpAddress", disconnected from the following network resource: "EventInfo.Resource".

#
Channel
Operational
Level
Informational

Message #

The user "%1", on client computer "%2", disconnected from the following network resource: "%4". Before the user disconnected, the client transferred %6 bytes and received %5 bytes. The client session duration was %7 seconds. Connection protocol used: "%8".

Fields #

NameDescription
EventInfo.Username
EventInfo.IpAddress
EventInfo.AuthType
EventInfo.Resource
EventInfo.BytesReceived
EventInfo.BytesTransfered
EventInfo.SessionDuration
EventInfo.ConnectionProtocol
EventInfo.ErrorCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 303,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 44,
    "keywords": 4611686018444165120,
    "time_created": "2024-11-04T13:59:25.431624+00:00",
    "event_record_id": 84,
    "correlation": {
      "ActivityID": "D993DEC4-0E8C-5014-E2B6-F10CDDA2250E"
    },
    "execution": {
      "process_id": 1444,
      "thread_id": 2256
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "EC2AMAZ-6C3C9U6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Username": "EC2AMAZ-6C3C9U6\\Administrator",
      "IpAddress": "198.51.100.1",
      "AuthType": "",
      "Resource": "ec2-18-179-8-103.ap-northeast-1.compute.amazonaws.com",
      "BytesReceived": "391624",
      "BytesTransfered": "241242",
      "SessionDuration": "57",
      "ConnectionProtocol": "HTTP",
      "ErrorCode": 1226
    }
  },
  "message": ""
}

References #

Event ID 304: The user "%1", on client computer "%2", met connection authorization policy and resource authorization policy requirements, but could not connect t...

#
Channel
Operational

Message #

The user "%1", on client computer "%2", met connection authorization policy and resource authorization policy requirements, but could not connect to resource "%4". Connection protocol used: "%5". The following error occurred: "%6".

Event ID 305: The user "%1", on client computer "%2", was not authorized to connect to this RD Gateway server because the authentication method attempted by the ...

#
Channel
Operational

Message #

The user "%1", on client computer "%2", was not authorized to connect to this RD Gateway server because the authentication method attempted by the user is not supported. The following authentication method was attempted. "%3". The following error occurred: "%6".

Event ID 306: The user "%1", on client computer "%2", was not authorized to connect to the RD Gateway server because a tunnel could not be created.

#
Channel
Operational

Message #

The user "%1", on client computer "%2", was not authorized to connect to the RD Gateway server because a tunnel could not be created. The authentication method attempted: "%3" and connection protocol "%5". The following error occurred: "%6".

Event ID 307: The user "%1", on client computer "%2", disconnected from the following network resource: "%3" because the session exceeded the session timeout lim...

#
Channel
Operational

Description

The user "%1", on client computer "%2", disconnected from the following network resource: "%3" because the session exceeded the session timeout limit of "%4" minutes.

Message #

The user "%1", on client computer "%2", disconnected from the following network resource: "%3" because the session exceeded the session timeout limit of "%4" minutes.
At the time the user was disconnected:
Client transferred: %5 bytes
 Client received:%6 bytes
 Client session duration: %7 seconds
The user can try reconnecting again to the network resource.

Event ID 308: The user "%1", on client computer "%2", met RD resource authorization policy (RD RAP) requirements but the network resource "%5" did not meet the r...

#
Channel
Operational

Message #

The user "%1", on client computer "%2", met RD resource authorization policy (RD RAP) requirements but the network resource "%5" did not meet the requirements, so the connection was not authorized. Try connection to another network resource or possibly lower RD Gateway security by modifying the RD RAP requirements for the connection to be authorized.

Event ID 309: The user "%1", on client computer "%2", was disconnected from the following network resource: "%4" because of a failure during reauthentication/rea...

#
Channel
Operational

Description

The user "%1", on client computer "%2", was disconnected from the following network resource: "%4" because of a failure during reauthentication/reauthorization.

Message #

The user "%1", on client computer "%2", was disconnected from the following network resource: "%4" because of a failure during reauthentication/reauthorization.
At the time the user was disconnected:
Client transferred: %6 bytes
Client received: %5 bytes
Client session duration: %7 seconds
The user can try reconnecting again to the resource by using a valid username and password.

Event ID 310: The user "%1", connected by using client computer "%2" and "%8" connection protocol to the network resource "%3" was successfully reauthenticated/r...

#
Channel
Operational

Message #

The user "%1",  connected by using client computer "%2" and "%8" connection protocol to the network resource "%3" was successfully reauthenticated/reauthorized after a session timeout of %4 minutes. No user action is required.

Event ID 311: The user "%1", on client computer "%2", did not connect to the following network resource: "%4" because the remote computer does not support secure...

#
Channel
Operational

Message #

The user "%1", on client computer "%2", did not connect to the following network resource: "%4" because the remote computer does not support secure device redirection. Try selecting another network resource or possibly lower RD Gateway security by modifying RD CAP to allow client connections to resources that do not enforce device redirection.

Event ID 312: The user "EventInfo.Username", on client computer "EventInfo.IpAddress", has initiated an outbound connection.

#
Channel
Operational

Description

The user "EventInfo.Username", on client computer "EventInfo.IpAddress", has initiated an outbound connection. This connection may not be authenticated yet.

Message #

The user "%1", on client computer "%2", has initiated an outbound connection. This connection may not be authenticated yet.

Fields #

NameDescription
EventInfo.Username
EventInfo.IpAddress

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B",
    "event_source_name": "",
    "event_id": 312,
    "version": 0,
    "level": 0,
    "task": 3,
    "opcode": 30,
    "keywords": 4611686018427387904,
    "time_created": "2024-11-04T13:59:31.379210+00:00",
    "event_record_id": 86,
    "correlation": {
      "ActivityID": "7CF86876-882F-0625-F153-3DEC514DA0B2"
    },
    "execution": {
      "process_id": 1444,
      "thread_id": 2256
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "EC2AMAZ-6C3C9U6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventInfo": {
      "Username": "Administrator",
      "IpAddress": "198.51.100.1:63920"
    }
  },
  "message": ""
}

References #

Event ID 313: The user "%1", on client computer "%2", has initiated an inbound connection.

#
Channel
Operational

Description

The user "%1", on client computer "%2", has initiated an inbound connection. This connection may not be authenticated yet.

Message #

The user "%1", on client computer "%2", has initiated an inbound connection. This connection may not be authenticated yet.

Event ID 400: The RD Gateway service is shutting down.

#
Channel
Operational

Message #

The RD Gateway service is shutting down. This maybe voluntary administrator restart or a configuration driven restart due to RDG server certificate change. If the RD Gateway shutdown was not expected, kindly verify whether the following services are started: (1) Network Policy Server; (2) Remote Procedure Call (RPC); (3) RPC/HTTP Load Balancing Service;  and (4) World Wide Web Publishing Service. Also, check Event Viewer for Network Policy Server (NPS) and IIS events that might indicate problems with NPS or IIS.

Event ID 401: The RD Gateway service successfully registered with the Service Connection Point.

#
Channel
Operational
Level
4

Description

The RD Gateway service successfully registered with the Service Connection Point. No user action is required.

Message #

The RD Gateway service successfully registered with the Service Connection Point. No user action is required.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-Gateway",
    "guid": "{4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B}",
    "event_source_name": "",
    "event_id": 401,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 16,
    "keywords": 4611686018444165120,
    "time_created": "2026-06-13T13:44:14.7523156+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 7104,
      "thread_id": 7080
    },
    "channel": "Microsoft-Windows-TerminalServices-Gateway/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The RD Gateway service successfully registered with the Service Connection Point. No user action is required."
}

Event ID 402: The RD Gateway service failed to register with the Service Connection Point.

#
Channel
Operational

Event ID 403: The RD Gateway service successfully unregistered with the Service Connection Point.

#
Channel
Operational

Description

The RD Gateway service successfully unregistered with the Service Connection Point. No user action is required.

Message #

The RD Gateway service successfully unregistered with the Service Connection Point. No user action is required.

Event ID 404: The RD Gateway service failed to unregister with the Service Connection Point.

#
Channel
Operational

Event ID 504: Logging was enabled for the following RD Gateway event: "%1".

#
Channel
Admin

Event ID 505: Logging could not be enabled for the following RD Gateway event: "%1".

#
Channel
Admin

Message #

Logging could not be enabled for the following RD Gateway event: "%1". The following error occurred: "%2". To resolve this issue, ensure that the correct permissions have been granted to the LogEvents registry key and that the Remote Registry service is started.

Event ID 506: Logging was disabled for the following RD Gateway event: "%1".

#
Channel
Admin

Event ID 507: Logging could not be disabled for the following RD Gateway event: "%1".

#
Channel
Admin

Message #

Logging could not be disabled for the following RD Gateway event: "%1". The following error occurred: "%2". To resolve this issue, ensure that the correct permissions have been granted to the LogEvents registry key and that the Remote Registry service is started.

Event ID 508: The value for the maximum number of connections allowed to the RD Gateway server was updated.

#
Channel
Admin

Event ID 509: The value for the maximum number of simultaneous connections allowed to the RD Gateway server could not be updated.

#
Channel
Admin

Description

The value for the maximum number of simultaneous connections allowed to the RD Gateway server could not be updated. The following error occurred: "%2".

Message #

The value for the maximum number of simultaneous connections allowed to the RD Gateway server could not be updated. The following error occurred: "%2".

Event ID 510: The central connection authorization policy was enabled.

#
Channel
Admin

Event ID 511: The central connection authorization policy store could not be enabled.

#
Channel
Admin

Message #

The central connection authorization policy store could not be enabled. The following error occurred: "%2". To resolve this issue, ensure that you have typed the name of the Network Policy Server (NPS) correctly and that the NPS exists on the network, and then try again. If the problem persists, then identify and resolve any network connectivity issues.

Event ID 512: The central connection authorization policy was disabled.

#
Channel
Admin

Event ID 513: The central connection authorization policy store could not be disabled.

#
Channel
Admin

Description

The central connection authorization policy store could not be disabled. The following error occurred: "%2".

Message #

The central connection authorization policy store could not be disabled. The following error occurred: "%2".

Event ID 514: The 'Request clients to send a statement of health' (SoH) setting is enabled on this RD Gateway server.

#
Channel
Admin

Message #

The 'Request clients to send a statement of health' (SoH) setting is enabled on this RD Gateway server. Therefore; each time a client attempts to connect to this RD Gateway server; the client’s SoH will be requested.

Event ID 515: The 'Request clients to send a statement of health' (SoH) setting could not be enabled on this RD Gateway server.

#
Channel
Admin

Message #

The 'Request clients to send a statement of health' (SoH) setting could not be enabled on this RD Gateway server. To resolve this issue; ensure that the QuarantineEnabled registry key exists and that the System and Administrators groups are granted Full Control permissions to this key. The following error occurred: '{name}'.

Fields #

NameDescription
name

Event ID 516: The 'Request clients to send a statement of health' (SoH) setting is not enabled on this RD Gateway server.

#
Channel
Admin

Message #

The 'Request clients to send a statement of health' (SoH) setting is not enabled on this RD Gateway server. Therefore; the client’s SoH will not be requested when the client attempts to connect to this RD Gateway server.

Event ID 517: The 'Request clients to send a statement of health' (SoH) setting could not be disabled on this RD Gateway server.

#
Channel
Admin

Message #

The 'Request clients to send a statement of health' (SoH) setting could not be disabled on this RD Gateway server. To resolve this issue; ensure that the QuarantineEnabled registry key exists and that the System and Administrators groups are granted Full Control permissions to this key. The following error occurred: '{name}'.

Fields #

NameDescription
name

Event ID 518: The 'Request clients to send a statement of health' (SoH) setting could not be enabled on this RD Gateway server.

#
Channel
Admin

Message #

The 'Request clients to send a statement of health' (SoH) setting could not be enabled on this RD Gateway server. This setting could not be enabled because the public key of the server certificate that is bound (mapped) to the Remote Desktop Gateway service contains an object identifier (also known as OID) of 2.5.29.15; but does not support the Extended Key Usage (EKU) for encryption. To resolve this issue; if the certificate that you plan to use contains an OID of 2.5.29.15; you must ensure that one of the following key usage values for this certificate is also set: (1) CERT_KEY_ENCIPHERMENT_KEY_USAGE (2) CERT_KEY_AGREEMENT_KEY_USAGE (3) CERT_DATA_ENCIPHERMENT_KEY_USAGE. Bind (map) the certificate again by using RD Gateway Manager; and then attempt to enable the 'Request clients to send a statement of health' setting again. For more information; see 'Obtain a certificate for the RD Gateway server' in the RD Gateway Help.

Event ID 519: The server certificate is not valid because the public key of the certificate contains an object identifier (also known as OID) of 2.

#
Channel
Admin

Message #

The server certificate is not valid because the public key of the certificate contains an object identifier (also known as OID) of 2.5.29.15, but does not support the Extended Key Usage (EKU) for encryption. For the "Request clients to send a statement of health" setting that is enabled on this RD Gateway server to function, if the certificate that you plan to use contains an OID of 2.5.29.15, you must ensure that one of the following key usage values for this certificate is also set: (1) CERT_KEY_ENCIPHERMENT_KEY_USAGE (2) CERT_KEY_AGREEMENT_KEY_USAGE (3) CERT_DATA_ENCIPHERMENT_KEY_USAGE. For more information, see "Obtain a certificate for the RD Gateway server" in the RD Gateway Help.

Event ID 520: The connection authorization policy "%1" was created.

#
Channel
Admin

Event ID 521: The connection authorization policy "%1" was deleted.

#
Channel
Admin

Event ID 522: The connection authorization policy "%1" was updated.

#
Channel
Admin

Event ID 523: The connection authorization policy "%1" could not be created.

#
Channel
Admin

Description

The connection authorization policy "%1" could not be created. The following error occurred: "%2".

Message #

The connection authorization policy "%1" could not be created. The following error occurred: "%2".

Event ID 524: The connection authorization policy "%1" could not be deleted.

#
Channel
Admin

Description

The connection authorization policy "%1" could not be deleted. The following error occurred: "%2".

Message #

The connection authorization policy "%1" could not be deleted. The following error occurred: "%2".

Event ID 525: The connection authorization policy "%1" could not be updated.

#
Channel
Admin

Description

The connection authorization policy "%1" could not be updated. The following error occurred: "%2".

Message #

The connection authorization policy "%1" could not be updated. The following error occurred: "%2".

Event ID 526: The system message was not enabled because a failure occurred.

#
Channel
Admin

Description

The system message was not enabled because a failure occurred. Try enabling the system message again.

Message #

The system message was not enabled because a failure occurred. Try enabling the system message again.

Event ID 527: The system message was successfully enabled.

#
Channel
Admin

Description

The system message was successfully enabled. No user action is required.

Message #

The system message was successfully enabled. No user action is required.

Event ID 528: The system message was not disabled because a failure occurred.

#
Channel
Admin

Description

The system message was not disabled because a failure occurred. Try removing the system message again.

Message #

The system message was not disabled because a failure occurred. Try removing the system message again.

Event ID 529: The system message was successfully disabled.

#
Channel
Admin

Description

The system message was successfully disabled. No user action is required.

Message #

The system message was successfully disabled. No user action is required.

Event ID 530: The logon message was not enabled because a failure occurred.

#
Channel
Admin

Description

The logon message was not enabled because a failure occurred. Try enabling the logon message again.

Message #

The logon message was not enabled because a failure occurred. Try enabling the logon message again.

Event ID 531: The logon message was successfully enabled.

#
Channel
Admin

Description

The logon message was successfully enabled. No user action is required.

Message #

The logon message was successfully enabled. No user action is required.

Event ID 532: The current logon message was not disabled because a failure occurred.

#
Channel
Admin

Description

The current logon message was not disabled because a failure occurred. Try disabling the logon message again.

Message #

The current logon message was not disabled because a failure occurred. Try disabling the logon message again.

Event ID 533: The current logon message was successfully disabled.

#
Channel
Admin

Description

The current logon message was successfully disabled. No user action is required.

Message #

The current logon message was successfully disabled. No user action is required.

Event ID 540: The resource authorization policy "%1" was created.

#
Channel
Admin

Event ID 541: The resource authorization policy "%1" was deleted.

#
Channel
Admin

Event ID 542: The resource authorization policy "%1" was updated.

#
Channel
Admin

Event ID 543: The resource authorization policy (RAP) "%1" could not be created.

#
Channel
Admin

Message #

The resource authorization policy (RAP) "%1" could not be created. The following error occurred: "%2". To resolve this issue, ensure that you have configured RAP settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 544: The resource authorization policy (RAP) "%1" could not be deleted.

#
Channel
Admin

Message #

The resource authorization policy (RAP) "%1" could not be deleted. The following error occurred: "%2". To resolve this issue, ensure that you have configured RAP settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 545: The resource authorization policy (RAP) "%1" could not be updated.

#
Channel
Admin

Message #

The resource authorization policy (RAP) "%1" could not be updated. The following error occurred: "%2". To resolve this issue, ensure that you have configured RAP settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 560: The resource group "%1" was created.

#
Channel
Admin

Event ID 561: The resource group "%1" was deleted.

#
Channel
Admin

Event ID 562: The resource group "%1" was updated.

#
Channel
Admin

Event ID 563: The resource group "%1" could not be created.

#
Channel
Admin

Message #

The resource group "%1" could not be created. The following error occurred: "%2". To resolve this issue, ensure that you have configured resource group settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 564: The resource group "%1" could not be deleted.

#
Channel
Admin

Message #

The resource group "%1" could not be deleted. The following error occurred: "%2". To resolve this issue, ensure that you have configured resource group settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 565: The resource group "%1" could not be updated.

#
Channel
Admin

Message #

The resource group "%1" could not be updated. The following error occurred: "%2". To resolve this issue, ensure that you have configured resource group settings correctly and set the correct value and permissions for the RAP.xml file and the RAPStore registry key.

Event ID 580: The Network Policy Server (NPS) "%1" was added to the central connection authorization policy.

#
Channel
Admin

Event ID 581: The Network Policy Server (NPS) "%1" was deleted from the central connection authorization policy.

#
Channel
Admin

Event ID 582: The central connection authorization policy settings for the Network Policy Server (NPS) "%1" have been updated.

#
Channel
Admin

Event ID 583: The Network Policy Server (NPS) "%1" could not be added to the central connection authorization policy.

#
Channel
Admin

Message #

The Network Policy Server (NPS) "%1" could not be added to the central connection authorization policy. The following error occurred: "%2". To resolve this issue, ensure that you have typed the name of the Network Policy Server (NPS) correctly and that the NPS exists on the network, and then try again. If the problem persists, then identify and any resolve network connectivity issues.

Event ID 584: The Network Policy Server (NPS) "%1" could not be deleted from the central connection authorization policy.

#
Channel
Admin

Description

The Network Policy Server (NPS) "%1" could not be deleted from the central connection authorization policy. The following error occurred: "%2".

Message #

The Network Policy Server (NPS) "%1" could not be deleted from the central connection authorization policy. The following error occurred: "%2".

Event ID 585: The central connection authorization policy settings for the Network Policy Server "%1" could not be updated.

#
Channel
Admin

Message #

The central connection authorization policy settings for the Network Policy Server "%1" could not be updated. The following error occurred: "%2". To resolve this issue, ensure that you have typed the name of the Network Policy Server (NPS) correctly and that the NPS exists on the network, and then try again. If the problem persists, then identify and resolve any network connectivity issues.

Event ID 600

#
Channel
Tracing

Message #

%1

Event ID 601: %1, Failed with %2.

#
Channel
Tracing

Description

, Failed with.

Event ID 620: The RD Gateway server "%1" was deleted from the list of servers in the RD Gateway server farm.

#
Channel
Admin

Event ID 621: The RD Gateway servers "%1" were added to the RD Gateway managed group.

#
Channel
Admin

Description

The RD Gateway servers "%1" were added to the RD Gateway managed group. No user action is required.

Message #

The RD Gateway servers "%1" were added to the RD Gateway managed group. No user action is required.

Event ID 622: The RD Gateway server "%1" could not be deleted from the list of servers in the RD Gateway server farm.

#
Channel
Admin

Description

The RD Gateway server "%1" could not be deleted from the list of servers in the RD Gateway server farm. The following error occurred: "%2".

Message #

The RD Gateway server "%1" could not be deleted from the list of servers in the RD Gateway server farm. The following error occurred: "%2".

Event ID 623: The RD Gateway servers "%1" could not be added to the Remote Desktop Gateway managed group.

#
Channel
Admin

Description

The RD Gateway servers "%1" could not be added to the Remote Desktop Gateway managed group. The following error occurred: "%2".

Message #

The RD Gateway servers "%1" could not be added to the Remote Desktop Gateway managed group. The following error occurred: "%2".

Event ID 624: The RD Gateway server "%1" is not a member of a domain and therefore cannot be added to the RD Gateway server farm.

#
Channel
Admin

Message #

The RD Gateway server "%1" is not a member of a domain and therefore cannot be added to the RD Gateway server farm. To add this RD Gateway server to the farm, you must first add the server to a domain.

Event ID 625: A Windows Firewall exception for RD Gateway has been configured to allow data for Remote Desktop Services client connections and RPC-HTTP load bala...

#
Channel
Admin

Message #

A Windows Firewall exception for RD Gateway has been configured to allow data for Remote Desktop Services client connections and RPC-HTTP load balancing to be sent between RD Gateway servers when load balancing is used. This exception is automatically configured when you add the first RD Gateway server to a RD Gateway server farm.

Event ID 626: The Windows Firewall exception for RD Gateway to allow network traffic comprising of Remote Desktop Services client connections data and RPC-HTTP l...

#
Channel
Admin

Message #

The Windows Firewall exception for RD Gateway to allow network traffic comprising of Remote Desktop Services client connections data and RPC-HTTP load balancing data (to be sent between RD Gateway servers when load balancing is used) has been disabled. This exception is automatically disabled when you remove all RD Gateway servers from a RD Gateway server farm.

Event ID 627: The Windows Firewall exception to allow network traffic through TCP port 3388.

#
Channel
Admin

Message #

The Windows Firewall exception to allow network traffic through TCP port 3388 (so that Remote Desktop Services client connections can be directed to the appropriate RD Gateway servers when load balancing is used) could not be configured.

Event ID 628: The Windows Firewall exception "RD Gateway Server Farm" that allows network traffic through TCP port 3388.

#
Channel
Admin

Message #

The Windows Firewall exception "RD Gateway Server Farm" that allows network traffic through TCP port 3388 (so that Remote Desktop Services client connections can be directed to the appropriate Remote Desktop Gateway servers when load balancing is used) could not be disabled. We recommend that you disable this exception manually by modifying Windows Firewall settings as needed.

Event ID 629: The RD Gateway servers "%1" were set to the RD Gateway managed group.

#
Channel
Admin

Description

The RD Gateway servers "%1" were set to the RD Gateway managed group. No user action is required.

Message #

The RD Gateway servers "%1" were set to the RD Gateway managed group. No user action is required.

Event ID 630: The RD Gateway servers "%1" could not be set to the RD Gateway managed group.

#
Channel
Admin

Description

The RD Gateway servers "%1" could not be set to the RD Gateway managed group. The following error occurred: "%2".

Message #

The RD Gateway servers "%1" could not be set to the RD Gateway managed group. The following error occurred: "%2".

Event ID 640: RD Gateway Network access Policy engine failed to contact IAS and the error was "%2".

#
Channel
Operational

Event ID 641: RD Gateway Network access Policy engine received failure from IAS and the error was "%2".

#
Channel
Operational

Event ID 642: The RD Gateway server cannot open the resource authorization policy store on Authorization Manager (Azman).

#
Channel
Operational

Description

The RD Gateway server cannot open the resource authorization policy store on Authorization Manager (Azman). The following error occurred: "%2".

Message #

The RD Gateway server cannot open the resource authorization policy store on Authorization Manager (Azman). The following error occurred: "%2".

Event ID 643: RD Gateway Resource access Policy engine failed to open Azman Application(Remote Desktop Gateway) and the error was "%2".

#
Channel
Operational

Event ID 700: The following exception code "%2" occured in the RD Gateway server.

#
Channel
Admin

Description

The following exception code "%2" occured in the RD Gateway server. The RD Gateway will be restarted. No user action is required.

Message #

The following exception code "%2" occured in the RD Gateway server. The RD Gateway will be restarted. No user action is required.

Event ID 701: The exception code "%2" occurred in the authentication plug-in: "%1" loaded by the RD Gateway server.

#
Channel
Admin

Message #

The exception code "%2" occurred in the authentication plug-in: "%1" loaded by the RD Gateway server. The RD Gateway server will be restarted. Continued failures might indicate a problem with the authentication plug-in.

Event ID 702: The exception code "%2" occurred in the authorization plug-in: "%1" loaded by the RD Gateway server.

#
Channel
Admin

Message #

The exception code "%2" occurred in the authorization plug-in: "%1" loaded by the RD Gateway server. The RD Gateway server will be restarted. Continued failures might indicate a problem with the authorization plug-in.

Event ID 1001: The Remote Desktop Gateway service cannot determine the version of Windows that this computer is running.

#
Channel
Admin

Message #

The Remote Desktop Gateway service cannot determine the version of Windows that this computer is running. Therefore, users cannot connect to this RD Gateway server. To resolve this issue, please contact Microsoft Product Support Services. The following error occurred: "%2".

Event ID 1002: The user authentication plug-in "%1" has been configured.

#
Channel
Admin

Description

The user authentication plug-in "%1" has been configured. The configuration will take effect after the RD Gateway service is restarted.

Message #

The user authentication plug-in "%1" has been configured. The configuration will take effect after the RD Gateway service is restarted.

Event ID 1003: RD Gateway native authentication is configured.

#
Channel
Admin

Description

RD Gateway native authentication is configured. The configuration changes will take effect after the RD Gateway service is restarted.

Message #

RD Gateway native authentication is configured. The configuration changes will take effect after the RD Gateway service is restarted.

Event ID 1004: The user authorization plug-in "%1" is enabled.

#
Channel
Admin

Description

The user authorization plug-in "%1" is enabled. No user action is required.

Message #

The user authorization plug-in "%1" is enabled. No user action is required.

Event ID 1005: The RD Gateway native authorization is enabled.

#
Channel
Admin

Description

The RD Gateway native authorization is enabled. No user action is required.

Message #

The RD Gateway native authorization is enabled. No user action is required.

Event ID 2001: The policy and server configuration settings for the RD Gateway server "%1" have been successfully imported.

#
Channel
Admin

Event ID 2002: The policy and server configuration settings for the RD Gateway server "%1" could not be imported.

#
Channel
Admin

Description

The policy and server configuration settings for the RD Gateway server "%1" could not be imported. This problem might occur if the settings have become corrupted.

Message #

The policy and server configuration settings for the RD Gateway server "%1" could not be imported. This problem might occur if the settings have become corrupted.

Event ID 2003: The policy and server configuration settings for the RD Gateway server "%1" have been successfully exported.

#
Channel
Admin

Event ID 2004: The policy and server configuration settings for the RD Gateway server "%1" could not be exported.

#
Channel
Admin

Description

The policy and server configuration settings for the RD Gateway server "%1" could not be exported. The following error occurred: "%2".

Message #

The policy and server configuration settings for the RD Gateway server "%1" could not be exported. The following error occurred: "%2".

Event ID 3000: The RD Gateway server certificate was changed.

#
Channel
Admin

Description

The RD Gateway server certificate was changed. No user action is required.

Message #

The RD Gateway server certificate was changed. No user action is required.

Event ID 3001: The RD Gateway server certificate cannot be changed.

#
Channel
Admin

Description

The RD Gateway server certificate cannot be changed. The following error occurred: "%2". Verify the certificate and try changing the certificate again.

Message #

The RD Gateway server certificate cannot be changed. The following error occurred: "%2". Verify the certificate and try changing the certificate again.

Event ID 4001: The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured.

#
Channel
Admin

Message #

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured (non-default) HTTPS port of the Remote Desktop Gateway has been modified.

Event ID 4002: The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured.

#
Channel
Admin

Message #

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured (non-default) HTTPS port of Remote Desktop Gateway could not be modified.

Event ID 4003: The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP po...

#
Channel
Admin

Description

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP port of the Remote Desktop Gateway has been modified.

Message #

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP port of the Remote Desktop Gateway has been modified.

Event ID 4004: The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP po...

#
Channel
Admin

Description

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP port of Remote Desktop Gateway could not be modified.

Message #

The Windows Firewall exception to allow network traffic comprising of Remote Desktop Services client connections data through the configured UDP port of Remote Desktop Gateway could not be modified.