Microsoft-Windows-WebAuth
37 events across 1 channel
Event ID 1000: AuthHost started at URL: <StartUrl> until matching termination URL: <TerminateUrl>.
#Event ID 1001: AuthHost started over at URL: <StartUrl>.
#Event ID 1002: AuthHost about to navigate (HTTP GET) to URL: <Url>.
#Event ID 1003: AuthHost about to navigate (HTTP POST) to URL: <Url>.
#Event ID 1010: AuthHost completed navigation to URL: <Url>.
#Event ID 1011: AuthHost completed document from URL: <Url>.
#Event ID 1020: AuthHost redirected to URL: <RedirectedUrl> from URL: <OriginalUrl> with HttpStatusCode: HttpStatusCode.
#Event ID 1021: AuthHost about to navigate (new window) to URL: <Url> from URL: <ReferrerUrl>.
#Event ID 1022: AuthHost about to navigate with delegation to URL: <Url>.
#Event ID 1023: AuthHost created new script engine at URL: <Url>.
#Event ID 1024: AuthHost about to launch URL: <Url> in browser from URL: <ReferrerUrl>.
#Event ID 1040: AuthHost terminated navigation at URL: <Url> matching termination URL: <TerminateUrl>.
#Event ID 1041: AuthHost terminated navigation with title: <Title> at URL: <Url> matching termination URL: <TerminateUrl>.
#Event ID 1043: AuthHost terminated navigation with HTTP POST data: <Post> at URL: <Url> matching termination URL: <TerminateUrl>.
#Event ID 1050: AuthHost encountered a navigation error at URL: <Url> with StatusCode: StatusCode.
#Description
AuthHost encountered a navigation error at URL: <Url> with StatusCode: StatusCode.
Message #
Fields #
| Name | Description |
|---|---|
Url UnicodeString | |
StatusCode HexInt32 | NTSTATUS reference |
Event ID 1051: AuthHost encountered a navigation error at URL: <Url> with HttpStatusCode: HttpStatusCode.
#Event ID 1100: AuthHost encountered a security problem: Problem and will retry the navigation.
#Event ID 1101: AuthHost encountered a security problem: StatusCode and will abort the navigation.
#Description
AuthHost encountered a security problem: StatusCode and will abort the navigation.
Message #
Fields #
| Name | Description |
|---|---|
StatusCode HexInt32 | NTSTATUS reference |
Event ID 1200: AuthHost allowed UrlAction: Action for URL: <Url>.
#Event ID 1201: AuthHost disallowed UrlAction: Action for URL: <Url>.
#Event ID 1202: AuthHost used default for UrlAction: Action for URL: <Url>.
#Event ID 1203: AuthHost prohibited UrlAction of Java permissions for URL: <Url>.
#Event ID 1204: AuthHost blocked credential prompt for URL: <Url>.
#Event ID 1205: AuthHost allowed credential silent logon for URL: <Url>.
#Event ID 1206: AuthHost allowed credential user prompt for URL: <Url>.
#Event ID 1300: AuthHost allowed UrlAction for ActiveX object: Clsid for URL: <Url>.
#Event ID 1301: AuthHost disallowed UrlAction for ActiveX object: Clsid for URL: <Url>.
#Event ID 1310: AuthHost allowed UrlAction for ActiveX object: Clsid for URL: <Url>.
#Event ID 1311: AuthHost disallowed UrlAction for ActiveX object: Clsid for URL: <Url>.
#Event ID 1400: AuthHost encountered Meta Tag: mswebdialog-title with content: <Content>.
#Event ID 1401: AuthHost resolved Meta Tag: mswebdialog-logo to URL: <Url>.
#Event ID 1402: AuthHost converted Meta Tag: mswebdialog-header-color with content: <Content> to value: ConvertedValue.
#Event ID 1403: AuthHost unable to convert Meta Tag: mswebdialog-header-color with content: <Content>.
#Event ID 1404: AuthHost resolved Meta Tag: mswebdialog-newwindowurl to URL: <Url>.
#Event ID 1405: AuthHost downloaded logo image from URL: <Url>.
#Event ID 1406: AuthHost encountered an error downloading logo image from URL: <Url> with Error: StatusCode.
#Description
AuthHost encountered an error downloading logo image from URL: <Url> with Error: StatusCode.
Message #
Fields #
| Name | Description |
|---|---|
Url UnicodeString | |
StatusCode HexInt32 | NTSTATUS reference |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID db6972b6-dddf-4820-84b1-2ed6ac0b96e5
Defined in AuthHost.exe, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02