Microsoft-Windows-User Profiles Service

EventTitleChannelSampleRule
1Recieved user logon notification on session Session.OperationalYN
2Finished processing user logon notification on session Session.OperationalYN
3Recieved user logoff notification on session Session.OperationalYN
4Finished processing user logoff notification on session Session.OperationalYN
5Registry file File is loaded at HKU\Key.OperationalYN
6Starting synchronize profile from Source to Target.OperationalNN
7Finished synchronize profile from Source to Target.OperationalNN
50Background hive upload for user UserSid started.OperationalNN
51Background hive upload for user UserSid succeeded.OperationalNN
52Background hive upload for user UserSid failed.OperationalNN
53Cannot delete file File.OperationalNN
54Open user regisry root key for UserSid failed.OperationalNN
55Save user hive to file File failed.OperationalNN
56Save user hive to file File succeeded.OperationalNN
57Enable background user hive upload task succeeded.OperationalNN
58Failed to enable background user hive upload task.OperationalNN
59Disable background user hive upload task succeeded.OperationalYN
60Failed to disable background user hive upload task.OperationalNN
61Slow network connection detected, abort background user hive upload task.OperationalNN
62Windows was unable to successfully evaluate whether this computer is a primary …OperationalNN
63This computer Result a primary computer for this user.OperationalNN
64The primary computer relationship for this computer and this user was not …OperationalNN
65The attempt to create or open the profile key for the user failed with error …OperationalNN
66Creating the local profile for the user failed with error Error.OperationalNN
67Logon type: LogonType.OperationalYN
68LastDownloadTime: DownloadTime.OperationalNN
70Waiting on network arrivals.OperationalNN
71After waiting Timeout ms, a network with the necessary capabilities was not …OperationalNN
72Terminating wait due to unexpected failure Result.OperationalNN
73Wait complete due to connectivity event but network not ready.OperationalNN
74Wait completed due to network connectivity or determination that no viable …OperationalNN
75Roaming Profiles configuration is being controlled by Group Policy.OperationalNN
76Roaming Profiles configuration is being controlled by WMI configuration classes …OperationalNN
1001Begin new user profile creation.DiagnosticNN
1002New user profile creation complete.DiagnosticNN
1003A network latency of MeasuredLatency milliseconds has been detected.DiagnosticNN
1004A network bandwidth of MeasuredBandwidth kilobits per second has been detected.DiagnosticNN
1005Delete cached profile ProfilePath since it is older than AgeLimitInDays days.DiagnosticNN
1500Windows cannot log you on because your profile cannot be loaded.ApplicationNN
1501Windows cannot create a temporary profile directory.ApplicationNN
1502Windows cannot load the locally stored profile.ApplicationNN
1503Windows cannot set security on your registry.ApplicationNN
1504Windows cannot update your roaming profile completely.ApplicationNN
1505Windows cannot load the user's profile but has logged you on with the default …ApplicationNN
1506Your roaming profile is not available.ApplicationNN
1508Windows was unable to load the registry.ApplicationNN
1509Windows was unable to load File.ApplicationNN
1510Windows cannot load your profile because it appears to be corrupted.ApplicationNN
1511Windows cannot find the local profile and is logging you on with a temporary …ApplicationNY
1512Windows cannot unload your registry file.ApplicationNN
1513Windows cannot copy your profile because it contains encrypted files or …ApplicationNN
1514The roaming profile path File is too long.ApplicationNN
1515Windows has backed up this user profile.ApplicationNN
1517Windows saved user UserSid registry while an application or service was still …ApplicationNN
1518Windows cannot create a local profile and is logging you on with a temporary …ApplicationNN
1519Windows cannot locate your roaming mandatory profile and is attempting to log …ApplicationNN
1520Windows cannot log you on because your roaming mandatory profile is not …ApplicationNN
1521Windows cannot locate the server copy of your roaming profile and is attempting …ApplicationNN
1522Windows cannot locate your roaming profile (read only) and is attempting to log …ApplicationNN
1523Your roaming profile (read only) is not available.ApplicationNN
1524Windows cannot unload your classes registry file - it is still in use by other …ApplicationNN
1525Windows has detected that Automatic Offline Caching is enabled on the Roaming …ApplicationNN
1526Windows could not load your roaming profile and is attempting to log you on with …ApplicationNN
1527Windows failed to initialize user profiles.ApplicationNN
1529Roaming user profiles across forests are disabled.ApplicationNN
1530Windows detected your registry file is still in use by other applications or …ApplicationYN
1531The User Profile Service has started successfully.ApplicationYN
1532The User Profile Service has stopped.ApplicationYN
1533Windows cannot delete the profile directory Folder.ApplicationNN
1534Profile notification of event Event for component Component failed, error code …ApplicationNN
1535Successfully suspended folder "Folder".ApplicationNN
1536Successfully unsuspended folder "Folder".ApplicationNN
1537Failed to suspend folder "Folder" DETAIL - Error.ApplicationNN
1538Failed to unsuspend folder "Folder" DETAIL - Error.ApplicationNN
1539Failed to sync folder "Folder" DETAIL - Error.ApplicationNN
1540Your roaming profile is not synchronized correctly with the server.ApplicationNN
1541Failed to apply CSC suspend policy.ApplicationNN
1542Windows cannot load classes registry file.ApplicationNN
1543A slow network connection is detected for the roaming profile Folder.ApplicationNN
1544Windows cannot back up a ProfileList entry because one already exists for this …ApplicationNN
1545User hive is loaded by another process (File Lock).ApplicationNN
1552User hive is loaded by another process (Registry Lock) Process name: …ApplicationNN
1073743340Windows unloaded user {User} registry when it received a notification that no …OperationalNN
1073743341Windows saved user {User} registry while an application or service was still …OperationalNN
1073743355The User Profile Service has started successfully.OperationalYN
1073743356The User Profile Service has stopped.OperationalYN
1073743359Successfully suspended folder '{Folder}'.OperationalNN
1073743360Successfully unsuspended folder '{Folder}'.OperationalNN
2147485172Windows cannot unload your classes registry file - it is still in use by other …OperationalNN
2147485173Windows has detected that Automatic Offline Caching is enabled on the Roaming …OperationalNN
2147485178Windows detected your registry file is still in use by other applications or …OperationalNN
2147485182Profile notification of event {Event} for component {Component} failed; error …OperationalNN
2147485188Your roaming profile is not synchronized correctly with the server.OperationalNN
3221226972Windows cannot log you on because your profile cannot be loaded.OperationalNN
3221226973Windows cannot create a temporary profile directory.OperationalNN
3221226974Windows cannot load the locally stored profile.OperationalNN
3221226975Windows cannot set security on your registry.OperationalNN
3221226976Windows Windows cannot update your roaming profile completely.OperationalNN
3221226977Windows cannot load the user's profile but has logged you on with the default …OperationalNN
3221226978Your roaming profile is not available.OperationalNN
3221226980Windows was unable to load the registry.OperationalNN
3221226982Windows cannot load your profile because it appears to be corrupted.OperationalNN
3221226983Windows cannot find the local profile and is logging you on with a temporary …OperationalNN
3221226984Windows cannot unload your registry file.OperationalNN
3221226985Windows cannot copy your profile because it contains encrypted files or …OperationalNN
3221226986The roaming profile path {File} is too long.OperationalNN
3221226987Windows has backed up this user profile.OperationalNN
3221226990Windows cannot create a local profile and is logging you on with a temporary …OperationalNN
3221226991Windows cannot locate your roaming mandatory profile and is attempting to log …OperationalNN
3221226992Windows cannot log you on because your roaming mandatory profile is not …OperationalNN
3221226993Windows cannot locate the server copy of your roaming profile and is attempting …OperationalNN
3221226994Windows cannot locate your roaming profile (read only) and is attempting to log …OperationalNN
3221226995Your roaming profile (read only) is not available.OperationalNN
3221226998Windows could not load your roaming profile and is attempting to log you on with …OperationalNN
3221226999Windows failed to initialize user profiles.OperationalNN
3221227001Roaming user profiles across forests are disabled.OperationalNN
3221227005Windows cannot delete the profile directory {Directory}.OperationalNN
3221227009Failed to suspend folder '{Folder}' DETAIL - {Error}.OperationalNN
3221227010Failed to unsuspend folder '{Folder}' DETAIL - {Error}.OperationalNN
3221227011Failed to sync folder '{Folder}' DETAIL - {Error}.OperationalNN
3221227013Failed to apply CSC suspend policy.OperationalNN
3221227014Windows cannot load classes registry file.OperationalNN
3221227015A slow network connection is detected for the roaming profile {Path}.OperationalNN

Event ID 1: Recieved user logon notification on session Session.

#
Channel
Operational
Level
Informational

Message #

Recieved user logon notification on session %1.

Fields #

NameDescription
Session UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "guid": "{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-29T16:33:48.1913361+00:00",
    "event_record_id": 2552,
    "correlation": {},
    "execution": {
      "process_id": 1956,
      "thread_id": 2076
    },
    "channel": "Microsoft-Windows-User Profile Service/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Session": "1"
  },
  "message": "Recieved user logon notification on session 1."
}

Event ID 2: Finished processing user logon notification on session Session.

#
Channel
Operational
Level
Informational

Message #

Finished processing user logon notification on session %1.

Fields #

NameDescription
Session UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "guid": "{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-29T16:33:56.4458392+00:00",
    "event_record_id": 2556,
    "correlation": {},
    "execution": {
      "process_id": 1956,
      "thread_id": 2076
    },
    "channel": "Microsoft-Windows-User Profile Service/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Session": "1"
  },
  "message": "Finished processing user logon notification on session 1."
}

Event ID 3: Recieved user logoff notification on session Session.

#
Channel
Operational
Level
Informational

Message #

Recieved user logoff notification on session %1.

Fields #

NameDescription
Session UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "guid": "{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}",
    "event_source_name": "",
    "event_id": 3,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T05:22:33.7590478+00:00",
    "event_record_id": 1443,
    "correlation": {},
    "execution": {
      "process_id": 1852,
      "thread_id": 7840
    },
    "channel": "Microsoft-Windows-User Profile Service/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Session": "1"
  },
  "message": "Recieved user logoff notification on session 1."
}

Event ID 4: Finished processing user logoff notification on session Session.

#
Channel
Operational
Level
Informational

Message #

Finished processing user logoff notification on session %1.

Fields #

NameDescription
Session UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "guid": "{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}",
    "event_source_name": "",
    "event_id": 4,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T05:22:33.8528968+00:00",
    "event_record_id": 1444,
    "correlation": {},
    "execution": {
      "process_id": 1852,
      "thread_id": 7840
    },
    "channel": "Microsoft-Windows-User Profile Service/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Session": "1"
  },
  "message": "Finished processing user logoff notification on session 1."
}

Event ID 5: Registry file File is loaded at HKU\Key.

#
Channel
Operational
Level
Informational

Message #

Registry file %1 is loaded at HKU\%2.

Fields #

NameDescription
File UnicodeString
Key UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "guid": "{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}",
    "event_source_name": "",
    "event_id": 5,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T01:01:44.4866856+00:00",
    "event_record_id": 2567,
    "correlation": {},
    "execution": {
      "process_id": 1956,
      "thread_id": 3940
    },
    "channel": "Microsoft-Windows-User Profile Service/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "File": "C:\\Users\\localuser\\AppData\\Local\\Microsoft\\Windows\\\\UsrClass.dat",
    "Key": "S-1-5-21-1006758700-2167138679-1475694448-1000_Classes"
  },
  "message": "Registry file C:\\Users\\localuser\\AppData\\Local\\Microsoft\\Windows\\\\UsrClass.dat is loaded at HKU\\S-1-5-21-1006758700-2167138679-1475694448-1000_Classes."
}

Event ID 6: Starting synchronize profile from Source to Target.

#
Channel
Operational

Message #

Starting synchronize profile from %1 to %2.

Fields #

NameDescription
Source UnicodeString
Target UnicodeString

Event ID 7: Finished synchronize profile from Source to Target.

#
Channel
Operational

Message #

Finished synchronize profile from %1 to %2. 

Result: %3

Fields #

NameDescription
Source UnicodeString
Target UnicodeString
Result UnicodeString

Event ID 50: Background hive upload for user UserSid started.

#
Channel
Operational

Message #

Background hive upload for user %1 started.

Fields #

NameDescription
UserSid UnicodeString

Event ID 51: Background hive upload for user UserSid succeeded.

#
Channel
Operational

Message #

Background hive upload for user %1 succeeded.

Fields #

NameDescription
UserSid UnicodeString

Event ID 52: Background hive upload for user UserSid failed.

#
Channel
Operational

Message #

Background hive upload for user %1 failed.

 Error: %2

Fields #

NameDescription
UserSid UnicodeString
Error UnicodeString

Event ID 53: Cannot delete file File.

#
Channel
Operational

Message #

Cannot delete file %1.

 Error: %2

Fields #

NameDescription
File UnicodeString
Error UnicodeString

Event ID 54: Open user regisry root key for UserSid failed.

#
Channel
Operational

Message #

Open user regisry root key for %1 failed.

 Error: %2

Fields #

NameDescription
UserSid UnicodeString
Error UnicodeString

Event ID 55: Save user hive to file File failed.

#
Channel
Operational

Message #

Save user hive to file %1 failed.

 Error: %2

Fields #

NameDescription
File UnicodeString
Error UnicodeString

Event ID 56: Save user hive to file File succeeded.

#
Channel
Operational

Message #

Save user hive to file %1 succeeded.

Fields #

NameDescription
File UnicodeString

Event ID 57: Enable background user hive upload task succeeded.

#
Channel
Operational

Event ID 58: Failed to enable background user hive upload task.

#
Channel
Operational

Message #

Failed to enable background user hive upload task.

 Error: %1

Fields #

NameDescription
Error UnicodeString

Event ID 59: Disable background user hive upload task succeeded.

#
Channel
Operational
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "guid": "{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}",
    "event_source_name": "",
    "event_id": 59,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-29T06:21:48.6520908+00:00",
    "event_record_id": 2486,
    "correlation": {},
    "execution": {
      "process_id": 1840,
      "thread_id": 1952
    },
    "channel": "Microsoft-Windows-User Profile Service/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "Disable background user hive upload task succeeded."
}

Event ID 60: Failed to disable background user hive upload task.

#
Channel
Operational

Message #

Failed to disable background user hive upload task.

 Error: %1

Fields #

NameDescription
Error UnicodeString

Event ID 61: Slow network connection detected, abort background user hive upload task.

#
Channel
Operational

Event ID 62: Windows was unable to successfully evaluate whether this computer is a primary computer for this user.

#
Channel
Operational

Description

Windows was unable to successfully evaluate whether this computer is a primary computer for this user. This may be due to failing to access the Active Directory server at this time. The user's roaming profile will be applied as configured. Contact the Administrator for more assistance. Error: Error

Message #

Windows was unable to successfully evaluate whether this computer is a primary computer for this user. This may be due to failing to access the Active Directory server at this time. The user's roaming profile will be applied as configured. Contact the Administrator for more assistance. Error: %1

Fields #

NameDescription
Error HexInt32

Event ID 63: This computer Result a primary computer for this user.

#
Channel
Operational

Message #

This computer %1 a primary computer for this user.

Fields #

NameDescription
Result UnicodeString

Event ID 64: The primary computer relationship for this computer and this user was not evaluated due to EnvIssue.

#
Channel
Operational

Message #

The primary computer relationship for this computer and this user was not evaluated due to %1.

Fields #

NameDescription
EnvIssue UnicodeString

Event ID 65: The attempt to create or open the profile key for the user failed with error Error.

#
Channel
Operational

Message #

The attempt to create or open the profile key for the user failed with error %1.

Fields #

NameDescription
Error HexInt32

Event ID 66: Creating the local profile for the user failed with error Error.

#
Channel
Operational

Message #

Creating the local profile for the user failed with error %1.

Fields #

NameDescription
Error HexInt32

Event ID 67: Logon type: LogonType.

#
Channel
Operational
Level
Informational

Message #

Logon type: %1 
Local profile location: %2 
Profile type: %3

Fields #

NameDescription
LogonType UnicodeStringLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). Logon type reference
LocalPath UnicodeString
ProfileType UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "guid": "{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}",
    "event_source_name": "",
    "event_id": 67,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T01:01:44.4879394+00:00",
    "event_record_id": 2568,
    "correlation": {},
    "execution": {
      "process_id": 1956,
      "thread_id": 3940
    },
    "channel": "Microsoft-Windows-User Profile Service/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "LogonType": "Regular",
    "LocalPath": "C:\\Users\\localuser",
    "ProfileType": "Regular"
  },
  "message": "Logon type: Regular \r\nLocal profile location: C:\\Users\\localuser \r\nProfile type: Regular"
}

Event ID 68: LastDownloadTime: DownloadTime.

#
Channel
Operational

Message #

LastDownloadTime: %1 
LastUploadTime: %2

Fields #

NameDescription
DownloadTime UnicodeString
UploadTime UnicodeString

Event ID 70: Waiting on network arrivals.

#
Channel
Operational

Description

Waiting on network arrivals. Max wait time Timeout ms.

Message #

Waiting on network arrivals. Max wait time %1 ms.

Fields #

NameDescription
Timeout UInt32

Event ID 71: After waiting Timeout ms, a network with the necessary capabilities was not ready for use.

#
Channel
Operational

Description

After waiting Timeout ms, a network with the necessary capabilities was not ready for use. Allowing profile load to proceed.

Message #

After waiting %1 ms, a network with the necessary capabilities was not ready for use. Allowing profile load to proceed.

Fields #

NameDescription
Timeout UInt32

Event ID 72: Terminating wait due to unexpected failure Result.

#
Channel
Operational

Message #

Terminating wait due to unexpected failure %1.

Fields #

NameDescription
Result HexInt32

Event ID 73: Wait complete due to connectivity event but network not ready.

#
Channel
Operational

Event ID 74: Wait completed due to network connectivity or determination that no viable network connection is likely to become available.

#
Channel
Operational

Description

Wait completed due to network connectivity or determination that no viable network connection is likely to become available. Allowing profile load to proceed.

Message #

Wait completed due to network connectivity or determination that no viable network connection is likely to become available. Allowing profile load to proceed.

Event ID 75: Roaming Profiles configuration is being controlled by Group Policy.

#
Channel
Operational

Event ID 76: Roaming Profiles configuration is being controlled by WMI configuration classes Win32_RoamingProfileUserConfiguration and Win32_RoamingProfileMachi...

#
Channel
Operational

Description

Roaming Profiles configuration is being controlled by WMI configuration classes Win32_RoamingProfileUserConfiguration and Win32_RoamingProfileMachineConfiguration.

Message #

Roaming Profiles configuration is being controlled by WMI configuration classes Win32_RoamingProfileUserConfiguration and Win32_RoamingProfileMachineConfiguration.

Event ID 1001: Begin new user profile creation.

#
Channel
Diagnostic
Task
ProfSvc_CreateNewProfile
Opcode
Start

Event ID 1002: New user profile creation complete.

#
Channel
Diagnostic
Task
ProfSvc_CreateNewProfile
Opcode
Stop

Event ID 1003: A network latency of MeasuredLatency milliseconds has been detected.

#
Channel
Diagnostic

Description

A network latency of MeasuredLatency milliseconds has been detected. Maximum latency to synchronize a roaming profile is set at LatencyThreshold milliseconds.

Message #

A network latency of %1 milliseconds has been detected.  Maximum latency to synchronize a roaming profile is set at %2 milliseconds.

Fields #

NameDescription
MeasuredLatency UInt32
LatencyThreshold UInt32

Event ID 1004: A network bandwidth of MeasuredBandwidth kilobits per second has been detected.

#
Channel
Diagnostic

Description

A network bandwidth of MeasuredBandwidth kilobits per second has been detected. Minimum bandwidth to synchronize a roaming profile is set at BandwidthThreshold kilobits per second.

Message #

A network bandwidth of %1 kilobits per second has been detected.  Minimum bandwidth to synchronize a roaming profile is set at %2 kilobits per second.

Fields #

NameDescription
MeasuredBandwidth UInt32
BandwidthThreshold UInt32

Event ID 1005: Delete cached profile ProfilePath since it is older than AgeLimitInDays days.

#
Channel
Diagnostic

Message #

Delete cached profile %1 since it is older than %2 days.

Fields #

NameDescription
ProfilePath UnicodeString
AgeLimitInDays UInt32

Event ID 1500: Windows cannot log you on because your profile cannot be loaded.

#
Channel
Application

Description

Windows cannot log you on because your profile cannot be loaded. Check that you are connected to the network, and that your network is functioning correctly.

Message #

Windows cannot log you on because your profile cannot be loaded. Check that you are connected to the network, and that your network is functioning correctly. 

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1501: Windows cannot create a temporary profile directory.

#
Channel
Application

Description

Windows cannot create a temporary profile directory. This problem may be caused by insufficient security rights.

Message #

Windows cannot create a temporary profile directory. This problem may be caused by insufficient security rights. 

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1502: Windows cannot load the locally stored profile.

#
Channel
Application

Description

Windows cannot load the locally stored profile. Possible causes of this error include insufficient security rights or a corrupt local profile.

Message #

Windows cannot load the locally stored profile. Possible causes of this error include insufficient security rights or a corrupt local profile. 

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1503: Windows cannot set security on your registry.

#
Channel
Application

Message #

Windows cannot set security on your registry. 

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1504: Windows cannot update your roaming profile completely.

#
Channel
Application

Description

Windows cannot update your roaming profile completely. Check previous events for more details.

Message #

Windows cannot update your roaming profile completely. Check previous events for more details.

Event ID 1505: Windows cannot load the user's profile but has logged you on with the default profile for the system.

#
Channel
Application

Message #

Windows cannot load the user's profile but has logged you on with the default profile for the system. 

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1506: Your roaming profile is not available.

#
Channel
Application

Description

Your roaming profile is not available. You are logged on with the locally stored profile. Changes to the profile will not be copied to the server. Possible causes of this error include network problems or insufficient security rights. DETAIL - Error

Message #

Your roaming profile is not available. You are logged on with the locally stored profile. Changes to the profile will not be copied to the server. Possible causes of this error include network problems or insufficient security rights.  

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1508: Windows was unable to load the registry.

#
Channel
Application

Description

Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights.

Message #

Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. 

 DETAIL - %1 for %2

Fields #

NameDescription
Error UnicodeString
File UnicodeString

Event ID 1509: Windows was unable to load File.

#
Channel
Application

Message #

Windows was unable to load %1.

Fields #

NameDescription
File UnicodeString
Status UInt32NTSTATUS reference
MachineKeys UnicodeString
UserKeys UnicodeString

Event ID 1510: Windows cannot load your profile because it appears to be corrupted.

#
Channel
Application

Event ID 1511: Windows cannot find the local profile and is logging you on with a temporary profile.

#
Channel
Application
Collection Priority
Recommended (Microsoft-WEF)

Description

Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off.

Message #

Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

  • Potential Exploitation of CVE-2022-21919 or CVE-2021-34484 for LPE source low: Detects potential exploitation attempts of CVE-2022-21919 or CVE-2021-34484 leading to local privilege escalation via the User Profile Service. During exploitation of this vulnerability, two logs (Provider_Name: Microsoft-Windows-User Profiles Service) with EventID 1511 and 1515 are created (EventID 1515 may generate many false positives). Additionally, the directory \Users\TEMP may be created during exploitation. This behavior was observed on Windows Server 2008.

Event ID 1512: Windows cannot unload your registry file.

#
Channel
Application

Description

Windows cannot unload your registry file. The memory used by the registry has not been freed. This problem is often caused by services running as a user account. Try configuring services to run in either the LocalService or NetworkService account. DETAIL - Error

Message #

Windows cannot unload your registry file. The memory used by the registry has not been freed. This problem is often caused by services running as a user account. Try configuring services to run in either the LocalService or NetworkService account. 

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1513: Windows cannot copy your profile because it contains encrypted files or directories.

#
Channel
Application

Description

Windows cannot copy your profile because it contains encrypted files or directories. The keys to decrypt the files or directories are also stored in the profile and are not available now. Decrypt the files and try again.

Message #

Windows cannot copy your profile because it contains encrypted files or directories. The keys to decrypt the files or directories are also stored in the profile and are not available now. Decrypt the files and try again.

Event ID 1514: The roaming profile path File is too long.

#
Channel
Application

Description

The roaming profile path File is too long. Windows is logging you on with a default profile.

Message #

The roaming profile path %1 is too long. Windows is logging you on with a default profile.

Fields #

NameDescription
File UnicodeString

Event ID 1515: Windows has backed up this user profile.

#
Channel
Application

Description

Windows has backed up this user profile. Windows will automatically try to use the backup profile the next time this user logs on.

Message #

Windows has backed up this user profile. Windows will automatically try to use the backup profile the next time this user logs on.

Event ID 1517: Windows saved user UserSid registry while an application or service was still using the registry when the user logged off.

#
Channel
Application

Description

Windows saved user UserSid registry while an application or service was still using the registry when the user logged off. The memory used by the user registry has not been freed. The registry will be unloaded when it is no longer in use. This error may be caused by services running as a user account. Try configuring services to run in either the LocalService or NetworkService account.

Message #

Windows saved user %1 registry while an application or service was still using the registry when the user logged off. The memory used by the user registry has not been freed. The registry will be unloaded when it is no longer in use. 

 This error may be caused by services running as a user account. Try configuring services to run in either the LocalService or NetworkService account.

Fields #

NameDescription
UserSid UnicodeString

Event ID 1518: Windows cannot create a local profile and is logging you on with a temporary profile.

#
Channel
Application
Collection Priority
Recommended (Microsoft-WEF)

Description

Windows cannot create a local profile and is logging you on with a temporary profile. This profile will be deleted when you log off. This problem may be caused by incorrect file system permissions or network problems.

Message #

Windows cannot create a local profile and is logging you on with a temporary profile. This profile will be deleted when you log off. This problem may be caused by incorrect file system permissions or network problems.

Event ID 1519: Windows cannot locate your roaming mandatory profile and is attempting to log you on with your local profile.

#
Channel
Application

Description

Windows cannot locate your roaming mandatory profile and is attempting to log you on with your local profile. This error may be caused by incorrect file system permissions or network problems.

Message #

Windows cannot locate your roaming mandatory profile and is attempting to log you on with your local profile. This error may be caused by incorrect file system permissions or network problems. 

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1520: Windows cannot log you on because your roaming mandatory profile is not available.

#
Channel
Application

Description

Windows cannot log you on because your roaming mandatory profile is not available. This error may be caused by incorrect file system permissions or network problems.

Message #

Windows cannot log you on because your roaming mandatory profile is not available. This error may be caused by incorrect file system permissions or network problems. 

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1521: Windows cannot locate the server copy of your roaming profile and is attempting to log you on with your local profile.

#
Channel
Application

Description

Windows cannot locate the server copy of your roaming profile and is attempting to log you on with your local profile. Changes to the profile will not be copied to the server when you log off. This error may be caused by network problems or insufficient security rights. DETAIL - Error

Message #

Windows cannot locate the server copy of your roaming profile and is attempting to log you on with your local profile. Changes to the profile will not be copied to the server when you log off. This error may be caused by network problems or insufficient security rights. 

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1522: Windows cannot locate your roaming profile (read only) and is attempting to log you on with your local profile.

#
Channel
Application

Description

Windows cannot locate your roaming profile (read only) and is attempting to log you on with your local profile. This error may be caused by network problems or insufficient security rights.

Message #

Windows cannot locate your roaming profile (read only) and is attempting to log you on with your local profile. This error may be caused by network problems or insufficient security rights. 

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1523: Your roaming profile (read only) is not available.

#
Channel
Application

Description

Your roaming profile (read only) is not available. You are logged on with the locally stored profile. This error may be caused by incorrect file system permissions or network problems.

Message #

Your roaming profile (read only) is not available. You are logged on with the locally stored profile. This error may be caused by incorrect file system permissions or network problems.  

 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1524: Windows cannot unload your classes registry file - it is still in use by other applications or services.

#
Channel
Application

Description

Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Message #

Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event ID 1525: Windows has detected that Automatic Offline Caching is enabled on the Roaming Profile share - to avoid potential profile corruption, Offline Cachin...

#
Channel
Application

Description

Windows has detected that Automatic Offline Caching is enabled on the Roaming Profile share - to avoid potential profile corruption, Offline Caching must be set to manual or disabled on shares where roaming user profiles are stored.

Message #

Windows has detected that Automatic Offline Caching is enabled on the Roaming Profile share - to avoid potential profile corruption, Offline Caching must be set to manual or disabled on shares where roaming user profiles are stored.

Event ID 1526: Windows could not load your roaming profile and is attempting to log you on with your local profile.

#
Channel
Application

Description

Windows could not load your roaming profile and is attempting to log you on with your local profile. Changes to the profile will not be copied to the server when you log off. Windows could not load your profile because a server copy of the profile folder already exists that does not have the correct security. Either the current user or the Administrators group must be the owner of the folder.

Message #

Windows could not load your roaming profile and is attempting to log you on with your local profile. Changes to the profile will not be copied to the server when you log off. Windows could not load your profile because a server copy of the profile folder already exists that does not have the correct security. Either the current user or the Administrators group must be the owner of the folder.

Event ID 1527: Windows failed to initialize user profiles.

#
Channel
Application

Description

Windows failed to initialize user profiles. Non-console users will be unable to log on.

Message #

Windows failed to initialize user profiles. Non-console users will be unable to log on.

Event ID 1529: Roaming user profiles across forests are disabled.

#
Channel
Application

Description

Roaming user profiles across forests are disabled. Windows did not load your roaming profile and is logging you on with a local profile. Changes to the profile will not be copied to the server when you log off.

Message #

Roaming user profiles across forests are disabled. Windows did not load your roaming profile and is logging you on with a local profile. Changes to the profile will not be copied to the server when you log off.

Event ID 1530: Windows detected your registry file is still in use by other applications or services.

#
Channel
Application
Level
Warning

Description

Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. No user action is required. DETAIL - Detail

Message #

Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. No user action is required.  

 DETAIL - 
 %1

Fields #

NameDescription
Detail

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "guid": "89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845",
    "event_source_name": "",
    "event_id": 1530,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2013-10-23T17:27:30.004750+00:00",
    "event_record_id": 170,
    "correlation": {},
    "execution": {
      "process_id": 916,
      "thread_id": 928
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "EVENT_HIVE_LEAK",
    "Data": {
      "Name": "Detail",
      "Value": "1 user registry handles leaked from \\Registry\\User\\S-1-5-21-3463664321-2923530833-3546627382-1000:\nProcess 432 (\\Device\\HarddiskVolume2\\Windows\\System32\\winlogon.exe) has opened key \\REGISTRY\\USER\\S-1-5-21-3463664321-2923530833-3546627382-1000\n"
    }
  },
  "message": "Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. No user action is required.  \n\n DETAIL - \n EVENT_HIVE_LEAK"
}

Example keys not documented in the fields table: Data, Name

References #

Event ID 1531: The User Profile Service has started successfully.

#
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "guid": "{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}",
    "event_source_name": "",
    "event_id": 1531,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T16:32:54.0483762+00:00",
    "event_record_id": 711,
    "correlation": {},
    "execution": {
      "process_id": 1956,
      "thread_id": 2036
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The User Profile Service has started successfully.  \r\n\r\n"
}

Event ID 1532: The User Profile Service has stopped.

#
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "guid": "{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}",
    "event_source_name": "",
    "event_id": 1532,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:22:34.5310830+00:00",
    "event_record_id": 1013,
    "correlation": {},
    "execution": {
      "process_id": 1852,
      "thread_id": 1928
    },
    "channel": "Application",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The User Profile Service has stopped.  \r\n\r\n"
}

Event ID 1533: Windows cannot delete the profile directory Folder.

#
Channel
Application

Description

Windows cannot delete the profile directory Folder. This error may be caused by files in this directory being used by another program.

Message #

Windows cannot delete the profile directory %1. This error may be caused by files in this directory being used by another program. 

 DETAIL - %2

Fields #

NameDescription
Folder UnicodeString
Error UnicodeString

Event ID 1534: Profile notification of event Event for component Component failed, error code is Error.

#
Channel
Application

Message #

Profile notification of event %1 for component %2 failed, error code is %3.

Fields #

NameDescription
Event UnicodeString
Component UnicodeString
Error UnicodeString

Event ID 1535: Successfully suspended folder "Folder".

#
Channel
Application

Message #

Successfully suspended folder "%1"

Fields #

NameDescription
Folder UnicodeString

Event ID 1536: Successfully unsuspended folder "Folder".

#
Channel
Application

Message #

Successfully unsuspended folder "%1"

Fields #

NameDescription
Folder UnicodeString

Event ID 1537: Failed to suspend folder "Folder" DETAIL - Error.

#
Channel
Application

Description

Failed to suspend folder "Folder".

Message #

Failed to suspend folder "%1"
 DETAIL - %2

Fields #

NameDescription
Folder UnicodeString
Error UnicodeString

Event ID 1538: Failed to unsuspend folder "Folder" DETAIL - Error.

#
Channel
Application

Description

Failed to unsuspend folder "Folder".

Message #

Failed to unsuspend folder "%1"
 DETAIL - %2

Fields #

NameDescription
Folder UnicodeString
Error UnicodeString

Event ID 1539: Failed to sync folder "Folder" DETAIL - Error.

#
Channel
Application

Description

Failed to sync folder "Folder".

Message #

Failed to sync folder "%1"
 DETAIL - %2

Fields #

NameDescription
Folder UnicodeString
Error UnicodeString

Event ID 1540: Your roaming profile is not synchronized correctly with the server.

#
Channel
Application

Description

Your roaming profile is not synchronized correctly with the server. Windows will load your previously-saved local profile instead. See the previous events for details.

Message #

Your roaming profile is not synchronized correctly with the server. Windows will load your previously-saved local profile instead. See the previous events for details.

Event ID 1541: Failed to apply CSC suspend policy.

#
Channel
Application

Description

Failed to apply CSC suspend policy. Cannot connect to CSC service.

Message #

Failed to apply CSC suspend policy. Cannot connect to CSC service.
 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1542: Windows cannot load classes registry file.

#
Channel
Application

Message #

Windows cannot load classes registry file.
 DETAIL - %1

Fields #

NameDescription
Error UnicodeString

Event ID 1543: A slow network connection is detected for the roaming profile Folder.

#
Channel
Application

Description

A slow network connection is detected for the roaming profile Folder. It will not be synchronized with the profile on this computer.

Message #

A slow network connection is detected for the roaming profile %1. It will not be synchronized with the profile on this computer.

Fields #

NameDescription
Folder UnicodeString

Event ID 1544: Windows cannot back up a ProfileList entry because one already exists for this user.

#
Channel
Application

Description

Windows cannot back up a ProfileList entry because one already exists for this user. Only the existing backup entry will be kept in the ProfileList. Future logons will restore the ProfileList entry from the existing backup entry.

Message #

Windows cannot back up a ProfileList entry because one already exists for this user. Only the existing backup entry will be kept in the ProfileList. Future logons will restore the ProfileList entry from the existing backup entry.

Event ID 1545: User hive is loaded by another process (File Lock).

#
Channel
Application

Description

User hive is loaded by another process (File Lock). Process name: InterferingImageName, PID: InterferingPID, ProfSvc PID: ProfsvcPID.

Message #

User hive is loaded by another process (File Lock). Process name: %1, PID: %2, ProfSvc PID: %3.

Fields #

NameDescription
InterferingImageName UnicodeString
InterferingPID UInt32
ProfsvcPID UInt32

Event ID 1552: User hive is loaded by another process (Registry Lock) Process name: InterferingImageName, PID: InterferingPID, ProfSvc PID: ProfsvcPID.

#
Channel
Application

Message #

User hive is loaded by another process (Registry Lock) Process name: %1, PID: %2, ProfSvc PID: %3.

Fields #

NameDescription
InterferingImageName UnicodeString
InterferingPID UInt32
ProfsvcPID UInt32

Event ID 1073743340: Windows unloaded user {User} registry when it received a notification that no other applications or services were using the profile.

#
Channel
Operational

Fields #

NameDescription
User

Event ID 1073743341: Windows saved user {User} registry while an application or service was still using the registry when the user logged off.

#
Channel
Operational

Message #

Windows saved user {User} registry while an application or service was still using the registry when the user logged off. The memory used by the user registry has not been freed. The registry will be unloaded when it is no longer in use.  This error may be caused by services running as a user account. Try configuring services to run in either the LocalService or NetworkService account.

Fields #

NameDescription
User

Event ID 1073743355: The User Profile Service has started successfully.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "event_id": 1531,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T19:31:56.9024507+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1073743356: The User Profile Service has stopped.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-User Profiles Service",
    "event_id": 1532,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T19:31:32.4740949+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1073743359: Successfully suspended folder '{Folder}'.

#
Channel
Operational

Fields #

NameDescription
Folder

Event ID 1073743360: Successfully unsuspended folder '{Folder}'.

#
Channel
Operational

Fields #

NameDescription
Folder

Event ID 2147485172: Windows cannot unload your classes registry file - it is still in use by other applications or services.

#
Channel
Operational

Description

Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Message #

Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event ID 2147485173: Windows has detected that Automatic Offline Caching is enabled on the Roaming Profile share - to avoid potential profile corruption; Offline Cachin...

#
Channel
Operational

Message #

Windows has detected that Automatic Offline Caching is enabled on the Roaming Profile share - to avoid potential profile corruption; Offline Caching must be set to manual or disabled on shares where roaming user profiles are stored.

Event ID 2147485178: Windows detected your registry file is still in use by other applications or services.

#
Channel
Operational

Message #

Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.   DETAIL -  {Detail}

Fields #

NameDescription
Detail

Event ID 2147485182: Profile notification of event {Event} for component {Component} failed; error code is {Error}.

#
Channel
Operational

Fields #

NameDescription
Event
Component
Error

Event ID 2147485188: Your roaming profile is not synchronized correctly with the server.

#
Channel
Operational

Description

Your roaming profile is not synchronized correctly with the server. Windows will load your previously-saved local profile instead. See the previous events for details.

Message #

Your roaming profile is not synchronized correctly with the server. Windows will load your previously-saved local profile instead. See the previous events for details.

Event ID 3221226972: Windows cannot log you on because your profile cannot be loaded.

#
Channel
Operational

Description

Windows cannot log you on because your profile cannot be loaded. Check that you are connected to the network; and that your network is functioning correctly. DETAIL - {Error}.

Message #

Windows cannot log you on because your profile cannot be loaded. Check that you are connected to the network; and that your network is functioning correctly.  DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226973: Windows cannot create a temporary profile directory.

#
Channel
Operational

Description

Windows cannot create a temporary profile directory. This problem may be caused by insufficient security rights. DETAIL - {Error}.

Message #

Windows cannot create a temporary profile directory. This problem may be caused by insufficient security rights.  DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226974: Windows cannot load the locally stored profile.

#
Channel
Operational

Description

Windows cannot load the locally stored profile. Possible causes of this error include insufficient security rights or a corrupt local profile. DETAIL - {Error}.

Message #

Windows cannot load the locally stored profile. Possible causes of this error include insufficient security rights or a corrupt local profile.  DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226975: Windows cannot set security on your registry.

#
Channel
Operational

Description

Windows cannot set security on your registry. DETAIL - {Error}.

Message #

Windows cannot set security on your registry.  DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226976: Windows Windows cannot update your roaming profile completely.

#
Channel
Operational

Description

Windows Windows cannot update your roaming profile completely. Check previous events for more details.

Message #

Windows Windows cannot update your roaming profile completely. Check previous events for more details.

Event ID 3221226977: Windows cannot load the user's profile but has logged you on with the default profile for the system.

#
Channel
Operational

Description

Windows cannot load the user's profile but has logged you on with the default profile for the system. DETAIL - {Error}.

Message #

Windows cannot load the user's profile but has logged you on with the default profile for the system.  DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226978: Your roaming profile is not available.

#
Channel
Operational

Message #

Your roaming profile is not available. You are logged on with the locally stored profile. Changes to the profile will not be copied to the server. Possible causes of this error include network problems or insufficient security rights.   DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226980: Windows was unable to load the registry.

#
Channel
Operational

Description

Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. DETAIL - {Error} for {File}.

Message #

Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights.  DETAIL - {Error} for {File}

Fields #

NameDescription
Error
File

Event ID 3221226982: Windows cannot load your profile because it appears to be corrupted.

#
Channel
Operational

Event ID 3221226983: Windows cannot find the local profile and is logging you on with a temporary profile.

#
Channel
Operational

Description

Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off.

Message #

Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off.

Event ID 3221226984: Windows cannot unload your registry file.

#
Channel
Operational

Message #

Windows cannot unload your registry file. The memory used by the registry has not been freed. This problem is often caused by services running as a user account. Try configuring services to run in either the LocalService or NetworkService account.  DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226985: Windows cannot copy your profile because it contains encrypted files or directories.

#
Channel
Operational

Message #

Windows cannot copy your profile because it contains encrypted files or directories. The keys to decrypt the files or directories are also stored in the profile and are not available now. Decrypt the files and try again.

Event ID 3221226986: The roaming profile path {File} is too long.

#
Channel
Operational

Description

The roaming profile path {File} is too long. Windows is logging you on with a default profile.

Message #

The roaming profile path {File} is too long. Windows is logging you on with a default profile.

Fields #

NameDescription
File

Event ID 3221226987: Windows has backed up this user profile.

#
Channel
Operational

Description

Windows has backed up this user profile. Windows will automatically try to use the backup profile the next time this user logs on.

Message #

Windows has backed up this user profile. Windows will automatically try to use the backup profile the next time this user logs on.

Event ID 3221226990: Windows cannot create a local profile and is logging you on with a temporary profile.

#
Channel
Operational

Message #

Windows cannot create a local profile and is logging you on with a temporary profile. This profile will be deleted when you log off. This problem may be caused by incorrect file system permissions or network problems.

Event ID 3221226991: Windows cannot locate your roaming mandatory profile and is attempting to log you on with your local profile.

#
Channel
Operational

Message #

Windows cannot locate your roaming mandatory profile and is attempting to log you on with your local profile. This error may be caused by incorrect file system permissions or network problems.  DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226992: Windows cannot log you on because your roaming mandatory profile is not available.

#
Channel
Operational

Description

Windows cannot log you on because your roaming mandatory profile is not available. This error may be caused by incorrect file system permissions or network problems. DETAIL - {Error}.

Message #

Windows cannot log you on because your roaming mandatory profile is not available. This error may be caused by incorrect file system permissions or network problems.  DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226993: Windows cannot locate the server copy of your roaming profile and is attempting to log you on with your local profile.

#
Channel
Operational

Message #

Windows cannot locate the server copy of your roaming profile and is attempting to log you on with your local profile. Changes to the profile will not be copied to the server when you log off. This error may be caused by network problems or insufficient security rights.  DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226994: Windows cannot locate your roaming profile (read only) and is attempting to log you on with your local profile.

#
Channel
Operational

Message #

Windows cannot locate your roaming profile (read only) and is attempting to log you on with your local profile. This error may be caused by network problems or insufficient security rights.  DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226995: Your roaming profile (read only) is not available.

#
Channel
Operational

Message #

Your roaming profile (read only) is not available. You are logged on with the locally stored profile. This error may be caused by incorrect file system permissions or network problems.   DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221226998: Windows could not load your roaming profile and is attempting to log you on with your local profile.

#
Channel
Operational

Message #

Windows could not load your roaming profile and is attempting to log you on with your local profile. Changes to the profile will not be copied to the server when you log off. Windows could not load your profile because a server copy of the profile folder already exists that does not have the correct security. Either the current user or the Administrators group must be the owner of the folder.

Event ID 3221226999: Windows failed to initialize user profiles.

#
Channel
Operational

Description

Windows failed to initialize user profiles. Non-console users will be unable to log on.

Message #

Windows failed to initialize user profiles. Non-console users will be unable to log on.

Event ID 3221227001: Roaming user profiles across forests are disabled.

#
Channel
Operational

Message #

Roaming user profiles across forests are disabled. Windows did not load your roaming profile and is logging you on with a local profile. Changes to the profile will not be copied to the server when you log off.

Event ID 3221227005: Windows cannot delete the profile directory {Directory}.

#
Channel
Operational

Description

Windows cannot delete the profile directory {Directory}. This error may be caused by files in this directory being used by another program. DETAIL - {Error}.

Message #

Windows cannot delete the profile directory {Directory}. This error may be caused by files in this directory being used by another program.  DETAIL - {Error}

Fields #

NameDescription
Directory
Error

Event ID 3221227009: Failed to suspend folder '{Folder}' DETAIL - {Error}.

#
Channel
Operational

Fields #

NameDescription
Folder
Error

Event ID 3221227010: Failed to unsuspend folder '{Folder}' DETAIL - {Error}.

#
Channel
Operational

Fields #

NameDescription
Folder
Error

Event ID 3221227011: Failed to sync folder '{Folder}' DETAIL - {Error}.

#
Channel
Operational

Fields #

NameDescription
Folder
Error

Event ID 3221227013: Failed to apply CSC suspend policy.

#
Channel
Operational

Description

Failed to apply CSC suspend policy. Cannot connect to CSC service. DETAIL - {Error}.

Message #

Failed to apply CSC suspend policy. Cannot connect to CSC service. DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221227014: Windows cannot load classes registry file.

#
Channel
Operational

Description

Windows cannot load classes registry file. DETAIL - {Error}.

Message #

Windows cannot load classes registry file. DETAIL - {Error}

Fields #

NameDescription
Error

Event ID 3221227015: A slow network connection is detected for the roaming profile {Path}.

#
Channel
Operational

Description

A slow network connection is detected for the roaming profile {Path}. It will not be synchronized with the profile on this computer.

Message #

A slow network connection is detected for the roaming profile {Path}. It will not be synchronized with the profile on this computer.

Fields #

NameDescription
Path

Provenance

ETW provider GUID 89b1e9f0-5aff-44a6-9b44-0a07a7ce5845

Defined in profsvc.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02