Microsoft-Windows-WorkFolders

EventTitleChannelSampleRule
0The Windows Work Folders service is running.OperationalYN
1The Windows Work Folders service is stopping.OperationalYN
2A sync partnership was created between LocalFolder and ServerURI …OperationalNN
3A sync partnership between LocalFolder and ServerURI (ServerPartnershipId) was …OperationalNN
4Resuming sync between LocalFolder and ServerURI (ServerPartnershipId).OperationalNN
5Attempting to apply the following Work Folders Group Policy configuration.OperationalNN
6Attempting to remove the following Work Folders Group Policy configuration.OperationalNN
7Configuring Work Folders through Group Policy with the following options.OperationalNN
8Configuration of Work Folders through Group Policy succeeded.OperationalNN
9While applying Work Folders configuration through Group Policy, an existing Work …OperationalNN
10Configuration of Work Folders through Group Policy failed.OperationalNN
11There was a problem removing the Work Folders configuration when applying Group …OperationalNN
12There was a problem communicating with the Windows Work Folders service.OperationalNN
13There was a problem retrieving your Work Folders Group Policy configuration.OperationalNN
14There was a problem retrieving your current Work Folders configuration.OperationalNN
15There was a problem comparing the existing Work Folders configuration to the …OperationalNN
16Server discovery on DiscoveryURL found server ServerURL.OperationalNN
17Sync Share discovery succeeded.OperationalNN
18The discovery URL was found from the user's email address.OperationalNN
19This PC is incompatible with the Work Folders server and must be upgraded.OperationalNN
502A sync partnership between LocalFolder and ServerURI (ServerPartnershipId) …OperationalNN
503A sync partnership between LocalFolder and ServerURI (ServerPartnershipId) …OperationalNN
516Server discovery on DiscoveryURL failed with HResultStr.OperationalNN
517Sync Share discovery failed.OperationalNN
518Searching for a discovery URL from the user's email address failed.OperationalNN
1000Some files cannot be downloaded.OperationalNN
1001Failed to get an ADFS access token from the server.OperationalNN
1002Failed to get an ADFS refresh token from the server.OperationalNN
1100Work Folders sucessfully uploaded a file.DebugNN
1101Work Folders failed to upload a file.DebugNN
1102Work Folders sucessfully downloaded a file.DebugNN
1103Work Folders failed to download a file.DebugNN
1104Work Folders sucessfully uploaded a change batch.DebugNN
1105Work Folders failed to upload a change batch.DebugNN
1106Work Folders sucessfully downloaded a change batch.DebugNN
1107Work Folders failed to download a change batch.DebugNN
2000Work Folders couldn't detect changed files using the USN change journal, so it's …DebugNN
2001Sync started.DebugNN
2002Sync completed.DebugNN
2003Sync batch upload completed.DebugNN
2004Sync batch download completed.DebugNN
2005HTTP request failure.DebugNN
2006Work Folders skipped uploading a file because of an error.DebugNN
2007Work Folders will skip downloading files because the user doesn't have enough …DebugNN
2008Couldn't authenticate the user.DebugNN
2009Work Folders successfully synchronized an item.DebugNN
2010Work Folders failed to synchronize an item.DebugNN
2011Work Folders successfully updated the current state of an item.DebugNN
2012Work Folders failed to update the current state of an item.DebugNN
2013Work Folders detected a conflict on an item and decided a conflict resolution.DebugNN
2014task_02014DebugNN
2015task_02015DebugNN
2016Work Folders successfully fetched file content for a file.DebugNN
2017Work Folders failed to fetch file content for a file.DebugNN
2018Work Folders cancelled fetching file content for a file.DebugNN
2019Work Folders successfully removed file content from disk a file.DebugNN
2020Work Folders failed to remove file content from disk a file.DebugNN
2021Work Folders successfully repaired a broken file.DebugNN
2022Work Folders failed to repair a broken file.DebugNN
2023Work Folders could not find a broken file on the server.DebugNN
2024The on-demand file access setting has changed.DebugNN
2025The on-demand file access setting has changed.DebugNN
2026Work Folders successfully converted a file to enable on-demand functionality.DebugNN
2027Work Folders failed to convert a file to enable on-demand functionality.DebugNN
2100Sync failed.OperationalNN
2101Work Folders suspended sync.OperationalNN
2102Work Folders resumed syncing.OperationalNN
2103Work Folders sync stopped because the Enterprise ID for this PC was remotely …OperationalNN
2104Work Folders detected a database corruption and recovered.OperationalNN
2105Work Folders detected a database corruption and recovery failed.OperationalNN
2106Work Folders detected that the server database has been recreated.OperationalNN
2107Work Folders detected that an error occured that requires the database to be …OperationalNN
2108Work Folders synchronization metadata is stale.OperationalNN
2109The Work Folders synchronization metadata was created.OperationalNN
2110The Work Folders synchronization metadata could not be created.OperationalNN
2111The Work Folders synchronization metadata was deleted.OperationalNN
2112The Work Folders synchronization metadata could not be deleted.OperationalNN
2113Work Folders failed to update the current state of an item.OperationalNN
2114Work Folders failed to synchronize an item.OperationalNN
2115Work Folders detected a database version that is incompatible and recovered it.OperationalNN
2116Work Folders detected a database version that is incompatible and recovery …OperationalNN
2117Work Folders failed to connect with Cloud Files.OperationalNN
2118Work Folders failed to disconnect with Cloud Files.OperationalNN
2119Work Folders failed to register with Cloud Files.OperationalNN
2120Work Folders failed to unregister with Cloud Files.OperationalNN
8000Starting sync.AnalyticNN
8001Work Folders is looking for changed files.AnalyticNN
8002Starting to download files.AnalyticNN
8003Starting to upload files.AnalyticNN
8004Finished syncing.AnalyticNN
8005Starting reconciliation sync.AnalyticNN
8006Finished reconciliation sync.AnalyticNN
8007Starting sync knowledge upload.AnalyticNN
8008Starting data transfer for file download.AnalyticNN
8009Applying downloaded files.AnalyticNN
8010Starting sync knowledge download.AnalyticNN
8011Creating a change batch for upload.AnalyticNN
8012Starting data transfer for file upload.AnalyticNN
8013Work Folders successfully connected with Cloud Files.AnalyticNN
8014Work Folders successfully disconnected with Cloud Files.AnalyticNN
8015Work Folders successfully registered with Cloud Files.AnalyticNN
8016Work Folders successfully unregistered with Cloud Files.AnalyticNN
8017Work Folders detected files that cannot be uploaded.AnalyticNN
8018Work Folders file repair completed.AnalyticNN
8019Starting cleanup before reconciliation.AnalyticNN
8020Finished cleanup before reconciliation.AnalyticNN
9001Credentials required for the user.WHCNN
9002Work Folders detected a sync error.WHCNN
9003Work Folders detected a file error.WHCNN
9004Your PC doesn't comply with your organization's security policies.WHCNN

Event ID 0: The Windows Work Folders service is running.

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WorkFolders",
    "guid": "{34A3697E-0F10-4E48-AF3C-F869B5BABEBB}",
    "event_source_name": "",
    "event_id": 0,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T03:58:29.6144658+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 14616,
      "thread_id": 14340
    },
    "channel": "Microsoft-Windows-WorkFolders/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "The Windows Work Folders service is running."
}

Event ID 1: The Windows Work Folders service is stopping.

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WorkFolders",
    "guid": "{34A3697E-0F10-4E48-AF3C-F869B5BABEBB}",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T04:15:21.9924849+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 14616,
      "thread_id": 14340
    },
    "channel": "Microsoft-Windows-WorkFolders/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "The Windows Work Folders service is stopping."
}

Event ID 2: A sync partnership was created between LocalFolder and ServerURI (ServerPartnershipId).

#
Channel
Operational
Opcode
Info

Message #

A sync partnership was created between %1 and %2 (%3).

Fields #

NameDescription
LocalFolder UnicodeString
ServerURI UnicodeString
ServerPartnershipId UnicodeString

Event ID 3: A sync partnership between LocalFolder and ServerURI (ServerPartnershipId) was deleted.

#
Channel
Operational
Opcode
Info

Message #

A sync partnership between %1 and %2 (%3) was deleted.

Fields #

NameDescription
LocalFolder UnicodeString
ServerURI UnicodeString
ServerPartnershipId UnicodeString

Event ID 4: Resuming sync between LocalFolder and ServerURI (ServerPartnershipId).

#
Channel
Operational
Opcode
Info

Message #

Resuming sync between %1 and %2 (%3).

Fields #

NameDescription
LocalFolder UnicodeString
ServerURI UnicodeString
ServerPartnershipId UnicodeString

Event ID 5: Attempting to apply the following Work Folders Group Policy configuration.

#
Channel
Operational
Opcode
Info

Message #

Attempting to apply the following Work Folders Group Policy configuration:
Work Folders URL: %1
Force automatic setup: %2
Ghosting policy: %3

Fields #

NameDescription
SyncUrl UnicodeString
AutoProvision Boolean
GhostingPolicy Int32

Event ID 6: Attempting to remove the following Work Folders Group Policy configuration.

#
Channel
Operational
Opcode
Info

Message #

Attempting to remove the following Work Folders Group Policy configuration:
Discovery URL: %1 
Server URL: %2
Ghosting policy: %3

Fields #

NameDescription
DiscoveryUrl UnicodeString
ServerUrl UnicodeString
GhostingPolicy Int32

Event ID 7: Configuring Work Folders through Group Policy with the following options.

#
Channel
Operational
Opcode
Info

Message #

Configuring Work Folders through Group Policy with the following options:
Partnership ID: %1
Partnership type: %2
Discovery URL: %3
Server URL: %4
Ghosting policy: %5

Fields #

NameDescription
PartnershipId UnicodeString
PartnershipType UnicodeString
DiscoveryUrl UnicodeString
ServerUrl UnicodeString
GhostingPolicy Int32

Event ID 8: Configuration of Work Folders through Group Policy succeeded.

#
Channel
Operational
Opcode
Info

Event ID 9: While applying Work Folders configuration through Group Policy, an existing Work Folders configuration was found.

#
Channel
Operational
Opcode
Info

Message #

While applying Work Folders configuration through Group Policy, an existing Work Folders configuration was found. 
Discovery URL: %1 
Server URL: %2
Configured by policy: %3
Ghosting policy: %4

Fields #

NameDescription
DiscoveryUrl UnicodeString
ServerUrl UnicodeString
ConfiguredByPolicy Boolean
GhostingPolicy Int32

Event ID 10: Configuration of Work Folders through Group Policy failed.

#
Channel
Operational
Opcode
Info

Message #

Configuration of Work Folders through Group Policy failed. 
Error: %1.

Fields #

NameDescription
HResultStr UnicodeString
HResult Int32

Event ID 11: There was a problem removing the Work Folders configuration when applying Group Policy.

#
Channel
Operational
Opcode
Info

Message #

There was a problem removing the Work Folders configuration when applying Group Policy. 
Error: %1

Fields #

NameDescription
HResultStr UnicodeString
HResult Int32

Event ID 12: There was a problem communicating with the Windows Work Folders service.

#
Channel
Operational
Opcode
Info

Description

There was a problem communicating with the Windows Work Folders service. Confirm that this service is running.

Message #

There was a problem communicating with the Windows Work Folders service. Confirm that this service is running. 
Error: %1

Fields #

NameDescription
HResultStr UnicodeString
HResult Int32

Event ID 13: There was a problem retrieving your Work Folders Group Policy configuration.

#
Channel
Operational
Opcode
Info

Message #

There was a problem retrieving your Work Folders Group Policy configuration. 
Error: %1

Fields #

NameDescription
HResultStr UnicodeString
HResult Int32

Event ID 14: There was a problem retrieving your current Work Folders configuration.

#
Channel
Operational
Opcode
Info

Message #

There was a problem retrieving your current Work Folders configuration. 
Error: %1.

Fields #

NameDescription
HResultStr UnicodeString
HResult Int32

Event ID 15: There was a problem comparing the existing Work Folders configuration to the configuration being applied by Group Policy.

#
Channel
Operational
Opcode
Info

Message #

There was a problem comparing the existing Work Folders configuration to the configuration being applied by Group Policy. 
Error: %1.

Fields #

NameDescription
HResultStr UnicodeString
HResult Int32

Event ID 16: Server discovery on DiscoveryURL found server ServerURL.

#
Channel
Operational
Opcode
Info

Message #

Server discovery on %1 found server %2.

Fields #

NameDescription
DiscoveryURL UnicodeString
ServerURL UnicodeString

Event ID 17: Sync Share discovery succeeded.

#
Channel
Operational
Opcode
Info

Description

Sync Share discovery succeeded. Server URL: ServerURL; Partnership type: SyncTargetType; Server partnership id: ServerPartnershipId.

Message #

Sync Share discovery succeeded. Server URL: %1; Partnership type: %2; Server partnership id: %3

Fields #

NameDescription
ServerURL UnicodeString
SyncTargetType UnicodeString
ServerPartnershipId UnicodeString

Event ID 18: The discovery URL was found from the user's email address.

#
Channel
Operational
Opcode
Info

Description

The discovery URL was found from the user's email address. User's email address: UserEmail; Discovery URL DiscoveryURL.

Message #

The discovery URL was found from the user's email address. User's email address: %1; Discovery URL %2

Fields #

NameDescription
UserEmail UnicodeString
DiscoveryURL UnicodeString

Event ID 19: This PC is incompatible with the Work Folders server and must be upgraded.

#
Channel
Operational
Opcode
Info

Description

This PC is incompatible with the Work Folders server and must be upgraded. Please contact your administrator for instructions on upgrading your PC.

Message #

This PC is incompatible with the Work Folders server and must be upgraded. Please contact your administrator for instructions on upgrading your PC.

Fields #

NameDescription
ServerURL UnicodeString
SyncTargetType UnicodeString
ServerPartnershipId UnicodeString

Event ID 502: A sync partnership between LocalFolder and ServerURI (ServerPartnershipId) failed to create with HResultStr.

#
Channel
Operational
Opcode
Info

Message #

A sync partnership between %1 and %2 (%3) failed to create with %4.

Fields #

NameDescription
LocalFolder UnicodeString
ServerURI UnicodeString
ServerPartnershipId UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 503: A sync partnership between LocalFolder and ServerURI (ServerPartnershipId) failed to delete with HResultStr.

#
Channel
Operational
Opcode
Info

Message #

A sync partnership between %1 and %2 (%3) failed to delete with %4.

Fields #

NameDescription
LocalFolder UnicodeString
ServerURI UnicodeString
ServerPartnershipId UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 516: Server discovery on DiscoveryURL failed with HResultStr.

#
Channel
Operational
Opcode
Info

Message #

Server discovery on %1 failed with %2.

Fields #

NameDescription
DiscoveryURL UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 517: Sync Share discovery failed.

#
Channel
Operational
Opcode
Info

Description

Sync Share discovery failed. Server URL: ServerURL; Partnership type: SyncTargetType; Error: HResultStr.

Message #

Sync Share discovery failed. Server URL: %1; Partnership type: %2; Error: %3

Fields #

NameDescription
ServerURL UnicodeString
SyncTargetType UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 518: Searching for a discovery URL from the user's email address failed.

#
Channel
Operational
Opcode
Info

Description

Searching for a discovery URL from the user's email address failed. User's email address: UserEmail; Error: HResultStr.

Message #

Searching for a discovery URL from the user's email address failed. User's email address: %1; Error: %2

Fields #

NameDescription
UserEmail UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 1000: Some files cannot be downloaded.

#
Channel
Operational
Opcode
Info

Description

Some files cannot be downloaded. Make sure the drive for Path has at least SizeMB MB free.

Message #

Some files cannot be downloaded. Make sure the drive for %1 has at least %2 MB free.

Fields #

NameDescription
Path UnicodeString
SizeMB Int64

Event ID 1001: Failed to get an ADFS access token from the server.

#
Channel
Operational
Opcode
Info

Description

Failed to get an ADFS access token from the server. User: User. ADFS URI: StsUri. Error: HResultStr.

Message #

Failed to get an ADFS access token from the server. User: %1. ADFS URI: %2. Error: %3

Fields #

NameDescription
User UnicodeString
StsUri UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 1002: Failed to get an ADFS refresh token from the server.

#
Channel
Operational
Opcode
Info

Description

Failed to get an ADFS refresh token from the server. User: User. ADFS URI: StsUri. Error: HResultStr.

Message #

Failed to get an ADFS refresh token from the server. User: %1. ADFS URI: %2. Error: %3

Fields #

NameDescription
User UnicodeString
StsUri UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 1100: Work Folders sucessfully uploaded a file.

#
Channel
Debug
Opcode
Info

Description

Work Folders sucessfully uploaded a file. File name:FileName; Sync ID: SyncId.

Message #

Work Folders sucessfully uploaded a file. File name:%1; Sync ID: %2

Fields #

NameDescription
FileName UnicodeString
SyncId GUID
HResultStr UnicodeString
HResult Int32

Event ID 1101: Work Folders failed to upload a file.

#
Channel
Debug
Opcode
Info

Description

Work Folders failed to upload a file. File name:FileName; Sync ID: SyncId; Error: HResultStr.

Message #

Work Folders failed to upload a file. File name:%1; Sync ID: %2; Error: %3

Fields #

NameDescription
FileName UnicodeString
SyncId GUID
HResultStr UnicodeString
HResult Int32

Event ID 1102: Work Folders sucessfully downloaded a file.

#
Channel
Debug
Opcode
Info

Description

Work Folders sucessfully downloaded a file. File name:FileName; Sync ID: SyncId.

Message #

Work Folders sucessfully downloaded a file. File name:%1; Sync ID: %2

Fields #

NameDescription
FileName UnicodeString
SyncId GUID
HResultStr UnicodeString
HResult Int32

Event ID 1103: Work Folders failed to download a file.

#
Channel
Debug
Opcode
Info

Description

Work Folders failed to download a file. File name:FileName; Sync ID: SyncId; Error: HResultStr.

Message #

Work Folders failed to download a file. File name:%1; Sync ID: %2; Error: %3

Fields #

NameDescription
FileName UnicodeString
SyncId GUID
HResultStr UnicodeString
HResult Int32

Event ID 1104: Work Folders sucessfully uploaded a change batch.

#
Channel
Debug
Opcode
Info

Description

Work Folders sucessfully uploaded a change batch. Partnership ID:SyncPartnershipId.

Message #

Work Folders sucessfully uploaded a change batch. Partnership ID:%1

Fields #

NameDescription
SyncPartnershipId UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 1105: Work Folders failed to upload a change batch.

#
Channel
Debug
Opcode
Info

Description

Work Folders failed to upload a change batch. Partnership ID:SyncPartnershipId; Error: HResultStr.

Message #

Work Folders failed to upload a change batch. Partnership ID:%1; Error: %2

Fields #

NameDescription
SyncPartnershipId UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 1106: Work Folders sucessfully downloaded a change batch.

#
Channel
Debug
Opcode
Info

Description

Work Folders sucessfully downloaded a change batch. Partnership ID:SyncPartnershipId.

Message #

Work Folders sucessfully downloaded a change batch. Partnership ID:%1

Fields #

NameDescription
SyncPartnershipId UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 1107: Work Folders failed to download a change batch.

#
Channel
Debug
Opcode
Info

Description

Work Folders failed to download a change batch. Partnership ID:SyncPartnershipId; Error: HResultStr.

Message #

Work Folders failed to download a change batch. Partnership ID:%1; Error: %2

Fields #

NameDescription
SyncPartnershipId UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2000: Work Folders couldn't detect changed files using the USN change journal, so it's scanning all files for changes.

#
Channel
Debug
Opcode
Info

Description

Work Folders couldn't detect changed files using the USN change journal, so it's scanning all files for changes. No action is required. Path: LocalReplicaRoot.

Message #

Work Folders couldn't detect changed files using the USN change journal, so it's scanning all files for changes. No action is required. Path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 2001: Sync started.

#
Channel
Debug
Opcode
Info

Description

Sync started. URI: SessionUri.

Message #

Sync started. URI: %1

Fields #

NameDescription
SessionUri UnicodeString

Event ID 2002: Sync completed.

#
Channel
Debug
Opcode
Info

Description

Sync completed. URI: SessionUri.

Message #

Sync completed.  URI: %1

Fields #

NameDescription
SessionUri UnicodeString

Event ID 2003: Sync batch upload completed.

#
Channel
Debug
Opcode
Info

Message #

Sync batch upload completed.

Uploaded %1 file(s) (%2 bytes).
Failed %3 file(s) (%4 bytes).
Elapsed time: %5 seconds.
Rate: %6 KBps.

Fields #

NameDescription
SuccessFileCount Int32
SuccessDataSize Int64
FailedFileCount Int32
FailedDataSize Int64
TotalBatchTime Int32
Rate Float

Event ID 2004: Sync batch download completed.

#
Channel
Debug
Opcode
Info

Message #

Sync batch download completed.

Downloaded %1 file(s) (%2 bytes).
Failed %3 file(s).
Elapsed time: %5 seconds.
Rate: %6 KBps.

Fields #

NameDescription
SuccessFileCount Int32
SuccessDataSize Int64
FailedFileCount Int32
FailedDataSize Int64
TotalBatchTime Int32
Rate Float

Event ID 2005: HTTP request failure.

#
Channel
Debug
Opcode
Info

Message #

HTTP request failure.

URI: %1 
Verb: %2 
Headers: %3 
Body Length: %4 
HTTP Response: %5 
Server HRESULT: %6

Fields #

NameDescription
Uri UnicodeString
Verb UnicodeString
Headers UnicodeString
BodyLength Int32
HttpResponse Int32
ServerCodeStr UnicodeString
HResult Int32

Event ID 2006: Work Folders skipped uploading a file because of an error.

#
Channel
Debug
Opcode
Info

Description

Work Folders skipped uploading a file because of an error. Sync ID: SyncId; Error: HResultStr.

Message #

Work Folders skipped uploading a file because of an error. Sync ID: %1; Error: %2

Fields #

NameDescription
SyncId GUID
HResultStr UnicodeString
HResult Int32

Event ID 2007: Work Folders will skip downloading files because the user doesn't have enough free space on the drive where Work Folders is located.

#
Channel
Debug
Opcode
Info

Description

Work Folders will skip downloading files because the user doesn't have enough free space on the drive where Work Folders is located. User: Username.

Message #

Work Folders will skip downloading files because the user doesn't have enough free space on the drive where Work Folders is located. User: %1

Fields #

NameDescription
Username UnicodeString

Event ID 2008: Couldn't authenticate the user.

#
Channel
Debug
Opcode
Info

Description

Couldn't authenticate the user. User: Username.

Message #

Couldn't authenticate the user. User: %1

Fields #

NameDescription
Username UnicodeString

Event ID 2009: Work Folders successfully synchronized an item.

#
Channel
Debug
Opcode
Info

Description

Work Folders successfully synchronized an item. Item: ItemName; Sync ID: SyncGID; Sync action: Action.

Message #

Work Folders successfully synchronized an item. Item: %1; Sync ID: %2; Sync action: %3

Fields #

NameDescription
ItemName UnicodeString
SyncGID GUID
Action UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2010: Work Folders failed to synchronize an item.

#
Channel
Debug
Opcode
Info

Description

Work Folders failed to synchronize an item. Item: ItemName; Sync ID: SyncGID; Sync action: Action; Error code: HResultStr.

Message #

Work Folders failed to synchronize an item. Item: %1; Sync ID: %2; Sync action: %3; Error code: %4

Fields #

NameDescription
ItemName UnicodeString
SyncGID GUID
Action UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2011: Work Folders successfully updated the current state of an item.

#
Channel
Debug
Opcode
Info

Description

Work Folders successfully updated the current state of an item. Item: ItemName; Sync ID: SyncGID; Update action: Action.

Message #

Work Folders successfully updated the current state of an item. Item: %1; Sync ID: %2; Update action: %3

Fields #

NameDescription
ItemName UnicodeString
SyncGID GUID
Action UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2012: Work Folders failed to update the current state of an item.

#
Channel
Debug
Opcode
Info

Description

Work Folders failed to update the current state of an item. Item: ItemName; Sync ID: SyncGID; Update action: Action; Error code: HResultStr.

Message #

Work Folders failed to update the current state of an item. Item: %1; Sync ID: %2; Update action: %3; Error code: %4

Fields #

NameDescription
ItemName UnicodeString
SyncGID GUID
Action UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2013: Work Folders detected a conflict on an item and decided a conflict resolution.

#
Channel
Debug
Opcode
Info

Description

Work Folders detected a conflict on an item and decided a conflict resolution. Concurrency conflict: ConcurrencyConflict; Source item name: SourceItemName; Source sync ID: SourceSyncGID; Destination item name: DestinationItemName; Destination sync ID: DestinationSyncGID; Data winner: DataWinner; Namespace winner: NamespaceWinner; Attributes winner: AttributesWinner; Tie breaker winner: TieBreakerWinner

Message #

Work Folders detected a conflict on an item and decided a conflict resolution. Concurrency conflict: %1; Source item name: %2; Source sync ID: %3; Destination item name: %4; Destination sync ID: %5; Data winner: %6; Namespace winner: %7; Attributes winner: %8; Tie breaker winner: %9

Fields #

NameDescription
ConcurrencyConflict Boolean
SourceItemName UnicodeString
SourceSyncGID GUID
DestinationItemName UnicodeString
DestinationSyncGID GUID
DataWinner UnicodeString
NamespaceWinner UnicodeString
AttributesWinner UnicodeString
TieBreakerWinner UnicodeString

Event ID 2014: task_02014

#
Channel
Debug
Opcode
Info

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 2015: task_02015

#
Channel
Debug
Opcode
Info

Fields #

NameDescription
LocalReplicaRoot UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2016: Work Folders successfully fetched file content for a file.

#
Channel
Debug
Opcode
Info

Description

Work Folders successfully fetched file content for a file. File name: FileName.

Message #

Work Folders successfully fetched file content for a file. File name: %1

Fields #

NameDescription
FileName UnicodeString

Event ID 2017: Work Folders failed to fetch file content for a file.

#
Channel
Debug
Opcode
Info

Description

Work Folders failed to fetch file content for a file. File name: FileName. Error: HResultStr.

Message #

Work Folders failed to fetch file content for a file. File name: %1. Error: %2

Fields #

NameDescription
FileName UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2018: Work Folders cancelled fetching file content for a file.

#
Channel
Debug
Opcode
Info

Description

Work Folders cancelled fetching file content for a file. File name: FileName.

Message #

Work Folders cancelled fetching file content for a file. File name: %1

Fields #

NameDescription
FileName UnicodeString

Event ID 2019: Work Folders successfully removed file content from disk a file.

#
Channel
Debug
Opcode
Info

Description

Work Folders successfully removed file content from disk a file. File name: FileName.

Message #

Work Folders successfully removed file content from disk a file. File name: %1

Fields #

NameDescription
FileName UnicodeString

Event ID 2020: Work Folders failed to remove file content from disk a file.

#
Channel
Debug
Opcode
Info

Description

Work Folders failed to remove file content from disk a file. File name: FileName. Error: HResultStr.

Message #

Work Folders failed to remove file content from disk a file. File name: %1. Error: %2

Fields #

NameDescription
FileName UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2021: Work Folders successfully repaired a broken file.

#
Channel
Debug
Opcode
Info

Description

Work Folders successfully repaired a broken file. File name: FileName.

Message #

Work Folders successfully repaired a broken file. File name: %1

Fields #

NameDescription
FileName UnicodeString

Event ID 2022: Work Folders failed to repair a broken file.

#
Channel
Debug
Opcode
Info

Description

Work Folders failed to repair a broken file. File name: FileName. Error: HResultStr.

Message #

Work Folders failed to repair a broken file. File name: %1. Error: %2

Fields #

NameDescription
FileName UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2023: Work Folders could not find a broken file on the server.

#
Channel
Debug
Opcode
Info

Description

Work Folders could not find a broken file on the server. The broken file will be deleted. File name: FileName.

Message #

Work Folders could not find a broken file on the server. The broken file will be deleted. File name: %1

Fields #

NameDescription
FileName UnicodeString

Event ID 2024: The on-demand file access setting has changed.

#
Channel
Debug
Opcode
Info

Description

The on-demand file access setting has changed. On-demand file access is now Disabled.

Message #

The on-demand file access setting has changed. On-demand file access is now Disabled.

Event ID 2025: The on-demand file access setting has changed.

#
Channel
Debug
Opcode
Info

Description

The on-demand file access setting has changed. On-demand file access is now Enabled.

Message #

The on-demand file access setting has changed. On-demand file access is now Enabled.

Event ID 2026: Work Folders successfully converted a file to enable on-demand functionality.

#
Channel
Debug
Opcode
Info

Description

Work Folders successfully converted a file to enable on-demand functionality. File name: FileName.

Message #

Work Folders successfully converted a file to enable on-demand functionality. File name: %1

Fields #

NameDescription
FileName UnicodeString

Event ID 2027: Work Folders failed to convert a file to enable on-demand functionality.

#
Channel
Debug
Opcode
Info

Description

Work Folders failed to convert a file to enable on-demand functionality. File name: FileName. Error: HResultStr.

Message #

Work Folders failed to convert a file to enable on-demand functionality. File name: %1. Error: %2

Fields #

NameDescription
FileName UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2100: Sync failed.

#
Channel
Operational
Opcode
Info

Description

Sync failed. Work Folders path: LocalReplicaRoot; Error: HResultStr.

Message #

Sync failed. Work Folders path: %1; Error: %2

Fields #

NameDescription
LocalReplicaRoot UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2101: Work Folders suspended sync.

#
Channel
Operational
Opcode
Info

Description

Work Folders suspended sync. Partnership: SyncPartnershipId.

Message #

Work Folders suspended sync. Partnership: %1

Fields #

NameDescription
SyncPartnershipId UnicodeString

Event ID 2102: Work Folders resumed syncing.

#
Channel
Operational
Opcode
Info

Description

Work Folders resumed syncing. Partnership: SyncPartnershipId.

Message #

Work Folders resumed syncing. Partnership: %1

Fields #

NameDescription
SyncPartnershipId UnicodeString

Event ID 2103: Work Folders sync stopped because the Enterprise ID for this PC was remotely revoked by the issuing authority.

#
Channel
Operational
Opcode
Info

Description

Work Folders sync stopped because the Enterprise ID for this PC was remotely revoked by the issuing authority. Access to files in Work Folders is blocked on this PC. To resume syncing, in the Work Folders Control Panel, click Stop using Work Folders and then recreate the Work Folders synchronization partnership. Partnership: SyncPartnershipId

Message #

Work Folders sync stopped because the Enterprise ID for this PC was remotely revoked by the issuing authority. Access to files in Work Folders is blocked on this PC. To resume syncing, in the Work Folders Control Panel, click Stop using Work Folders and then recreate the Work Folders synchronization partnership. Partnership: %1

Fields #

NameDescription
SyncPartnershipId UnicodeString

Event ID 2104: Work Folders detected a database corruption and recovered.

#
Channel
Operational
Opcode
Info

Description

Work Folders detected a database corruption and recovered. Database path: DatabasePath.

Message #

Work Folders detected a database corruption and recovered. Database path: %1

Fields #

NameDescription
DatabasePath UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2105: Work Folders detected a database corruption and recovery failed.

#
Channel
Operational
Opcode
Info

Description

Work Folders detected a database corruption and recovery failed. Database path: DatabasePath; Error: HResultStr.

Message #

Work Folders detected a database corruption and recovery failed. Database path: %1; Error: %2

Fields #

NameDescription
DatabasePath UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2106: Work Folders detected that the server database has been recreated.

#
Channel
Operational
Opcode
Info

Description

Work Folders detected that the server database has been recreated. Local epoch: LocalEpoch; Server epoch: ServerEpoch.

Message #

Work Folders detected that the server database has been recreated. Local epoch: %1; Server epoch: %2

Fields #

NameDescription
LocalEpoch GUID
ServerEpoch GUID

Event ID 2107: Work Folders detected that an error occured that requires the database to be recreated.

#
Channel
Operational
Opcode
Info

Description

Work Folders detected that an error occured that requires the database to be recreated. Database path: DatabasePath; Error code: HResultStr.

Message #

Work Folders detected that an error occured that requires the database to be recreated. Database path: %1; Error code: %2

Fields #

NameDescription
DatabasePath UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2108: Work Folders synchronization metadata is stale.

#
Channel
Operational
Opcode
Info

Description

Work Folders synchronization metadata is stale. It will be automatically rebuild. Work Folders path: LocalReplicaRoot.

Message #

Work Folders synchronization metadata is stale. It will be automatically rebuild. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 2109: The Work Folders synchronization metadata was created.

#
Channel
Operational
Opcode
Info

Description

The Work Folders synchronization metadata was created. Work Folders path: LocalReplicaRoot.

Message #

The Work Folders synchronization metadata was created. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 2110: The Work Folders synchronization metadata could not be created.

#
Channel
Operational
Opcode
Info

Description

The Work Folders synchronization metadata could not be created. Work Folders path: LocalReplicaRoot; Error: HResultStr.

Message #

The Work Folders synchronization metadata could not be created. Work Folders path: %1; Error: %2

Fields #

NameDescription
LocalReplicaRoot UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2111: The Work Folders synchronization metadata was deleted.

#
Channel
Operational
Opcode
Info

Description

The Work Folders synchronization metadata was deleted. Work Folders path: LocalReplicaRoot.

Message #

The Work Folders synchronization metadata was deleted. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 2112: The Work Folders synchronization metadata could not be deleted.

#
Channel
Operational
Opcode
Info

Description

The Work Folders synchronization metadata could not be deleted. Work Folders path: LocalReplicaRoot; Error: HResultStr.

Message #

The Work Folders synchronization metadata could not be deleted. Work Folders path: %1; Error: %2

Fields #

NameDescription
LocalReplicaRoot UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2113: Work Folders failed to update the current state of an item.

#
Channel
Operational
Opcode
Info

Description

Work Folders failed to update the current state of an item. Item: ItemName; Sync ID: SyncGID; Update action: Action; Error code: HResultStr.

Message #

Work Folders failed to update the current state of an item. Item: %1; Sync ID: %2; Update action: %3; Error code: %4

Fields #

NameDescription
ItemName UnicodeString
SyncGID GUID
Action UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2114: Work Folders failed to synchronize an item.

#
Channel
Operational
Opcode
Info

Description

Work Folders failed to synchronize an item. Item: ItemName; Sync ID: SyncGID; Sync action: Action; Error code: HResultStr.

Message #

Work Folders failed to synchronize an item. Item: %1; Sync ID: %2; Sync action: %3; Error code: %4

Fields #

NameDescription
ItemName UnicodeString
SyncGID GUID
Action UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2115: Work Folders detected a database version that is incompatible and recovered it.

#
Channel
Operational
Opcode
Info

Description

Work Folders detected a database version that is incompatible and recovered it. Database path: DatabasePath.

Message #

Work Folders detected a database version that is incompatible and recovered it. Database path: %1

Fields #

NameDescription
DatabasePath UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2116: Work Folders detected a database version that is incompatible and recovery failed.

#
Channel
Operational
Opcode
Info

Description

Work Folders detected a database version that is incompatible and recovery failed. Database path: DatabasePath; Error: HResultStr.

Message #

Work Folders detected a database version that is incompatible and recovery failed. Database path: %1; Error: %2

Fields #

NameDescription
DatabasePath UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2117: Work Folders failed to connect with Cloud Files.

#
Channel
Operational
Opcode
Info

Description

Work Folders failed to connect with Cloud Files. Sync Path: DatabasePath. Error: HResultStr.

Message #

Work Folders failed to connect with Cloud Files. Sync Path: %1. Error: %2

Fields #

NameDescription
DatabasePath UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2118: Work Folders failed to disconnect with Cloud Files.

#
Channel
Operational
Opcode
Info

Description

Work Folders failed to disconnect with Cloud Files. Error: HResultStr.

Message #

Work Folders failed to disconnect with Cloud Files. Error: %1

Fields #

NameDescription
HResultStr UnicodeString
HResult Int32

Event ID 2119: Work Folders failed to register with Cloud Files.

#
Channel
Operational
Opcode
Info

Description

Work Folders failed to register with Cloud Files. Sync Path: DatabasePath. Error: HResultStr.

Message #

Work Folders failed to register with Cloud Files. Sync Path: %1. Error: %2

Fields #

NameDescription
DatabasePath UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 2120: Work Folders failed to unregister with Cloud Files.

#
Channel
Operational
Opcode
Info

Description

Work Folders failed to unregister with Cloud Files. Sync Path: DatabasePath. Error: HResultStr.

Message #

Work Folders failed to unregister with Cloud Files. Sync Path: %1. Error: %2

Fields #

NameDescription
DatabasePath UnicodeString
HResultStr UnicodeString
HResult Int32

Event ID 8000: Starting sync.

#
Channel
Analytic
Task
SyncPartnership
Opcode
Start

Description

Starting sync. Work Folders path: LocalReplicaRoot.

Message #

Starting sync. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8001: Work Folders is looking for changed files.

#
Channel
Analytic
Task
SyncPartnership
Opcode
ChangeUpdateStart

Description

Work Folders is looking for changed files. Work Folders path: LocalReplicaRoot.

Message #

Work Folders is looking for changed files. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8002: Starting to download files.

#
Channel
Analytic
Task
SyncPartnership
Opcode
DownloadStart

Description

Starting to download files. Work Folders path: LocalReplicaRoot.

Message #

Starting to download files. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8003: Starting to upload files.

#
Channel
Analytic
Task
SyncPartnership
Opcode
UploadStart

Description

Starting to upload files. Work Folders path: LocalReplicaRoot.

Message #

Starting to upload files. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8004: Finished syncing.

#
Channel
Analytic
Task
SyncPartnership
Opcode
Stop

Description

Finished syncing. Work Folders path: LocalReplicaRoot.

Message #

Finished syncing. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString
FullEnumerationOccurred Boolean

Event ID 8005: Starting reconciliation sync.

#
Channel
Analytic
Task
SyncPartnership
Opcode
ReconciliationStart

Description

Starting reconciliation sync. Work Folders path: LocalReplicaRoot.

Message #

Starting reconciliation sync. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8006: Finished reconciliation sync.

#
Channel
Analytic
Task
SyncPartnership
Opcode
ReconciliationStop

Description

Finished reconciliation sync. Work Folders path: LocalReplicaRoot.

Message #

Finished reconciliation sync. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8007: Starting sync knowledge upload.

#
Channel
Analytic
Task
SyncPartnership
Opcode
KnowledgeUploadStart

Description

Starting sync knowledge upload. Server partnership id: ServerPartnershipId.

Message #

Starting sync knowledge upload. Server partnership id: %1

Fields #

NameDescription
ServerPartnershipId UnicodeString

Event ID 8008: Starting data transfer for file download.

#
Channel
Analytic
Task
SyncPartnership
Opcode
DownloadTransferStart

Description

Starting data transfer for file download. Server partnership id: ServerPartnershipId.

Message #

Starting data transfer for file download. Server partnership id: %1

Fields #

NameDescription
ServerPartnershipId UnicodeString

Event ID 8009: Applying downloaded files.

#
Channel
Analytic
Task
SyncPartnership
Opcode
ChangeBatchApplyStart

Description

Applying downloaded files. Work Folders path: LocalReplicaRoot.

Message #

Applying downloaded files. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8010: Starting sync knowledge download.

#
Channel
Analytic
Task
SyncPartnership
Opcode
KnowledgeDownloadStart

Description

Starting sync knowledge download. Server partnership id: ServerPartnershipId.

Message #

Starting sync knowledge download. Server partnership id: %1

Fields #

NameDescription
ServerPartnershipId UnicodeString

Event ID 8011: Creating a change batch for upload.

#
Channel
Analytic
Task
SyncPartnership
Opcode
ChangeBatchGenStart

Description

Creating a change batch for upload. Work Folders path: LocalReplicaRoot.

Message #

Creating a change batch for upload. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8012: Starting data transfer for file upload.

#
Channel
Analytic
Task
SyncPartnership
Opcode
UploadTransferStart

Description

Starting data transfer for file upload. Server partnership id: ServerPartnershipId.

Message #

Starting data transfer for file upload. Server partnership id: %1

Fields #

NameDescription
ServerPartnershipId UnicodeString

Event ID 8013: Work Folders successfully connected with Cloud Files.

#
Channel
Analytic
Task
SyncPartnership

Event ID 8014: Work Folders successfully disconnected with Cloud Files.

#
Channel
Analytic
Task
SyncPartnership

Event ID 8015: Work Folders successfully registered with Cloud Files.

#
Channel
Analytic
Task
SyncPartnership

Description

Work Folders successfully registered with Cloud Files. Sync Path: LocalReplicaRoot.

Message #

Work Folders successfully registered with Cloud Files. Sync Path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8016: Work Folders successfully unregistered with Cloud Files.

#
Channel
Analytic
Task
SyncPartnership

Description

Work Folders successfully unregistered with Cloud Files. Sync Path: LocalReplicaRoot.

Message #

Work Folders successfully unregistered with Cloud Files. Sync Path: %1.

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8017: Work Folders detected files that cannot be uploaded.

#
Channel
Analytic
Task
SyncPartnership

Description

Work Folders detected files that cannot be uploaded. File repair started.

Message #

Work Folders detected files that cannot be uploaded. File repair started.

Event ID 8018: Work Folders file repair completed.

#
Channel
Analytic
Task
SyncPartnership

Event ID 8019: Starting cleanup before reconciliation.

#
Channel
Analytic
Task
SyncPartnership

Description

Starting cleanup before reconciliation. Work Folders path: LocalReplicaRoot.

Message #

Starting cleanup before reconciliation. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 8020: Finished cleanup before reconciliation.

#
Channel
Analytic
Task
SyncPartnership

Description

Finished cleanup before reconciliation. Work Folders path: LocalReplicaRoot.

Message #

Finished cleanup before reconciliation. Work Folders path: %1

Fields #

NameDescription
LocalReplicaRoot UnicodeString

Event ID 9001: Credentials required for the user.

#
Channel
WHC
Opcode
Info

Fields #

NameDescription
hc_stateid UInt32
Application UnicodeString

Event ID 9002: Work Folders detected a sync error.

#
Channel
WHC
Opcode
Info

Description

Work Folders detected a sync error. Check partnership status, network connectivity, and disk space.

Message #

Work Folders detected a sync error. Check partnership status, network connectivity, and disk space.

Fields #

NameDescription
hc_stateid UInt32
Application UnicodeString

Event ID 9003: Work Folders detected a file error.

#
Channel
WHC
Opcode
Info

Description

Work Folders detected a file error. Check file sizes and types are supported.

Message #

Work Folders detected a file error. Check file sizes and types are supported.

Fields #

NameDescription
hc_stateid UInt32
Application UnicodeString

Event ID 9004: Your PC doesn't comply with your organization's security policies.

#
Channel
WHC
Opcode
Info

Fields #

NameDescription
hc_stateid UInt32
Application UnicodeString

Provenance

ETW provider GUID 34a3697e-0f10-4e48-af3c-f869b5babebb

Defined in WorkFoldersSvc.dll, which carries the event manifest.

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB