Microsoft-Windows-WDAG-PolicyEvaluator-CSP
11 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 300 | Microsoft Defender Application Guard CSP: Failed to set one or more settings : … | Operational | N |
| 301 | Microsoft Defender Application Guard CSP: delete value failed:ErrorCode. | Operational | N |
| 302 | Microsoft Defender Application Guard CSP: Feature Installation action failed … | Operational | N |
| 350 | Failed to start container service when Hvsi is turned on: ErrorCode. | Operational | N |
| 351 | Failed to merge policy to CSP current hive: ErrorCode. | Operational | N |
| 352 | At least one mandatory network isolation policy must be set, please configure: … | Operational | N |
| 353 | Failed to send alert message back to MDM server: ErrorCode. | Operational | N |
| 354 | Failed to update WDAG status | Operational | N |
| 355 | The system does not meet the minimal requirement: MissingPolicy. | Operational | N |
| 356 | Message SecondMessage. | Operational | Y |
| 357 | Failed to update WDAG Platform status | Operational | N |
Event ID 300: Microsoft Defender Application Guard CSP: Failed to set one or more settings : ErrorCode.
#Event ID 301: Microsoft Defender Application Guard CSP: delete value failed:ErrorCode.
#Event ID 302: Microsoft Defender Application Guard CSP: Feature Installation action failed because of missing dependency
#Event ID 350: Failed to start container service when Hvsi is turned on: ErrorCode.
#Event ID 351: Failed to merge policy to CSP current hive: ErrorCode.
#Event ID 352: At least one mandatory network isolation policy must be set, please configure: MissingPolicy.
#Event ID 353: Failed to send alert message back to MDM server: ErrorCode.
#Event ID 355: The system does not meet the minimal requirement: MissingPolicy.
#Event ID 356: Message SecondMessage.
#Description
Message SecondMessage
Message #
Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
SecondMessage UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WDAG-PolicyEvaluator-CSP",
"guid": "64A98C25-9E00-404E-84AD-6700DFE02529",
"event_source_name": "",
"event_id": 356,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-12T02:57:48.777469+00:00",
"event_record_id": 1466,
"correlation": {
"ActivityID": "16A85717-40AE-4833-8345-ED00771B7DAE"
},
"execution": {
"process_id": 7160,
"thread_id": 8604
},
"channel": "Microsoft-Windows-WDAG-PolicyEvaluator-CSP/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Message": "Published Notification of Policy Change",
"SecondMessage": ""
},
"message": ""
}
Event ID 357: Failed to update WDAG Platform status
#Description
Failed to update WDAG Platform status.
Message #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 64a98c25-9e00-404e-84ad-6700dfe02529
Defined in hvsievaluator.exe, which carries the event manifest.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02