Microsoft-Windows-TerminalServices-RemoteConnectionManager

195 events across 5 channels

EventTitleChannelSample
2message.DebugN
3message.DebugN
4message.DebugN
5message.DebugN
6message.DebugN
7message.DebugN
8message.DebugN
9message.DebugN
256Remote Desktop Services Remote Connection Manager is starting upAnalyticN
257Remote Desktop Services Remote Connection Manager has finished start up.AnalyticN
258Listener http://schemas.OperationalY
259Listener listenerName has stopped listening.OperationalN
260Listener listenerName failed while listening.AnalyticN
261Listener http://schemas.OperationalY
262Listener listenerName has been asked to stop listening.OperationalN
263WDDM graphics mode is enabledOperationalY
272Connection with ID Param1 has started.AnalyticN
273Connection with ID Param1 for session Param2 has completed, total time Param3 …AnalyticN
274Reconnect connection ID Param1 to session Param2 took Param3 (ms).AnalyticN
1003The remote desktop client 'Param1' has provided an invalid license.OperationalN
1004The Remote Desktop Session Host server cannot issue a client license.OperationalN
1006The RD Session Host server received large number of incomplete connections.AdminN
1011The remote session could not be established from remote desktop client Param1 …OperationalN
1012Remote session from client name %1 exceeded the maximum allowed failed logon …OperationalN
1022TermService clustering failed to redirect a client to an alternate clustered …OperationalN
1024TermService clustering failed to initialize because the Session Directory …OperationalN
1035RD Session Host Server listener stack was downOperationalN
1036RD Session Host Server session creation failedOperationalN
1041Autoreconnect failed to reconnect user to session because authentication failedOperationalN
1046Failed to load RD Session Host Server Profile pathOperationalN
1050The RD Session Host Server listener %1 is configured with inconsistent …OperationalN
1051The RD Session Host Server is configured to use SSL with user selected …OperationalN
1052The RD Session Host Server is configured to use a certificate that will expire …OperationalN
1053The RD Session Host Server is configured to use a certificate that is expiredOperationalN
1054The RD Session Host Server is configured to use a certificate that does not …OperationalN
1055The RD Session Host Server is configured to use a certificate but is unable to …OperationalN
1056A new self signed certificate to be used for RD Session Host Server …OperationalY
1056A new self signed certificate to be used for RD Session Host Server …SystemY
1057The RD Session Host Server has failed to create a new self signed certificate to …OperationalN
1058The RD Session Host Server has failed to replace the expired self signed …OperationalN
1059The RD Session Host Server authentication certificate configuration data was …OperationalN
1060The Remote Desktop Services User Home Directory was not set because the path …OperationalN
1062The RD Session Host server is configured to use a template-based certificate for …OperationalN
1063A new template-based certificate to be used by the RD Session Host server for …OperationalN
1064The RD Session Host server cannot install a new template-based certificate to be …OperationalN
1065The template-based certificate that is being used by the RD Session Host server …OperationalN
1066RD Session Host Server was unable to process session arbitration requestOperationalN
1067The RD Session Host server cannot register 'TERMSRV' Service Principal Name to …OperationalN
1068The RD Licensing mode has not been configured.AdminN
1069The RD Licensing grace period has expired and Licensing mode for the Remote …AdminN
1070A logon request was denied because the RD Session Host server is currently in …OperationalN
1071A connection request was denied because the RD Session Host server is currently …OperationalN
1072The cn column for the template-based certificate %1 returned an unknown data …OperationalN
1073The msPKI-Cert-Template-OID column for the template-based certificate %1 …OperationalN
1136RD Session Host Server role is not installed.OperationalY
1137The roaming user profile cache manager for Remote Desktop Services could not …OperationalN
1138The roaming user profile cache manager for Remote Desktop Services could not …AdminN
1139The roaming user profile cache manager for Remote Desktop Services could not …AdminN
1140The "Limit the size of the entire roaming user profile cache" Group Policy …OperationalN
1141The "Limit the size of the entire roaming user profile cache" Group Policy …OperationalN
1142The "Limit the size of the entire roaming user profile cache" Group Policy …OperationalN
1143The "Limit the size of the entire roaming user profile cache" Group Policy …OperationalY
1144The roaming user profile cache manager for Remote Desktop Services could not …AdminN
1145The roaming user profile cache manager for Remote Desktop Services deleted the …OperationalN
1146Remote Desktop Services: Remote control session initiated.OperationalN
1147Remote Desktop Services: Remote control session connection succeeded.OperationalN
1148Remote Desktop Services: Remote control session connection failed.OperationalN
1149Remote Desktop Services: User authentication succeeded.OperationalY
1150Remote Desktop Services: User config data have been merged.AnalyticN
1151The remote user's connection was declined by the logged on user.OperationalN
1152Failed to create KVP sessions string.OperationalN
1153Failed to write KVP sessions string.OperationalN
1154Failed to open KVP registry key.OperationalN
1155The Remote Connection Manager selected Kernel mode RDP protocol stack.OperationalY
1156The Remote Connection Manager selected User mode RDP protocol stack.OperationalN
1157The listener named listenerName has modified some configuration settings.AdminN
1158Remote Desktop Services accepted a connection from IP address EventXML.Param1.AdminY
1280Remote Desktop Configuration service could not remove user Param1\Param2 from …AdminN
1281Remote Desktop Configuration service could not remove user Param1\Param2 from …AdminN
1282Remote Desktop Configuration service could not remove user with SID Param1 from …AdminN
1283Remote Desktop Configuration service could not remove user with SID Param1 from …AdminN
1284Remote Desktop Configuration service has added user Param1\Param2 to …AdminN
1285Remote Desktop Configuration service has added user Param1\Param2 to Remote …AdminN
1286Remote Desktop Configuration service has removed user with SID Param1 from …AdminN
1287Remote Desktop Configuration service has removed user with SID Param1 from …AdminN
1288Remote Desktop Configuration service has removed user Param1\Param2 from …AdminN
1289Remote Desktop Configuration service has removed user Param1\Param2 from Remote …AdminN
2304SessionArbitrationStartAnalyticN
2305SessionArbitrationStopAnalyticN
2306NotifyLogonToLicensingStartAnalyticN
2307NotifyLogonToLicensingStopAnalyticN
20480Remote Desktop Services Network Fair Share started.AdminN
20481Remote Desktop Services Network Fair Share stopped.AdminN
20482Remote Desktop Services Network Fair Share was enabled for the user account …AdminN
20483Remote Desktop Service Network Fairshare has been enabled for connection on …AdminN
20484Remote Desktop Services could not enable Network Fair Share for the user account …AdminN
20485Remote Desktop Services could not enable Network Fair Share for the connection …AdminN
20486Remote Desktop Services could not enable Network Fair Share for session Param1.AdminN
20487Remote Desktop Services Network Fair Share was disabled for the user account …AdminN
20488Remote Desktop Services Network Fair Share was disabled for the connection on …AdminN
20489Remote Desktop Services could not disable Network Fair Share for the user …AdminN
20490Remote Desktop Services could not disable Network Fair Share for the connection …AdminN
20491Remote Desktop Services could not disconnect a user disk for the user account …AdminN
20492Remote Desktop Services could not detach a user disk for the user account with a …AdminN
20493Remote Desktop Services could not apply a user desktop for a user account with a …AdminN
20494Remote Desktop Services could not obtain a user profile disk for the user …AdminN
20495Remote Desktop Services could not attach a user profile disk for a user account …AdminN
20496Remote Desktop Services could not apply a user desktop for a user account with a …AdminN
20497The RD Licensing has taken too long to process the client licenseAdminN
20498Remote Desktop Services has taken too long to complete the client connectionAdminN
20499Remote Desktop Services has taken too long to load the user configuration from …AdminN
20500Remote Desktop Services took time milliseconds to load the user configuration …AdminN
20501Remote Desktop Services failed to shutdown within the time allocatedAdminY
20502Remote Desktop Services failed to retrieve information about a connection for …AdminN
20503Shadow View Session Started.OperationalN
20504Shadow View Session Stopped.OperationalN
20506Shadow Control Session Started.OperationalN
20507Shadow Control Session Stopped.OperationalN
20508Shadow View Permission Granted.OperationalN
20509Shadow View Permission Denied.OperationalN
20510Shadow Control Permission Granted.OperationalN
20511Shadow Control Permission Denied.OperationalN
20512Shadow Session Failure.OperationalN
20513Shadow Session Failure.OperationalN
20514Shadow Session Failure.OperationalN
20515Session Session has been idle over its time limit, and was logged off.AdminN
20516Session Session has been idle over its time limit, and was disconnected.AdminN
20517Session Session has exceeded its time limit, and was logged off.AdminN
20518Session Session has exceeded its time limit, and was disconnected.AdminN
20519Session Session has exceeded its disconnect time limit, and was logged off.AdminN
20520User config info will be loaded from domain controller for this Param1 …AdminN
20521User config info will be loaded from local machine for this EventXML.Param1 …AdminY
20522Shadow Session Clipboard Copy Request.OperationalN
20523Connection from listener EventXML.ListenerName will have terminal class of …OperationalY
20524Supplemental Kerberos credentials are not configuredOperationalY
20525Successfully updated supplemental Kerberos credential Param1 in Param2 logon …OperationalN
20526Successfully removed supplemental Kerberos credential Param1 from Param2 logon …OperationalN
20527Failed to update supplemental Kerberos credentials.OperationalN
20528Failed to update supplemental Kerberos credential Param1 in Param2 logon …OperationalN
20529Failed to remove supplemental Kerberos credential Param1 from Param2 logon …OperationalN
20530Supplemental Kerberos credential Param1 configuration is invalid.OperationalN
20531Remote Desktop Service's Threadpool is in terminated state.OperationalN
24576Remote Desktop Configuration service could not remove user {Param1}\{Param2} …AdminN
24577Remote Desktop Configuration service could not remove user with SID {Param1} …AdminN
24578Remote Desktop Configuration service has added user {Param1}\{Param2} to …AdminN
50180The remote session could not be established from remote desktop client Param1 …OperationalN
50195The Remote Desktop Session Host server cannot communicate with the Remote …AdminN
50213Remote Desktop Session Host server was unable to retrieve users licensing …AdminN
50214Remote Desktop Session Host server was successfully validated errorCode …AdminN
50215Remote Desktop Session Host server was unable to retrieve user licensing …AdminN
50216Remote Desktop Session Host server was unable to validate RDS license.AdminN
50280The RD Licensing grace period has expired and the service has not registered …AdminN
50281The RD Licensing grace period is about to expire on Param1 and the service has …AdminN
50282The Remote Desktop Session Host server does not have a Remote Desktop license …AdminN
50283The Remote Desktop Session Host server could not contact the Remote Desktop …AdminN
50284The Remote Desktop license server Param1 does not support the version of the …AdminN
50285The certificate issued by the Remote Desktop license server to the Remote …AdminN
50304The Remote Desktop Virtualization Host server cannot issue a client license.OperationalN
50305The RD Licensing grace period has expired and Licensing mode for the Remote …AdminN
50306The RD Licensing grace period has expired and the service has not registered …AdminN
50307The RD Licensing grace period is about to expire on Param1 and the service has …AdminN
50308The Remote Desktop Virtualization Host server does not have a Remote Desktop …AdminN
50309The Remote Desktop Virtualization Host server could not contact the Remote …AdminN
50310The Remote Desktop license server Param1 does not support the version of the …AdminN
50311The certificate issued by the Remote Desktop license server to the Remote …AdminN
50312The Remote Desktop Virtualization Host server cannot communicate with the Remote …AdminN
1073742836Remote session from client name %1 exceeded the maximum allowed failed logon …OperationalN
3221226494TermService clustering failed to redirect a client to an alternate clustered …OperationalN
3221226496TermService clustering failed to initialize because the Session Directory …OperationalN
3221226507RD Session Host Server listener stack was down.OperationalN
3221226508RD Session Host Server session creation failed.OperationalN
3221226513Autoreconnect failed to reconnect user to session because authentication failed.OperationalN
3221226518Failed to load RD Session Host Server Profile path.OperationalN
3221226522The RD Session Host Server listener %1 is configured with inconsistent …OperationalN
3221226523The RD Session Host Server is configured to use SSL with user selected …OperationalN
3221226524The RD Session Host Server is configured to use a certificate that will expire …OperationalN
3221226525The RD Session Host Server is configured to use a certificate that is expired.OperationalN
3221226526The RD Session Host Server is configured to use a certificate that does not …OperationalN
3221226527The RD Session Host Server is configured to use a certificate but is unable to …OperationalN
3221226528A new self signed certificate to be used for RD Session Host Server …OperationalY
3221226529The RD Session Host Server has failed to create a new self signed certificate to …OperationalN
3221226530The RD Session Host Server has failed to replace the expired self signed …OperationalN
3221226531The RD Session Host Server authentication certificate configuration data was …OperationalN
3221226532The Remote Desktop Services User Home Directory was not set because the path …OperationalN
3221226533Remote Desktop Session Host server was unable to retrieve users Licensing …OperationalN
3221226534The RD Session Host server is configured to use a template-based certificate for …OperationalN
3221226535A new template-based certificate to be used by the RD Session Host server for …OperationalN
3221226536The RD Session Host server cannot install a new template-based certificate to be …OperationalN
3221226537The template-based certificate that is being used by the RD Session Host server …OperationalN
3221226538RD Session Host Server was unable to process session arbitration request.OperationalN
3221226539The RD Session Host server cannot register 'TERMSRV' Service Principal Name to …OperationalN
3221226542A logon request was denied because the RD Session Host server is currently in …OperationalN
3221226543A connection request was denied because the RD Session Host server is currently …OperationalN
3221226544The cn column for the template-based certificate %1 returned an unknown data …OperationalN
3221226545The msPKI-Cert-Template-OID column for the template-based certificate %1 …OperationalN

Event ID 2: message.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 3: message.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 4: message.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 5: message.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 6: message.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 7: message.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 8: message.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 9: message.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 256: Remote Desktop Services Remote Connection Manager is starting up

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic
Task
RCMStartStop
Opcode
Start

Description

Remote Desktop Services Remote Connection Manager is starting up.

Message #

Remote Desktop Services Remote Connection Manager is starting up

Event ID 257: Remote Desktop Services Remote Connection Manager has finished start up.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic
Opcode
Stop

Description

Remote Desktop Services Remote Connection Manager has finished start up. Return code isSuccess.

Message #

Remote Desktop Services Remote Connection Manager has finished start up. Return code %1

Fields #

NameDescription
isSuccess Boolean

Event ID 258: Listener http://schemas.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
Informational

Description

Listener has started listening.

Message #

Listener %1 has started listening

Fields #

NameDescription
EventXML.listenerName
listenerName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "{C76BAA63-AE81-421C-B425-340B4B24157F}",
    "event_source_name": "",
    "event_id": 258,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-05-29T16:32:54.1040012+00:00",
    "event_record_id": 173,
    "correlation": {
      "ActivityID": "{F462A52A-5DAA-46E2-960E-FB3B92800000}"
    },
    "execution": {
      "process_id": 1300,
      "thread_id": 1600
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventXML": {
      "listenerName": "31C5CE94259D4006A9E4"
    }
  },
  "message": "Listener 31C5CE94259D4006A9E4 has started listening"
}

Event ID 259: Listener listenerName has stopped listening.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Listener listenerName has stopped listening.

Message #

Listener %1 has stopped listening

Fields #

NameDescription
listenerName UnicodeString

Event ID 260: Listener listenerName failed while listening.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic

Description

Listener listenerName failed while listening. Error code errorCode.

Message #

Listener %1 failed while listening. Error code %2

Fields #

NameDescription
listenerName UnicodeString
errorCode Pointer

Event ID 261: Listener http://schemas.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
Informational

Description

Listener received a connection.

Message #

Listener %1 received a connection

Fields #

NameDescription
listenerName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "C76BAA63-AE81-421C-B425-340B4B24157F",
    "event_source_name": "",
    "event_id": 261,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2019-02-13T18:04:45.905782+00:00",
    "event_record_id": 227,
    "correlation": {},
    "execution": {
      "process_id": 1280,
      "thread_id": 1876
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational",
    "computer": "PC01.example.corp",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventXML": {
      "xmlns:auto-ns2": "http://schemas.microsoft.com/win/2004/08/events",
      "listenerName": "RDP-Tcp"
    }
  },
  "message": "Listener http://schemas.microsoft.com/win/2004/08/events received a connection"
}

References #

Event ID 262: Listener listenerName has been asked to stop listening.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Listener listenerName has been asked to stop listening.

Message #

Listener %1 has been asked to stop listening

Fields #

NameDescription
listenerName UnicodeString

Event ID 263: WDDM graphics mode is enabled

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
Informational

Description

WDDM graphics mode is enabled.

Message #

WDDM graphics mode is enabled

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "C76BAA63-AE81-421C-B425-340B4B24157F",
    "event_source_name": "",
    "event_id": 263,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-11T06:27:38.404213+00:00",
    "event_record_id": 253,
    "correlation": {
      "ActivityID": "F4626F1C-FB1F-4005-81D8-895393540000"
    },
    "execution": {
      "process_id": 1536,
      "thread_id": 2316
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 272: Connection with ID Param1 has started.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic
Task
ConnectionTime
Opcode
Start

Description

Connection with ID Param1 has started.

Message #

Connection with ID %1 has started

Fields #

NameDescription
Param1 UnicodeString

Event ID 273: Connection with ID Param1 for session Param2 has completed, total time Param3 (ms), stack time Param4 (ms).

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic
Task
ConnectionTime
Opcode
Stop

Description

Connection with ID Param1 for session Param2 has completed, total time Param3 (ms), stack time Param4 (ms).

Message #

Connection with ID %1 for session %2 has completed, total time %3 (ms), stack time %4 (ms)

Fields #

NameDescription
Param1 UnicodeString
Param2 Int32
Param3 Int64
Param4 Int64

Event ID 274: Reconnect connection ID Param1 to session Param2 took Param3 (ms).

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic
Task
ConnectionTime
Opcode
Stop

Description

Reconnect connection ID Param1 to session Param2 took Param3 (ms).

Message #

Reconnect connection ID %1 to session %2 took %3 (ms)

Fields #

NameDescription
Param1 UnicodeString
Param2 Int32
Param3 Int64

Event ID 1003: The remote desktop client 'Param1' has provided an invalid license.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The remote desktop client 'Param1' has provided an invalid license.

Message #

The remote desktop client '%1' has provided an invalid license.

Fields #

NameDescription
Param1 UnicodeString

Event ID 1004: The Remote Desktop Session Host server cannot issue a client license.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The Remote Desktop Session Host server cannot issue a client license. It was unable to issue the license due to a changed (mismatched) client license, insufficient memory, or an internal error. Further details for this problem may have been reported at the client's computer.

Message #

The Remote Desktop Session Host server cannot issue a client license.  It was unable to issue the license due to a changed (mismatched) client license, insufficient memory, or an internal error. Further details for this problem may have been reported at the client's computer.

Event ID 1006: The RD Session Host server received large number of incomplete connections.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The RD Session Host server received large number of incomplete connections. The system may be under attack.

Message #

The RD Session Host server received large number of incomplete connections.  The system may be under attack.

Event ID 1011: The remote session could not be established from remote desktop client Param1 because its temporary license has expired.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The remote session could not be established from remote desktop client Param1 because its temporary license has expired.

Message #

The remote session could not be established from remote desktop client %1 because its temporary license has expired.

Fields #

NameDescription
Param1 UnicodeString

Event ID 1012: Remote session from client name %1 exceeded the maximum allowed failed logon attempts

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1022: TermService clustering failed to redirect a client to an alternate clustered server, ntstatus=

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1024: TermService clustering failed to initialize because the Session Directory Provider failed to initialize, hresult=

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1035: RD Session Host Server listener stack was down

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1036: RD Session Host Server session creation failed

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1041: Autoreconnect failed to reconnect user to session because authentication failed

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1046: Failed to load RD Session Host Server Profile path

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1050: The RD Session Host Server listener %1 is configured with inconsistent authentication and encryption settings

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1051: The RD Session Host Server is configured to use SSL with user selected certificate, however, no usable certificate was found on the server

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1052: The RD Session Host Server is configured to use a certificate that will expire in %2 days

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1053: The RD Session Host Server is configured to use a certificate that is expired

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1054: The RD Session Host Server is configured to use a certificate that does not contain an Enhanced Key Usage attribute of Server Authentication

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1055: The RD Session Host Server is configured to use a certificate but is unable to access the private key associated with this certificate

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1056: A new self signed certificate to be used for RD Session Host Server authentication on SSL connections was generated

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "event_id": 1056,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:29.6241537+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "Binary": "711E31623D227BA329E804181302537F5A6E304A",
    "Data": "DESKTOP-FF3N5XK.ludus.domain"
  }
}

Event ID 1056: A new self signed certificate to be used for RD Session Host Server authentication on SSL connections was generated

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
System
Level
Informational

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "{C76BAA63-AE81-421C-B425-340B4B24157F}",
    "event_source_name": "",
    "event_id": 1056,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-27T21:58:51.5401996+00:00",
    "event_record_id": 1213,
    "correlation": {},
    "execution": {
      "process_id": 2568,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "telemetry-W11-d.cell-d.ludus.domain"
  },
  "message": "A new self signed certificate to be used for RD Session Host Server authentication on SSL connections was generated. The name on this certificate is telemetry-W11-d.cell-d.ludus.domain. The SHA1 hash of the certificate is in the event data."
}

Event ID 1057: The RD Session Host Server has failed to create a new self signed certificate to be used for RD Session Host Server authentication on SSL connections

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1058: The RD Session Host Server has failed to replace the expired self signed certificate used for RD Session Host Server authentication on SSL connections

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1059: The RD Session Host Server authentication certificate configuration data was invalid and the service reset it

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1060: The Remote Desktop Services User Home Directory was not set because the path specified does not exist or not accessible

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1062: The RD Session Host server is configured to use a template-based certificate for Transport Layer Security (TLS) 1

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1063: A new template-based certificate to be used by the RD Session Host server for Transport Layer Security (TLS) 1

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1064: The RD Session Host server cannot install a new template-based certificate to be used for Transport Layer Security (TLS) 1

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1065: The template-based certificate that is being used by the RD Session Host server for Transport Layer Security (TLS) 1

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1066: RD Session Host Server was unable to process session arbitration request

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1067: The RD Session Host server cannot register 'TERMSRV' Service Principal Name to be used for server authentication

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1068: The RD Licensing mode has not been configured.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The RD Licensing mode has not been configured.

Message #

The RD Licensing mode has not been configured.

Event ID 1069: The RD Licensing grace period has expired and Licensing mode for the Remote Desktop Session Host server has not been configured.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The RD Licensing grace period has expired and Licensing mode for the Remote Desktop Session Host server has not been configured. Licensing mode must be configured for continuous operation.

Message #

The RD Licensing grace period has expired and Licensing mode for the Remote Desktop Session Host server has not been configured. Licensing mode must be configured for continuous operation.

Event ID 1070: A logon request was denied because the RD Session Host server is currently in drain mode and therefore not accepting new user logons

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1071: A connection request was denied because the RD Session Host server is currently configured to not accept connections

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1072: The cn column for the template-based certificate %1 returned an unknown data type

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1073: The msPKI-Cert-Template-OID column for the template-based certificate %1 returned an unknown data type

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Event ID 1136: RD Session Host Server role is not installed.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
Informational

Description

RD Session Host Server role is not installed.

Message #

RD Session Host Server role is not installed.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "{C76BAA63-AE81-421C-B425-340B4B24157F}",
    "event_source_name": "",
    "event_id": 1136,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-05-29T16:32:57.4737762+00:00",
    "event_record_id": 178,
    "correlation": {},
    "execution": {
      "process_id": 2492,
      "thread_id": 3020
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "RD Session Host Server role is not installed."
}

Event ID 1137: The roaming user profile cache manager for Remote Desktop Services could not start.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The roaming user profile cache manager for Remote Desktop Services could not start. Error Code: Param1.

Message #

The roaming user profile cache manager for Remote Desktop Services could not start. Error Code: %1

Fields #

NameDescription
Param1 UInt32

Event ID 1138: The roaming user profile cache manager for Remote Desktop Services could not start because an incorrect value was specified for the monitoring inte...

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The roaming user profile cache manager for Remote Desktop Services could not start because an incorrect value was specified for the monitoring interval. Error Code: Param1.

Message #

The roaming user profile cache manager for Remote Desktop Services could not start because an incorrect value was specified for the monitoring interval. Error Code: %1

Fields #

NameDescription
Param1 UInt32

Event ID 1139: The roaming user profile cache manager for Remote Desktop Services could not start because an incorrect value was specified for the maximum cache s...

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The roaming user profile cache manager for Remote Desktop Services could not start because an incorrect value was specified for the maximum cache size. Error Code: Param1.

Message #

The roaming user profile cache manager for Remote Desktop Services could not start because an incorrect value was specified for the maximum cache size. Error Code: %1

Fields #

NameDescription
Param1 UInt32

Event ID 1140: The "Limit the size of the entire roaming user profile cache" Group Policy setting has been enabled, but the roaming user profile cache manager for...

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The "Limit the size of the entire roaming user profile cache" Group Policy setting has been enabled, but the roaming user profile cache manager for Remote Desktop Services has encountered a problem. Error Code: Param1

Message #

The "Limit the size of the entire roaming user profile cache" Group Policy setting has been enabled, but the roaming user profile cache manager for Remote Desktop Services has encountered a problem. Error Code: %1

Fields #

NameDescription
Param1 UInt32

Event ID 1141: The "Limit the size of the entire roaming user profile cache" Group Policy setting has been disabled, but the roaming user profile cache manager fo...

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The "Limit the size of the entire roaming user profile cache" Group Policy setting has been disabled, but the roaming user profile cache manager for Remote Desktop Services has encountered a problem. Error Code: Param1

Message #

The "Limit the size of the entire roaming user profile cache" Group Policy setting has been disabled, but the roaming user profile cache manager for Remote Desktop Services has encountered a problem. Error Code: %1

Fields #

NameDescription
Param1 UInt32

Event ID 1142: The "Limit the size of the entire roaming user profile cache" Group Policy setting has been enabled.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The "Limit the size of the entire roaming user profile cache" Group Policy setting has been enabled.

Message #

The "Limit the size of the entire roaming user profile cache" Group Policy setting has been enabled.

Event ID 1143: The "Limit the size of the entire roaming user profile cache" Group Policy setting has been disabled.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
Informational

Description

The "Limit the size of the entire roaming user profile cache" Group Policy setting has been disabled.

Message #

The "Limit the size of the entire roaming user profile cache" Group Policy setting has been disabled.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "C76BAA63-AE81-421C-B425-340B4B24157F",
    "event_source_name": "",
    "event_id": 1143,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-13T18:27:00.338529+00:00",
    "event_record_id": 177,
    "correlation": {},
    "execution": {
      "process_id": 2248,
      "thread_id": 10044
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1144: The roaming user profile cache manager for Remote Desktop Services could not delete the roaming user profile for the user Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The roaming user profile cache manager for Remote Desktop Services could not delete the roaming user profile for the user Param1. The roaming user profile cache might still exceed the Param2 gigabyte limit. Error Code: Param3

Message #

The roaming user profile cache manager for Remote Desktop Services could not delete the roaming user profile for the user %1. The roaming user profile cache might still exceed the %2 gigabyte limit. Error Code: %3

Fields #

NameDescription
Param1 UnicodeString
Param2 UInt32
Param3 UInt32

Event ID 1145: The roaming user profile cache manager for Remote Desktop Services deleted the roaming user profile for the user Param1 because the roaming user profil...

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The roaming user profile cache manager for Remote Desktop Services deleted the roaming user profile for the user Param1 because the roaming user profile cache exceeded the Param2 gigabyte limit.

Message #

The roaming user profile cache manager for Remote Desktop Services deleted the roaming user profile for the user %1 because the roaming user profile cache exceeded the %2 gigabyte limit.

Fields #

NameDescription
Param1 UnicodeString
Param2 UInt32

Event ID 1146: Remote Desktop Services: Remote control session initiated.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Remote Desktop Services: Remote control session initiated.

Message #

Remote Desktop Services: Remote control session initiated:

%1 initiated a remote control session:
User: %2
Domain: %3

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString

Event ID 1147: Remote Desktop Services: Remote control session connection succeeded.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Remote Desktop Services: Remote control session connection succeeded.

Message #

Remote Desktop Services: Remote control session connection succeeded:

%1 initiated a remote control session:
User: %2
Domain: %3

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString

Event ID 1148: Remote Desktop Services: Remote control session connection failed.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Remote Desktop Services: Remote control session connection failed.

Message #

Remote Desktop Services: Remote control session connection failed:

%1 initiated a remote control session:
User: %2
Domain: %3

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString

Event ID 1149: Remote Desktop Services: User authentication succeeded.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
Informational

Description

Remote Desktop Services: User authentication succeeded.

Message #

Remote Desktop Services: User authentication succeeded:

User: %1
Domain: %2
Source Network Address: %3

Fields #

NameDescription
Param1
Param2
Param3

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "C76BAA63-AE81-421C-B425-340B4B24157F",
    "event_source_name": "",
    "event_id": 1149,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2019-02-13T18:04:57.452387+00:00",
    "event_record_id": 228,
    "correlation": {},
    "execution": {
      "process_id": 1280,
      "thread_id": 2748
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational",
    "computer": "PC01.example.corp",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventXML": {
      "xmlns:auto-ns2": "http://schemas.microsoft.com/win/2004/08/events",
      "Param1": "admin01",
      "Param2": "example",
      "Param3": "127.0.0.1"
    }
  },
  "message": "Remote Desktop Services: User authentication succeeded:\n\nUser: http://schemas.microsoft.com/win/2004/08/events\nDomain: admin01\nSource Network Address: example"
}

Detection Patterns #

Community Notes #

RDP user auth succeeded, combine with 4624 (successful logon)/4625 (logoff) to track lateral movement.

Detection Rules #

View all rules referencing this event →

Splunk # view in coverage

  • Windows RDP Connection Successful source: The following analytic detects successful Remote Desktop Protocol (RDP) connections by monitoring EventCode 1149 from the Windows TerminalServices RemoteConnectionManager Operational log. This detection is significant as successful RDP…

References #

Event ID 1150: Remote Desktop Services: User config data have been merged.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic

Description

Remote Desktop Services: User config data have been merged.

Message #

Remote Desktop Services: User config data have been merged:

User: %1
Domain: %2
Source Network Address: %3

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString

Event ID 1151: The remote user's connection was declined by the logged on user.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The remote user's connection was declined by the logged on user.

Message #

The remote user's connection was declined by the logged on user.

User Account: %2
Domain: %1
Source IP Address: %3

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString

Event ID 1152: Failed to create KVP sessions string.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Failed to create KVP sessions string. Error Code Param1.

Message #

Failed to create KVP sessions string. Error Code %1

Fields #

NameDescription
Param1 UInt32

Event ID 1153: Failed to write KVP sessions string.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Failed to write KVP sessions string. Error Code Param1.

Message #

Failed to write KVP sessions string. Error Code %1

Fields #

NameDescription
Param1 UInt32

Event ID 1154: Failed to open KVP registry key.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Failed to open KVP registry key. Error Code {Param1}.

Message #

Failed to open KVP registry key. Error Code {Param1}

Fields #

NameDescription
Param1

Event ID 1155: The Remote Connection Manager selected Kernel mode RDP protocol stack.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
Informational

Description

The Remote Connection Manager selected Kernel mode RDP protocol stack.

Message #

The Remote Connection Manager selected Kernel mode RDP protocol stack.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "C76BAA63-AE81-421C-B425-340B4B24157F",
    "event_source_name": "",
    "event_id": 1155,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2019-02-13T17:18:28.040385+00:00",
    "event_record_id": 220,
    "correlation": {
      "ActivityID": "8F0C0C22-A5AA-4F83-B10F-0880AB96471F"
    },
    "execution": {
      "process_id": 1280,
      "thread_id": 1548
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational",
    "computer": "PC01.example.corp",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The Remote Connection Manager selected Kernel mode RDP protocol stack."
}

References #

Event ID 1156: The Remote Connection Manager selected User mode RDP protocol stack.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The Remote Connection Manager selected User mode RDP protocol stack.

Message #

The Remote Connection Manager selected User mode RDP protocol stack.

Event ID 1157: The listener named listenerName has modified some configuration settings.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The listener named listenerName has modified some configuration settings.

Message #

The listener named %1 has modified some configuration settings.

Fields #

NameDescription
listenerName UnicodeString

Event ID 1158: Remote Desktop Services accepted a connection from IP address EventXML.Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin
Level
Informational

Description

Remote Desktop Services accepted a connection from IP address EventXML.Param1.

Message #

Remote Desktop Services accepted a connection from IP address %1.

Fields #

NameDescription
Param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "C76BAA63-AE81-421C-B425-340B4B24157F",
    "event_source_name": "",
    "event_id": 1158,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-13T16:46:57.106454+00:00",
    "event_record_id": 4,
    "correlation": {
      "ActivityID": "F420602A-491C-41CA-97CE-1A07AEAA0000"
    },
    "execution": {
      "process_id": 1472,
      "thread_id": 4588
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Admin",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventXML": {
      "Param1": "198.51.100.2"
    }
  },
  "message": ""
}

Event ID 1280: Remote Desktop Configuration service could not remove user Param1\Param2 from administrators group, error Code: Param3.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service could not remove user Param1\Param2 from administrators group, error Code: Param3.

Message #

Remote Desktop Configuration service could not remove user %1\%2 from administrators group, error Code: %3

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 Int32

Event ID 1281: Remote Desktop Configuration service could not remove user Param1\Param2 from Remote Desktop Users group, error Code: Param3.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service could not remove user Param1\Param2 from Remote Desktop Users group, error Code: Param3.

Message #

Remote Desktop Configuration service could not remove user %1\%2 from Remote Desktop Users group, error Code: %3

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 Int32

Event ID 1282: Remote Desktop Configuration service could not remove user with SID Param1 from administrators group, error Code: Param2.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service could not remove user with SID Param1 from administrators group, error Code: Param2.

Message #

Remote Desktop Configuration service could not remove user with SID %1 from administrators group, error Code: %2

Fields #

NameDescription
Param1 UnicodeString
Param2 UInt32

Event ID 1283: Remote Desktop Configuration service could not remove user with SID Param1 from Remote Desktop Users group, error Code: Param2.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service could not remove user with SID Param1 from Remote Desktop Users group, error Code: Param2.

Message #

Remote Desktop Configuration service could not remove user with SID %1 from Remote Desktop Users group, error Code: %2

Fields #

NameDescription
Param1 UnicodeString
Param2 UInt32

Event ID 1284: Remote Desktop Configuration service has added user Param1\Param2 to administrators group.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service has added user Param1\Param2 to administrators group.

Message #

Remote Desktop Configuration service has added user %1\%2 to administrators group

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString

Event ID 1285: Remote Desktop Configuration service has added user Param1\Param2 to Remote Desktop Users group.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service has added user Param1\Param2 to Remote Desktop Users group.

Message #

Remote Desktop Configuration service has added user %1\%2 to Remote Desktop Users group

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString

Event ID 1286: Remote Desktop Configuration service has removed user with SID Param1 from administrators group.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service has removed user with SID Param1 from administrators group.

Message #

Remote Desktop Configuration service has removed user with SID %1 from administrators group

Fields #

NameDescription
Param1 UnicodeString

Event ID 1287: Remote Desktop Configuration service has removed user with SID Param1 from Remote Desktop Users group.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service has removed user with SID Param1 from Remote Desktop Users group.

Message #

Remote Desktop Configuration service has removed user with SID %1 from Remote Desktop Users group

Fields #

NameDescription
Param1 UnicodeString

Event ID 1288: Remote Desktop Configuration service has removed user Param1\Param2 from administrators group.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service has removed user Param1\Param2 from administrators group.

Message #

Remote Desktop Configuration service has removed user %1\%2 from administrators group

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString

Event ID 1289: Remote Desktop Configuration service has removed user Param1\Param2 from Remote Desktop Users group.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service has removed user Param1\Param2 from Remote Desktop Users group.

Message #

Remote Desktop Configuration service has removed user %1\%2 from Remote Desktop Users group

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString

Event ID 2304: SessionArbitrationStart

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic
Task
SessionArbitration
Opcode
Start

Fields #

NameDescription
Param1 Int32

Event ID 2305: SessionArbitrationStop

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic
Task
SessionArbitration
Opcode
Stop

Fields #

NameDescription
Param1 Int32

Event ID 2306: NotifyLogonToLicensingStart

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic
Task
NotifyLogonToLicensing
Opcode
Start

Fields #

NameDescription
Param1 Int32
Param2 UnicodeString

Event ID 2307: NotifyLogonToLicensingStop

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Analytic
Task
NotifyLogonToLicensing
Opcode
Stop

Fields #

NameDescription
Param1 Int32
Param2 UnicodeString

Event ID 20480: Remote Desktop Services Network Fair Share started.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services Network Fair Share started.

Message #

Remote Desktop Services Network Fair Share started.

Event ID 20481: Remote Desktop Services Network Fair Share stopped.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services Network Fair Share stopped.

Message #

Remote Desktop Services Network Fair Share stopped.

Event ID 20482: Remote Desktop Services Network Fair Share was enabled for the user account Param1 with a weight of Param2.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services Network Fair Share was enabled for the user account Param1 with a weight of Param2.

Message #

Remote Desktop Services Network Fair Share was enabled for the user account %1 with a weight of %2.

Fields #

NameDescription
Param1 UnicodeString
Param2 Int32

Event ID 20483: Remote Desktop Service Network Fairshare has been enabled for connection on session Param1 with weight of Param2.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Service Network Fairshare has been enabled for connection on session Param1 with weight of Param2.

Message #

Remote Desktop Service Network Fairshare has been enabled for connection on session %1 with weight of %2.

Fields #

NameDescription
Param1 Int32
Param2 Int32

Event ID 20484: Remote Desktop Services could not enable Network Fair Share for the user account Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not enable Network Fair Share for the user account Param1. The error code is Param2.

Message #

Remote Desktop Services could not enable Network Fair Share for the user account %1. The error code is %2.

Fields #

NameDescription
Param1 UnicodeString
Param2 HexInt32

Event ID 20485: Remote Desktop Services could not enable Network Fair Share for the connection on session Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not enable Network Fair Share for the connection on session Param1. The error code is Param2.

Message #

Remote Desktop Services could not enable Network Fair Share for the connection on session %1. The error code is %2.

Fields #

NameDescription
Param1 Int32
Param2 HexInt32

Event ID 20486: Remote Desktop Services could not enable Network Fair Share for session Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not enable Network Fair Share for session Param1. The error code is Param2.

Message #

Remote Desktop Services could not enable Network Fair Share for session %1. The error code is %2.

Fields #

NameDescription
Param1 Int32
Param2 HexInt32

Event ID 20487: Remote Desktop Services Network Fair Share was disabled for the user account Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services Network Fair Share was disabled for the user account Param1.

Message #

Remote Desktop Services Network Fair Share was disabled for the user account %1.

Fields #

NameDescription
Param1 UnicodeString

Event ID 20488: Remote Desktop Services Network Fair Share was disabled for the connection on session Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services Network Fair Share was disabled for the connection on session Param1.

Message #

Remote Desktop Services Network Fair Share was disabled for the connection on session %1.

Fields #

NameDescription
Param1 Int32

Event ID 20489: Remote Desktop Services could not disable Network Fair Share for the user account Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not disable Network Fair Share for the user account Param1. The error code is Param2.

Message #

Remote Desktop Services could not disable Network Fair Share for the user account %1. The error code is %2.

Fields #

NameDescription
Param1 UnicodeString
Param2 HexInt32

Event ID 20490: Remote Desktop Services could not disable Network Fair Share for the connection on session Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not disable Network Fair Share for the connection on session Param1. The error code is Param2.

Message #

Remote Desktop Services could not disable Network Fair Share for the connection on session %1. The error code is %2.

Fields #

NameDescription
Param1 Int32
Param2 HexInt32

Event ID 20491: Remote Desktop Services could not disconnect a user disk for the user account with a SID of Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not disconnect a user disk for the user account with a SID of Param1. The error code is Param2.Param3.

Message #

Remote Desktop Services could not disconnect a user disk for the user account with a SID of %1. The error code is %2.%3

Fields #

NameDescription
Param1 UnicodeString
Param2 HexInt32
Param3 Int32

Event ID 20492: Remote Desktop Services could not detach a user disk for the user account with a SID of Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not detach a user disk for the user account with a SID of Param1. The error code is Param2.Param3.

Message #

Remote Desktop Services could not detach a user disk for the user account with a SID of %1. The error code is %2.%3

Fields #

NameDescription
Param1 UnicodeString
Param2 HexInt32
Param3 Int32

Event ID 20493: Remote Desktop Services could not apply a user desktop for a user account with a SID of Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not apply a user desktop for a user account with a SID of Param1. A temporary profile was enforced for the user. Verify that the user profile disk settings are correct. The error code is Param2.Param3

Message #

Remote Desktop Services could not apply a user desktop for a user account with a SID of %1. A temporary profile was enforced for the user. Verify that the user profile disk settings are correct. The error code is %2.%3

Fields #

NameDescription
Param1 UnicodeString
Param2 HexInt32
Param3 Int32

Event ID 20494: Remote Desktop Services could not obtain a user profile disk for the user account with a SID of Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not obtain a user profile disk for the user account with a SID of Param1. Verify that the user profile disk location is accessible, the server's computer account has read and write permissions to it, and that the location has a user profile disk template file present. The error code is Param2.Param3

Message #

Remote Desktop Services could not obtain a user profile disk for the user account with a SID of %1. Verify that the user profile disk location is accessible, the server's computer account has read and write permissions to it, and that the location has a user profile disk template file present. The error code is %2.%3

Fields #

NameDescription
Param1 UnicodeString
Param2 HexInt32
Param3 Int32

Event ID 20495: Remote Desktop Services could not attach a user profile disk for a user account with a SID of Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not attach a user profile disk for a user account with a SID of Param1. The error code is Param2.Param3.

Message #

Remote Desktop Services could not attach a user profile disk for a user account with a SID of %1. The error code is %2.%3

Fields #

NameDescription
Param1 UnicodeString
Param2 HexInt32
Param3 Int32

Event ID 20496: Remote Desktop Services could not apply a user desktop for a user account with a SID of Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services could not apply a user desktop for a user account with a SID of Param1. A temporary profile could not be enforced for the user. The user will get a normal profile, and the user's state will be discarded when the user logs off. Verify that the user profile disk settings are correct. The error code is Param2.Param3

Message #

Remote Desktop Services could not apply a user desktop for a user account with a SID of %1. A temporary profile could not be enforced for the user. The user will get a normal profile, and the user's state will be discarded when the user logs off. Verify that the user profile disk settings are correct. The error code is %2.%3

Fields #

NameDescription
Param1 UnicodeString
Param2 HexInt32
Param3 Int32

Event ID 20497: The RD Licensing has taken too long to process the client license

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The RD Licensing has taken too long to process the client license.

Message #

The RD Licensing has taken too long to process the client license

Event ID 20498: Remote Desktop Services has taken too long to complete the client connection

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services has taken too long to complete the client connection.

Message #

Remote Desktop Services has taken too long to complete the client connection

Event ID 20499: Remote Desktop Services has taken too long to load the user configuration from server UserName for user ServerName.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services has taken too long to load the user configuration from server UserName for user ServerName.

Message #

Remote Desktop Services has taken too long to load the user configuration from server %1 for user %2

Fields #

NameDescription
UserName UnicodeString
ServerName UnicodeString

Event ID 20500: Remote Desktop Services took time milliseconds to load the user configuration from server UserName for user ServerName.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services took time milliseconds to load the user configuration from server UserName for user ServerName.

Message #

Remote Desktop Services took %3 milliseconds to load the user configuration from server %1 for user %2

Fields #

NameDescription
UserName UnicodeString
ServerName UnicodeString
time Int32

Event ID 20501: Remote Desktop Services failed to shutdown within the time allocated

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin
Level
Warning

Description

Remote Desktop Services failed to shutdown within the time allocated.

Message #

Remote Desktop Services failed to shutdown within the time allocated

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "C76BAA63-AE81-421C-B425-340B4B24157F",
    "event_source_name": "",
    "event_id": 20501,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-13T18:32:00.352717+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 1480,
      "thread_id": 12992
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 20502: Remote Desktop Services failed to retrieve information about a connection for session Session within the time allocated.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Services failed to retrieve information about a connection for session Session within the time allocated.

Message #

Remote Desktop Services failed to retrieve information about a connection for session %1 within the time allocated

Fields #

NameDescription
Session Int32

Event ID 20503: Shadow View Session Started.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow View Session Started.

Message #

Shadow View Session Started

User %1 on computer %2 viewing user %3 (Session ID: %4)

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString
Param4 Int32

Event ID 20504: Shadow View Session Stopped.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow View Session Stopped.

Message #

Shadow View Session Stopped

User %1 on computer %2 viewing user %3 (Session ID: %4)

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString
Param4 Int32

Event ID 20506: Shadow Control Session Started.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow Control Session Started.

Message #

Shadow Control Session Started

User %1 on computer %2 controlling user %3 (Session ID: %4)

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString
Param4 Int32

Event ID 20507: Shadow Control Session Stopped.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow Control Session Stopped.

Message #

Shadow Control Session Stopped

User %1 on computer %2 controlling user %3 (Session ID: %4)

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString
Param4 Int32

Event ID 20508: Shadow View Permission Granted.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow View Permission Granted.

Message #

Shadow View Permission Granted

User %1 (Session ID: %3) granted permission to user %2

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 Int32

Event ID 20509: Shadow View Permission Denied.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow View Permission Denied.

Message #

Shadow View Permission Denied

User %1 (Session ID: %3) denied permission to user %2

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 Int32

Event ID 20510: Shadow Control Permission Granted.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow Control Permission Granted.

Message #

Shadow Control Permission Granted

User %1 (Session ID: %3) granted permission to user %2

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 Int32

Event ID 20511: Shadow Control Permission Denied.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow Control Permission Denied.

Message #

Shadow Control Permission Denied

User %1 (Session ID: %3) denied permission to user %2

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 Int32

Event ID 20512: Shadow Session Failure.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow Session Failure.

Message #

Shadow Session Failure

User %2 encountered error %3 trying to shadow user %1 (Session ID: %4)

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 HexInt32
Param4 Int32

Event ID 20513: Shadow Session Failure.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow Session Failure.

Message #

Shadow Session Failure

User %2 was unable to shadow user %1 (Session ID: %3) because of group policy settings.

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 Int32

Event ID 20514: Shadow Session Failure.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow Session Failure.

Message #

Shadow Session Failure

User %2 was unable to shadow user %1 (Session ID: %3) because that session is already being shadowed.

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 Int32

Event ID 20515: Session Session has been idle over its time limit, and was logged off.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Session Session has been idle over its time limit, and was logged off.

Message #

Session %1 has been idle over its time limit, and was logged off

Fields #

NameDescription
Session Int32

Event ID 20516: Session Session has been idle over its time limit, and was disconnected.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Session Session has been idle over its time limit, and was disconnected.

Message #

Session %1 has been idle over its time limit, and was disconnected

Fields #

NameDescription
Session Int32

Event ID 20517: Session Session has exceeded its time limit, and was logged off.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Session Session has exceeded its time limit, and was logged off.

Message #

Session %1 has exceeded its time limit, and was logged off

Fields #

NameDescription
Session Int32

Event ID 20518: Session Session has exceeded its time limit, and was disconnected.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Session Session has exceeded its time limit, and was disconnected.

Message #

Session %1 has exceeded its time limit, and was disconnected

Fields #

NameDescription
Session Int32

Event ID 20519: Session Session has exceeded its disconnect time limit, and was logged off.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Session Session has exceeded its disconnect time limit, and was logged off.

Message #

Session %1 has exceeded its disconnect time limit, and was logged off

Fields #

NameDescription
Session Int32

Event ID 20520: User config info will be loaded from domain controller for this Param1 connection.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

User config info will be loaded from domain controller for this Param1 connection.

Message #

User config info will be loaded from domain controller for this %1 connection

Fields #

NameDescription
Param1 UnicodeString

Event ID 20521: User config info will be loaded from local machine for this EventXML.Param1 connection.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin
Level
Informational

Description

User config info will be loaded from local machine for this EventXML.Param1 connection.

Message #

User config info will be loaded from local machine for this %1 connection

Fields #

NameDescription
Param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "C76BAA63-AE81-421C-B425-340B4B24157F",
    "event_source_name": "",
    "event_id": 20521,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:31:11.531699+00:00",
    "event_record_id": 16,
    "correlation": {
      "ActivityID": "F420649C-F05B-4253-B980-683E9A630000"
    },
    "execution": {
      "process_id": 1536,
      "thread_id": 2316
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Admin",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventXML": {
      "Param1": "RDP-Tcp"
    }
  },
  "message": ""
}

Event ID 20522: Shadow Session Clipboard Copy Request.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Shadow Session Clipboard Copy Request.

Message #

Shadow Session Clipboard Copy Request

User %1 on computer %2 controlling user %3 (Session ID: %4) Clipboard format: %5

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString
Param4 Int32
Param5 Int32

Event ID 20523: Connection from listener EventXML.ListenerName will have terminal class of EventXML.Class.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
Informational

Description

Connection from listener EventXML.ListenerName will have terminal class of EventXML.Class.

Message #

Connection from listener %1 will have terminal class of %2

Fields #

NameDescription
ListenerName UnicodeString
Class GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "guid": "C76BAA63-AE81-421C-B425-340B4B24157F",
    "event_source_name": "",
    "event_id": 20523,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-11T06:27:24.766379+00:00",
    "event_record_id": 244,
    "correlation": {
      "ActivityID": "F462B7C1-94B7-4A0B-B9BF-0F6B56B60000"
    },
    "execution": {
      "process_id": 1536,
      "thread_id": 1836
    },
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventXML": {
      "ListenerName": "31C5CE94259D4006A9E4",
      "Class": "D5993EAE-8D06-4A05-9CB4-94CEA280DC6B"
    }
  },
  "message": ""
}

Event ID 20524: Supplemental Kerberos credentials are not configured

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
Informational

Description

Supplemental Kerberos credentials are not configured.

Message #

Supplemental Kerberos credentials are not configured

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "event_id": 20524,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:29.3344433+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-TerminalServices-RemoteConnectionManager"
  },
  "event_data": {}
}

Event ID 20525: Successfully updated supplemental Kerberos credential Param1 in Param2 logon session.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Successfully updated supplemental Kerberos credential Param1 in Param2 logon session.

Message #

Successfully updated supplemental Kerberos credential %1 in %2 logon session

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString

Event ID 20526: Successfully removed supplemental Kerberos credential Param1 from Param2 logon session.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Successfully removed supplemental Kerberos credential Param1 from Param2 logon session.

Message #

Successfully removed supplemental Kerberos credential %1 from %2 logon session

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString

Event ID 20527: Failed to update supplemental Kerberos credentials.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Failed to update supplemental Kerberos credentials. Param1.

Message #

Failed to update supplemental Kerberos credentials. %1

Fields #

NameDescription
Param1 UnicodeString

Event ID 20528: Failed to update supplemental Kerberos credential Param1 in Param2 logon session.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Failed to update supplemental Kerberos credential Param1 in Param2 logon session. Param3.

Message #

Failed to update supplemental Kerberos credential %1 in %2 logon session. %3

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString

Event ID 20529: Failed to remove supplemental Kerberos credential Param1 from Param2 logon session.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Failed to remove supplemental Kerberos credential Param1 from Param2 logon session. Param3.

Message #

Failed to remove supplemental Kerberos credential %1 from %2 logon session. %3

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString
Param3 UnicodeString

Event ID 20530: Supplemental Kerberos credential Param1 configuration is invalid.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Supplemental Kerberos credential Param1 configuration is invalid. Param2.

Message #

Supplemental Kerberos credential %1 configuration is invalid. %2

Fields #

NameDescription
Param1 UnicodeString
Param2 UnicodeString

Event ID 20531: Remote Desktop Service's Threadpool is in terminated state.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Remote Desktop Service's Threadpool is in terminated state. Remote Desktop Connections may not work, this usually happens when TermService is being shutdown. If this was unintentional, restart Termservice manually.

Message #

Remote Desktop Service's Threadpool is in terminated state. Remote Desktop Connections may not work, this usually happens when TermService is being shutdown. If this was unintentional, restart Termservice manually.

Event ID 24576: Remote Desktop Configuration service could not remove user {Param1}\{Param2} from administrators group; error Code: {Param3}.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service could not remove user {Param1}\{Param2} from administrators group; error Code: {Param3}.

Message #

Remote Desktop Configuration service could not remove user {Param1}\{Param2} from administrators group; error Code: {Param3}

Fields #

NameDescription
Param1
Param2
Param3

Event ID 24577: Remote Desktop Configuration service could not remove user with SID {Param1} from administrators group; error Code: {Param2}.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service could not remove user with SID {Param1} from administrators group; error Code: {Param2}.

Message #

Remote Desktop Configuration service could not remove user with SID {Param1} from administrators group; error Code: {Param2}

Fields #

NameDescription
Param1
Param2

Event ID 24578: Remote Desktop Configuration service has added user {Param1}\{Param2} to administrators group.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Configuration service has added user {Param1}\{Param2} to administrators group.

Message #

Remote Desktop Configuration service has added user {Param1}\{Param2} to administrators group

Fields #

NameDescription
Param1
Param2

Event ID 50180: The remote session could not be established from remote desktop client Param1 because its license could not be renewed.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The remote session could not be established from remote desktop client Param1 because its license could not be renewed.

Message #

The remote session could not be established from remote desktop client %1 because its license could not be renewed.

Fields #

NameDescription
Param1 UnicodeString

Event ID 50195: The Remote Desktop Session Host server cannot communicate with the Remote Desktop license server Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The Remote Desktop Session Host server cannot communicate with the Remote Desktop license server Param1. Ensure that the computer account for the Remote Desktop Session Host server is a member of the RDS Endpoint Servers group on the license server.

Message #

The Remote Desktop Session Host server cannot communicate with the Remote Desktop license server %1. Ensure that the computer account for the Remote Desktop Session Host server is a member of the RDS Endpoint Servers group on the license server.

Fields #

NameDescription
Param1 UnicodeString

Event ID 50213: Remote Desktop Session Host server was unable to retrieve users licensing information from AD.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Session Host server was unable to retrieve users licensing information from AD. Error errorCode.

Message #

Remote Desktop Session Host server was unable to retrieve users licensing information from AD. Error %1

Fields #

NameDescription
errorCode UnicodeString

Event ID 50214: Remote Desktop Session Host server was successfully validated errorCode licensing information from AAD.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Session Host server was successfully validated errorCode licensing information from AAD.

Message #

Remote Desktop Session Host server was successfully validated %1 licensing information from AAD.

Fields #

NameDescription
errorCode UnicodeString

Event ID 50215: Remote Desktop Session Host server was unable to retrieve user licensing information from AAD.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Session Host server was unable to retrieve user licensing information from AAD. Error errorCode.

Message #

Remote Desktop Session Host server was unable to retrieve user licensing information from AAD. Error %1

Fields #

NameDescription
errorCode UnicodeString

Event ID 50216: Remote Desktop Session Host server was unable to validate RDS license.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

Remote Desktop Session Host server was unable to validate RDS license. Error errorCode.

Message #

Remote Desktop Session Host server was unable to validate RDS license. Error %1

Fields #

NameDescription
errorCode UnicodeString

Event ID 50280: The RD Licensing grace period has expired and the service has not registered with a license server with installed licenses.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The RD Licensing grace period has expired and the service has not registered with a license server with installed licenses. A RD Licensing server is required for continuous operation. A Remote Desktop Session Host server can operate without a license server for 120 days after initial start up.

Message #

The RD Licensing grace period has expired and the service has not registered with a license server with installed licenses. A RD Licensing server is required for continuous operation. A Remote Desktop Session Host server can operate without a license server for 120 days after initial start up.

Event ID 50281: The RD Licensing grace period is about to expire on Param1 and the service has not registered with a license server with installed licenses.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The RD Licensing grace period is about to expire on Param1 and the service has not registered with a license server with installed licenses. A RD Licensing server is required for continuous operation. A Remote Desktop Session Host server can operate without a license server for 120 days after initial start up.

Message #

The RD Licensing grace period is about to expire on %1 and the service has not registered with a license server with installed licenses. A RD Licensing server is required for continuous operation. A Remote Desktop Session Host server can operate without a license server for 120 days after initial start up.

Fields #

NameDescription
Param1 UnicodeString

Event ID 50282: The Remote Desktop Session Host server does not have a Remote Desktop license server specified.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The Remote Desktop Session Host server does not have a Remote Desktop license server specified. To specify a license server for the Remote Desktop Session Host server, use the Remote Desktop Session Host Configuration tool.

Message #

The Remote Desktop Session Host server does not have a Remote Desktop license server specified. To specify a license server for the Remote Desktop Session Host server, use the Remote Desktop Session Host Configuration tool.

Event ID 50283: The Remote Desktop Session Host server could not contact the Remote Desktop license server Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The Remote Desktop Session Host server could not contact the Remote Desktop license server Param1. Ensure that the Remote Desktop Licensing service is running on the license server, that the license server is accepting network requests, and that the license server is registered in WINS and DNS.

Message #

The Remote Desktop Session Host server could not contact the Remote Desktop license server %1. Ensure that the Remote Desktop Licensing service is running on the license server, that the license server is accepting network requests, and that the license server is registered in WINS and DNS.

Fields #

NameDescription
Param1 UnicodeString

Event ID 50284: The Remote Desktop license server Param1 does not support the version of the operating system running on the Remote Desktop Session Host server.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The Remote Desktop license server Param1 does not support the version of the operating system running on the Remote Desktop Session Host server.

Message #

The Remote Desktop license server %1 does not support the version of the operating system running on the Remote Desktop Session Host server.

Fields #

NameDescription
Param1 UnicodeString

Event ID 50285: The certificate issued by the Remote Desktop license server to the Remote Desktop Session Host server is not valid.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The certificate issued by the Remote Desktop license server to the Remote Desktop Session Host server is not valid. The license server will not issue Remote Desktop Services client access licenses to clients connecting to the Remote Desktop Session Host server. To resolve this issue, delete the certificate on the Remote Desktop Session Host server and then restart the Remote Desktop Services service.

Message #

The certificate issued by the Remote Desktop license server to the Remote Desktop Session Host server is not valid. The license server will not issue Remote Desktop Services client access licenses to clients connecting to the Remote Desktop Session Host server. To resolve this issue, delete the certificate on the Remote Desktop Session Host server and then restart the Remote Desktop Services service.

Event ID 50304: The Remote Desktop Virtualization Host server cannot issue a client license.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The Remote Desktop Virtualization Host server cannot issue a client license. It was unable to issue the license due to a changed (mismatched) client license, insufficient memory, or an internal error. Further details for this problem may have been reported at the client's computer.

Message #

The Remote Desktop Virtualization Host server cannot issue a client license.  It was unable to issue the license due to a changed (mismatched) client license, insufficient memory, or an internal error. Further details for this problem may have been reported at the client's computer.

Event ID 50305: The RD Licensing grace period has expired and Licensing mode for the Remote Desktop Virtualization Host server has not been configured.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The RD Licensing grace period has expired and Licensing mode for the Remote Desktop Virtualization Host server has not been configured. Licensing mode must be configured for continuous operation.

Message #

The RD Licensing grace period has expired and Licensing mode for the Remote Desktop Virtualization Host server has not been configured. Licensing mode must be configured for continuous operation.

Event ID 50306: The RD Licensing grace period has expired and the service has not registered with a license server with installed licenses.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The RD Licensing grace period has expired and the service has not registered with a license server with installed licenses. A RD Licensing server is required for continuous operation. A Remote Desktop Virtualization Host server can operate without a license server for 120 days after initial start up.

Message #

The RD Licensing grace period has expired and the service has not registered with a license server with installed licenses. A RD Licensing server is required for continuous operation. A Remote Desktop Virtualization Host server can operate without a license server for 120 days after initial start up.

Event ID 50307: The RD Licensing grace period is about to expire on Param1 and the service has not registered with a license server with installed licenses.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The RD Licensing grace period is about to expire on Param1 and the service has not registered with a license server with installed licenses. A RD Licensing server is required for continuous operation. A Remote Desktop Virtualization Host server can operate without a license server for 120 days after initial start up.

Message #

The RD Licensing grace period is about to expire on %1 and the service has not registered with a license server with installed licenses. A RD Licensing server is required for continuous operation. A Remote Desktop Virtualization Host server can operate without a license server for 120 days after initial start up.

Fields #

NameDescription
Param1 UnicodeString

Event ID 50308: The Remote Desktop Virtualization Host server does not have a Remote Desktop license server specified.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The Remote Desktop Virtualization Host server does not have a Remote Desktop license server specified. To specify a license server for the Remote Desktop Virtualization Host server, use the RDS module for Windows PowerShell.

Message #

The Remote Desktop Virtualization Host server does not have a Remote Desktop license server specified. To specify a license server for the Remote Desktop Virtualization Host server, use the RDS module for Windows PowerShell.

Event ID 50309: The Remote Desktop Virtualization Host server could not contact the Remote Desktop license server Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The Remote Desktop Virtualization Host server could not contact the Remote Desktop license server Param1. Ensure that the Remote Desktop Licensing service is running on the license server, that the license server is accepting network requests, and that the license server is registered in WINS and DNS.

Message #

The Remote Desktop Virtualization Host server could not contact the Remote Desktop license server %1. Ensure that the Remote Desktop Licensing service is running on the license server, that the license server is accepting network requests, and that the license server is registered in WINS and DNS.

Fields #

NameDescription
Param1 UnicodeString

Event ID 50310: The Remote Desktop license server Param1 does not support the version of the operating system running on the Remote Desktop Virtualization Host server.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The Remote Desktop license server Param1 does not support the version of the operating system running on the Remote Desktop Virtualization Host server.

Message #

The Remote Desktop license server %1 does not support the version of the operating system running on the Remote Desktop Virtualization Host server.

Fields #

NameDescription
Param1 UnicodeString

Event ID 50311: The certificate issued by the Remote Desktop license server to the Remote Desktop Virtualization Host server is not valid.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The certificate issued by the Remote Desktop license server to the Remote Desktop Virtualization Host server is not valid. The license server will not issue licenses to clients connecting to the Remote Desktop Virtualization Host server. To resolve this issue, delete the certificate on the Remote Desktop Virtualization Host server and then restart the Remote Desktop Services service.

Message #

The certificate issued by the Remote Desktop license server to the Remote Desktop Virtualization Host server is not valid. The license server will not issue licenses to clients connecting to the Remote Desktop Virtualization Host server. To resolve this issue, delete the certificate on the Remote Desktop Virtualization Host server and then restart the Remote Desktop Services service.

Event ID 50312: The Remote Desktop Virtualization Host server cannot communicate with the Remote Desktop license server Param1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Admin

Description

The Remote Desktop Virtualization Host server cannot communicate with the Remote Desktop license server Param1. Ensure that the computer account for the Remote Desktop Virtualization Host server is a member of the RDS Endpoint Servers group on the license server.

Message #

The Remote Desktop Virtualization Host server cannot communicate with the Remote Desktop license server %1. Ensure that the computer account for the Remote Desktop Virtualization Host server is a member of the RDS Endpoint Servers group on the license server.

Fields #

NameDescription
Param1 UnicodeString

Event ID 1073742836: Remote session from client name %1 exceeded the maximum allowed failed logon attempts.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Remote session from client name exceeded the maximum allowed failed logon attempts. The session was forcibly terminated.

Message #

Remote session from client name %1 exceeded the maximum allowed failed logon attempts. The session was forcibly terminated.

Event ID 3221226494: TermService clustering failed to redirect a client to an alternate clustered server, ntstatus=.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

TermService clustering failed to redirect a client to an alternate clustered server, ntstatus=.

Message #

TermService clustering failed to redirect a client to an alternate clustered server, ntstatus=%1.

Event ID 3221226496: TermService clustering failed to initialize because the Session Directory Provider failed to initialize, hresult=.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

TermService clustering failed to initialize because the Session Directory Provider failed to initialize, hresult=.

Message #

TermService clustering failed to initialize because the Session Directory Provider failed to initialize, hresult=%1.

Event ID 3221226507: RD Session Host Server listener stack was down.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

RD Session Host Server listener stack was down. The relevant status code .

Message #

RD Session Host Server listener stack was down. The relevant status code %1.

Event ID 3221226508: RD Session Host Server session creation failed.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

RD Session Host Server session creation failed. The relevant status code was .

Message #

RD Session Host Server session creation failed. The relevant status code was %1.

Event ID 3221226513: Autoreconnect failed to reconnect user to session because authentication failed.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Autoreconnect failed to reconnect user to session because authentication failed. ().

Message #

Autoreconnect failed to reconnect user to session because authentication failed. (%1)

Event ID 3221226518: Failed to load RD Session Host Server Profile path.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Failed to load RD Session Host Server Profile path. Note that the profile path must be less than 256 characters in length. User Name: Domain.

Message #

Failed to load RD Session Host Server Profile path. Note that the profile path must be less than 256 characters in length. User Name: %1 Domain: %2

Event ID 3221226522: The RD Session Host Server listener %1 is configured with inconsistent authentication and encryption settings.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host Server listener %1 is configured with inconsistent authentication and encryption settings. The Encryption Level is currently set to %2 and Security Layer is set to %3. These settings were automatically corrected to allow connections to proceed. Please change the Security Layer and Encryption Level settings in Group Policy or by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Message #

The RD Session Host Server listener %1 is configured with inconsistent authentication and encryption settings. The Encryption Level is currently set to %2 and Security Layer is set to %3. These settings were automatically corrected to allow connections to proceed. Please change the Security Layer and Encryption Level settings in Group Policy or by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Event ID 3221226523: The RD Session Host Server is configured to use SSL with user selected certificate, however, no usable certificate was found on the server.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host Server is configured to use SSL with user selected certificate, however, no usable certificate was found on the server. The default certificate will be used for RD Session Host Server authentication from now on. Please check the security settings by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Message #

The RD Session Host Server is configured to use SSL with user selected certificate, however, no usable certificate was found on the server. The default certificate will be used for RD Session Host Server authentication from now on. Please check the security settings by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Event ID 3221226524: The RD Session Host Server is configured to use a certificate that will expire in %2 days.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host Server is configured to use a certificate that will expire in %2 days. %1 The SHA1 hash of the certificate is in the event data. Please check the security settings by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Message #

The RD Session Host Server is configured to use a certificate that will expire in %2 days. %1 The SHA1 hash of the certificate is in the event data. Please check the security settings by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Event ID 3221226525: The RD Session Host Server is configured to use a certificate that is expired.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host Server is configured to use a certificate that is expired. %1 The SHA1 hash of the certificate is in the event data. The default certificate will be used for RD Session Host Server authentication from now on. Please check the security settings by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Message #

The RD Session Host Server is configured to use a certificate that is expired. %1 The SHA1 hash of the certificate is in the event data. The default certificate will be used for RD Session Host Server authentication from now on. Please check the security settings by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Event ID 3221226526: The RD Session Host Server is configured to use a certificate that does not contain an Enhanced Key Usage attribute of Server Authentication.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host Server is configured to use a certificate that does not contain an Enhanced Key Usage attribute of Server Authentication. %1 The SHA1 hash of the certificate is in the event data. The default certificate will be used for RD Session Host Server authentication from now on. Please check the security settings by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Message #

The RD Session Host Server is configured to use a certificate that does not contain an Enhanced Key Usage attribute of Server Authentication. %1 The SHA1 hash of the certificate is in the event data. The default certificate will be used for RD Session Host Server authentication from now on. Please check the security settings by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Event ID 3221226527: The RD Session Host Server is configured to use a certificate but is unable to access the private key associated with this certificate.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host Server is configured to use a certificate but is unable to access the private key associated with this certificate. %1 The SHA1 hash of the certificate is in the event data. The default certificate will be used for RD Session Host Server authentication from now on. Please check the security settings by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Message #

The RD Session Host Server is configured to use a certificate but is unable to access the private key associated with this certificate. %1 The SHA1 hash of the certificate is in the event data. The default certificate will be used for RD Session Host Server authentication from now on. Please check the security settings by using the Remote Desktop Session Host Configuration tool in the Administrative Tools folder.

Event ID 3221226528: A new self signed certificate to be used for RD Session Host Server authentication on SSL connections was generated.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational
Level
4

Description

A new self signed certificate to be used for RD Session Host Server authentication on SSL connections was generated. The name on this certificate is %1. The SHA1 hash of the certificate is in the event data.

Message #

A new self signed certificate to be used for RD Session Host Server authentication on SSL connections was generated. The name on this certificate is %1. The SHA1 hash of the certificate is in the event data.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-RemoteConnectionManager",
    "event_id": 1056,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:29.6241537+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "Binary": "711E31623D227BA329E804181302537F5A6E304A",
    "Data": "DESKTOP-FF3N5XK.ludus.domain"
  }
}

Event ID 3221226529: The RD Session Host Server has failed to create a new self signed certificate to be used for RD Session Host Server authentication on SSL connections.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host Server has failed to create a new self signed certificate to be used for RD Session Host Server authentication on SSL connections. The relevant status code was .

Message #

The RD Session Host Server has failed to create a new self signed certificate to be used for RD Session Host Server authentication on SSL connections. The relevant status code was %1.

Event ID 3221226530: The RD Session Host Server has failed to replace the expired self signed certificate used for RD Session Host Server authentication on SSL connecti...

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host Server has failed to replace the expired self signed certificate used for RD Session Host Server authentication on SSL connections. The relevant status code was .

Message #

The RD Session Host Server has failed to replace the expired self signed certificate used for RD Session Host Server authentication on SSL connections. The relevant status code was %1.

Event ID 3221226531: The RD Session Host Server authentication certificate configuration data was invalid and the service reset it.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host Server authentication certificate configuration data was invalid and the service reset it. If the computer was configured to use a specific certificate, please verify it is available in the certificate store and use the administrative tools to select it again.

Message #

The RD Session Host Server authentication certificate configuration data was invalid and the service reset it. If the computer was configured to use a specific certificate, please verify it is available in the certificate store and use the administrative tools to select it again.

Event ID 3221226532: The Remote Desktop Services User Home Directory was not set because the path specified does not exist or not accessible.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The Remote Desktop Services User Home Directory was not set because the path specified does not exist or not accessible. The default Home Directory Path was used instead. User Name: Domain.

Message #

The Remote Desktop Services User Home Directory was not set because the path specified does not exist or not accessible. The default Home Directory Path was used instead. User Name: %1 Domain: %2

Event ID 3221226533: Remote Desktop Session Host server was unable to retrieve users Licensing information from AD.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

Remote Desktop Session Host server was unable to retrieve users Licensing information from AD. Error {errorCode}.

Message #

Remote Desktop Session Host server was unable to retrieve users Licensing information from AD. Error {errorCode}

Fields #

NameDescription
errorCode

Event ID 3221226534: The RD Session Host server is configured to use a template-based certificate for Transport Layer Security (TLS) 1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host server is configured to use a template-based certificate for Transport Layer Security (TLS) 1.0\Secure Sockets Layer (SSL) authentication and encryption, but the subject name on the certificate is invalid. %1 The SHA1 hash of the certificate is in the event data. Therefore, the default certificate will be used by the RD Session Host server for authentication. To resolve this issue, make sure that template used to create this certificate is configured to use DNS name as subject name .

Message #

The RD Session Host server is configured to use a template-based certificate for Transport Layer Security (TLS) 1.0\Secure Sockets Layer (SSL) authentication and encryption, but the subject name on the certificate is invalid. %1 The SHA1 hash of the certificate is in the event data. Therefore, the default certificate will be used by the RD Session Host server for authentication. To resolve this issue, make sure that template used to create this certificate is configured to use DNS name as subject name .

Event ID 3221226535: A new template-based certificate to be used by the RD Session Host server for Transport Layer Security (TLS) 1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

A new template-based certificate to be used by the RD Session Host server for Transport Layer Security (TLS) 1.0\Secure Sockets Layer (SSL) authentication and encryption has been installed. The name for this certificate is %1. The SHA1 hash of the certificate is provided in the event data.

Message #

A new template-based certificate to be used by the RD Session Host server for Transport Layer Security (TLS) 1.0\Secure Sockets Layer (SSL) authentication and encryption has been installed. The name for this certificate is %1. The SHA1 hash of the certificate is provided in the event data.

Event ID 3221226536: The RD Session Host server cannot install a new template-based certificate to be used for Transport Layer Security (TLS) 1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host server cannot install a new template-based certificate to be used for Transport Layer Security (TLS) 1.0\Secure Sockets Layer (SSL) authentication and encryption. The following error occured: %1.

Message #

The RD Session Host server cannot install a new template-based certificate to be used for Transport Layer Security (TLS) 1.0\Secure Sockets Layer (SSL) authentication and encryption. The following error occured: %1.

Event ID 3221226537: The template-based certificate that is being used by the RD Session Host server for Transport Layer Security (TLS) 1.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The template-based certificate that is being used by the RD Session Host server for Transport Layer Security (TLS) 1.0\Secure Sockets Layer (SSL) authentication and encryption has expired and cannot be replaced by the RD Session Host server. The following error occurred: %1.

Message #

The template-based certificate that is being used by the RD Session Host server for Transport Layer Security (TLS) 1.0\Secure Sockets Layer (SSL) authentication and encryption has expired and cannot be replaced by the RD Session Host server. The following error occurred: %1.

Event ID 3221226538: RD Session Host Server was unable to process session arbitration request.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

RD Session Host Server was unable to process session arbitration request. Error.

Message #

RD Session Host Server was unable to process session arbitration request. Error %1

Event ID 3221226539: The RD Session Host server cannot register 'TERMSRV' Service Principal Name to be used for server authentication.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The RD Session Host server cannot register 'TERMSRV' Service Principal Name to be used for server authentication. The following error occured: .

Message #

The RD Session Host server cannot register 'TERMSRV' Service Principal Name to be used for server authentication. The following error occured: %1.

Event ID 3221226542: A logon request was denied because the RD Session Host server is currently in drain mode and therefore not accepting new user logons.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

A logon request was denied because the RD Session Host server is currently in drain mode and therefore not accepting new user logons. To configure the server to allow new user logons, use the Remote Desktop Services Configuration tool.

Message #

A logon request was denied because the RD Session Host server is currently in drain mode and therefore not accepting new user logons. To configure the server to allow new user logons, use the Remote Desktop Services Configuration tool.

Event ID 3221226543: A connection request was denied because the RD Session Host server is currently configured to not accept connections.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

A connection request was denied because the RD Session Host server is currently configured to not accept connections. To configure the server to allow connections, use the chglogon command-line tool.

Message #

A connection request was denied because the RD Session Host server is currently configured to not accept connections. To configure the server to allow connections, use the chglogon command-line tool.

Event ID 3221226544: The cn column for the template-based certificate %1 returned an unknown data type %2.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The cn column for the template-based certificate returned an unknown data type .

Message #

The cn column for the template-based certificate %1 returned an unknown data type %2.

Event ID 3221226545: The msPKI-Cert-Template-OID column for the template-based certificate %1 returned an unknown data type %2.

#
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Channel
Operational

Description

The msPKI-Cert-Template-OID column for the template-based certificate returned an unknown data type .

Message #

The msPKI-Cert-Template-OID column for the template-based certificate %1 returned an unknown data type %2.

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID c76baa63-ae81-421c-b425-340b4b24157f

Defined in termsrv.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads