Skip to main content

Windows identity and security event channels

33channels
32curated reasons
2themes fed
Livestatus

Identity, secrets, code integrity and policy channels, bound as one feed: LAPS, BitLocker, Code Integrity, AppLocker, Group Policy, certificate and key stores, biometrics and passkeys, device registration and Entra join, logon and profile. Curated reasons over the code-integrity families, with the unread remainder still capped at Warning.

Feed id: win.eventlog.identity_security.

Channels​

This feed binds 33 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.

ChannelTicket class
Microsoft-Windows-AAD/Operationalauth
Microsoft-Windows-AppLocker/EXE and DLLsecurity_audit
Microsoft-Windows-AppLocker/MSI and Scriptsecurity_audit
Microsoft-Windows-AppLocker/Packaged app-Deploymentsecurity_audit
Microsoft-Windows-AppLocker/Packaged app-Executionsecurity_audit
Microsoft-Windows-Authentication User Interface/Operationalauth
Microsoft-Windows-Biometrics/Operationalauth
Microsoft-Windows-BitLocker/BitLocker Management
Microsoft-Windows-CAPI2/Operational (disabled by default on client Windows; enable it on the host to produce data)certificates
Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operationalcertificates
Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operationalcertificates
Microsoft-Windows-CodeIntegrity/Operationalsecurity_audit
Microsoft-Windows-Crypto-DPAPI/Operationalcertificates
Microsoft-Windows-Crypto-NCrypt/KeyMgmtcertificates
Microsoft-Windows-Crypto-NCrypt/Operationalcertificates
Microsoft-Windows-EnrollmentPolicyWebService/Admincertificates
Microsoft-Windows-EnrollmentWebService/Admincertificates
Microsoft-Windows-GroupPolicy/Operationaldevice_management
Microsoft-Windows-HelloForBusiness/Operationalauth
Microsoft-Windows-LAPS/Operationalauth
Microsoft-Windows-LiveId/Operationalauth
Microsoft-Windows-NTLM/Operationalauth
Microsoft-Windows-Security-Mitigations/KernelModesecurity_audit
Microsoft-Windows-Security-Mitigations/UserModesecurity_audit
Microsoft-Windows-SENSE/Operationalendpoint_protection
Microsoft-Windows-SmartCard-Audit/Authenticationauth
Microsoft-Windows-SmartCard-DeviceEnum/Operationalauth
Microsoft-Windows-UAC/Operationalsecurity_audit
Microsoft-Windows-User Device Registration/Admindevice_management
Microsoft-Windows-User Profile Service/Operationaluser_profiles
Microsoft-Windows-WebAuthN/Operationalauth
Microsoft-Windows-Winlogon/Operationalauth
Microsoft-Windows-Workplace Join/Admindevice_management

Fields​

FieldTypeUnitMeaning
win.eventlog.identity_security.code_integrity_requested_levelintSigning level Code Integrity required of the file, from the CodeIntegrity load and policy ids (RequestedPolicy or Requested Signing Level depending on the id). The raw number, which is what every rule keys on.
win.eventlog.identity_security.code_integrity_requested_level_namestringBounded meaning token for that level (signing_level_unchecked, signing_level_unsigned, signing_level_policy_trusted, signing_level_developer, signing_level_authenticode, signing_level_store_protected, signing_level_store, signing_level_antimalware, signing_level_microsoft, signing_level_ngen, signing_level_windows, signing_level_windows_tcb). Display beside the number; a level outside the published set leaves this unset.
win.eventlog.identity_security.code_integrity_validated_levelintSigning level the file actually carried, from the same ids (ValidatedPolicy or Validated Signing Level). Read beside the requested level: the pair is what says how far short the signature fell.
win.eventlog.identity_security.code_integrity_validated_level_namestringBounded meaning token for the validated level, from the same set as the requested one. A level outside the published set leaves this unset.
win.eventlog.identity_security.code_integrity_policy_namestringName of the Code Integrity policy that refused a file, from CodeIntegrity 3076 and 3077 (PolicyName). The first thing to read on those ids: it says which policy is in force.
win.eventlog.identity_security.code_integrity_policy_idstringIdentifier of that policy, from the same ids (PolicyID). Separates two revisions of one policy name.
win.eventlog.identity_security.code_integrity_file_user_writableboolWhether the refused file sits somewhere an ordinary user can write, from CodeIntegrity 3076 and 3077 (UserWriteable). The single most decision-relevant field on those ids.
win.eventlog.identity_security.code_integrity_file_sha256stringSHA-256 of the refused file, from CodeIntegrity 3076 and 3077 (SHA256 Hash). File content, not file location, so it identifies the binary without naming where it lives.
win.eventlog.identity_security.code_integrity_secure_requiredstringSecure-load requirement flag the loader carried, from CodeIntegrity 3002, 3004 and 3023 (SecureRequired). Promoted as the provider wrote it: no published value map was read for it.
win.eventlog.identity_security.code_integrity_filestringBare file name of the image Code Integrity refused, from the CodeIntegrity load ids (FileNameBuffer, last path segment only). The recurrence pivot for one file that keeps being refused.
win.eventlog.identity_security.code_integrity_catalogstringSignature catalog Code Integrity could not read, from CodeIntegrity 3010 (FileNameBuffer, which on that id is a bare catalog file name). Ties the failure back to the servicing package that delivers the catalog.
win.eventlog.identity_security.mitigation_processstringBare file name of the process an exploit mitigation fired on, from the Security-Mitigations ids (ProcessPath, last path segment only). The pivot the count is not: a path appearing for the first time is what flags an application that just broke.
win.eventlog.identity_security.shadow_stack_nonenforcement_reasonintWhy Windows let a process continue after a shadow stack return-address mismatch, from Security-Mitigations 25 (NonenforcementReason). Promoted as the number: no published value map was read for it.
win.eventlog.identity_security.shadow_stack_control_pc_imagestringBare file name of the module a mismatched return address points into, from Security-Mitigations 25 (ControlPcImageName, last path segment only). The most diagnostic field on that id.
win.eventlog.identity_security.entra_error_messagestringThe authentication library own sentence describing that error, from the same ids (ErrorMessage). Publisher text, and the only thing that tells a transport failure from a tenant configuration failure.
win.eventlog.identity_security.correlation_idstringCorrelation identifier the cloud authentication plugin stamped on one attempt (CorrelationID). New on every attempt, so it joins a device-side record to a tenant-side one and never groups.
win.eventlog.identity_security.http_statusintHTTP status a service returned to a device-side operation, from User Device Registration 204 (HttpStatus). Separates a refusal the service made from one the network made.
win.eventlog.identity_security.directory_error_codeintThe SECOND code on a registration failure, from the User Device Registration ids that carry both (ErrorCode beside ExitCode). The exit code is the outcome a ticket is about and rides the result family; this one is the detail underneath it. The two lookup ids carry no exit code, so their ErrorCode is the acting code and rides the result family instead of appearing here.
win.eventlog.identity_security.directory_error_subcodestringSub-code the registration service named beside a failure (ErrorSubcode), e.g. two devices claiming one name. The only field that separates the duplicate-identity case from a generic failure.
win.eventlog.identity_security.registration_attributestringDevice-object attribute a registration update was trying to write, from User Device Registration 252 (Attribute).
win.eventlog.identity_security.whfb_policy_enabledstringWhether a policy asks for Windows Hello for Business on this device, from User Device Registration 360 (NgcPolicyEnabled). The field that separates a deliberate absence from a failed rollout.
win.eventlog.identity_security.whfb_user_remotestringWhether the user is connected over a remote desktop session, from the same checklist (UserIsRemote). Windows Hello does not provision over one by design.
win.eventlog.identity_security.whfb_device_joinedstringWhether the device is joined to the directory, from the same checklist (DeviceIsJoined).
win.eventlog.identity_security.whfb_hardware_metstringWhether the device meets the Windows Hello for Business hardware requirements, from the same checklist (NgcHardwarePolicyMet).
win.eventlog.identity_security.whfb_primary_refresh_tokenstringWhether the user signed in with cloud credentials, from the same checklist (AADPrt). Presence of the token, never the token.
win.eventlog.identity_security.whfb_key_statusstringKey status the provider decoded itself, from User Device Registration 385 (KeyStatusSymbolicName), e.g. a platform module with no attestation capability. Better than any table because the provider ships the name.
win.eventlog.identity_security.dpapi_failure_reasonintReason code the data-protection subsystem gave for an unprotect that did not complete, from Crypto-DPAPI 8198 (ReasonForFailure). Promoted as the number: no published value map was read for it.
win.eventlog.identity_security.dpapi_master_key_guidstringIdentifier of the master key an unprotect was against, from Crypto-DPAPI 8202 and 8204 (MasterKeyGUID). A key identifier, never key material.
win.eventlog.identity_security.crypto_providerstringKey-storage provider a key operation ran against, from the Crypto-NCrypt operational ids (ProviderName). The axis the band turns on: the same status word means opposite things on the software and the hardware provider.
win.eventlog.identity_security.crypto_operation_typeintOperation type the key-storage call carried, from the same ids (OperationType). Promoted as the number: no published value map was read for it.
win.eventlog.identity_security.crypto_functionstringKey-isolation function that failed, from Crypto-NCrypt 13 (Function). Names the call rather than the caller.
win.eventlog.identity_security.vbs_can_be_enabledintWhether the platform states that virtualization-based key protection can be enabled at all, from Crypto-NCrypt 26 (CanBeEnabled). Zero means the hardware or firmware cannot support it and retrying will not change the outcome.
win.eventlog.identity_security.vbs_restart_attemptsintRunning count of virtualization-based key protection restart attempts, from Crypto-NCrypt 26 (TotalAttemptedRestarts). A counter, so it belongs on the row and never in a grouping key.
win.eventlog.identity_security.vbs_restart_successesintRunning count of those attempts that succeeded, from the same id (TotalSuccessfulRestarts). Read beside the attempt count: the pair is the whole story.
win.eventlog.identity_security.gp_connectivity_failureboolWhether Group Policy attributes a failed pass to the network, from GroupPolicy 7000 and 7001 (IsConnectivityFailure). The field that separates a machine off the corporate network from one that cannot reach its own domain.
win.eventlog.identity_security.gp_is_machineintWhether a policy pass was the computer boot pass or a user logon pass, from the same ids (IsMachine).
win.eventlog.identity_security.gp_elapsed_secondsintSeconds the failed policy pass took, from the same ids. The provider misspells the field name and this is the corrected spelling.
win.eventlog.identity_security.gp_extension_namestringClient-side extension that reported a failure code, from GroupPolicy 6016 and 7016 (CSEExtensionName). The diagnostic: a failure in the security extension is a different problem from one in the drive-maps extension.
win.eventlog.identity_security.gp_extension_idstringIdentifier of that extension, from the same ids (CSEExtensionId). The stable pivot when the display name is localized.
win.eventlog.identity_security.gp_dc_discovery_msintMilliseconds Group Policy spent trying to discover a domain controller before giving up, from GroupPolicy 7326 (DCDiscoveryTimeInMilliSeconds).
win.eventlog.identity_security.gp_mutual_auth_enforcedboolWhether the machine requires mutual authentication when it reads policy from a file share, from GroupPolicy 9001 (MutualAuthenticationEnforced).
win.eventlog.identity_security.gp_integrity_enforcedboolWhether the machine requires integrity protection on that same read, from the same id (IntegrityEnforced). Read beside the mutual-authentication flag: the pair is the whole finding.
win.eventlog.identity_security.ntlm_versionstringVersion of the legacy authentication protocol that was used, from the NTLM client ids (NtlmVersion). The first version is broken and this is the field that finds it.
win.eventlog.identity_security.ntlm_usage_reasonstringWhy the legacy protocol was used rather than Kerberos, from the outbound ids (NtlmUsageReason). Publisher-decoded text, e.g. a target name Kerberos could not resolve or an application that called it directly.
win.eventlog.identity_security.ntlm_channel_bindingstringChannel-binding state of the exchange, from the same ids (ChannelBindingStatus).
win.eventlog.identity_security.ntlm_mic_statusstringMessage-integrity-check state of the exchange, from the same ids. The provider spells this field name with a space, beside a version field that has none.
win.eventlog.identity_security.bitlocker_backup_targetstringWhere a BitLocker recovery key backup was addressed, as a literal: a personal cloud account, the cloud directory where the provider names it, and the unqualified directory where it does not. The destination comes from the sentence the event id renders, not from BackendName.
win.eventlog.identity_security.bitlocker_volume_mount_pointstringRaw BitLocker volume mount point from event_data.VolumeMountPoint when present on a backup or success event.
win.eventlog.identity_security.bitlocker_secure_boot_reasonstringWhy BitLocker could not use the measured boot state, as a literal per arm: the feature is off, the measurement log is invalid, or the measurement could not be read. A literal from the event id.
win.eventlog.identity_security.cert_subjectstringSubject of the certificate that expired or is about to, from the certificate lifecycle ids (SubjectName). The only field that separates a domain controller certificate from a vendor application signing certificate.
win.eventlog.identity_security.cert_not_valid_afterintInstant the certificate stops being valid, from the same ids (NotValidAfter). In a grouping key it is what stops a renewed certificate from being suppressed as a duplicate of the old one.
win.eventlog.identity_security.cert_storestringWhich store the certificate is in, machine or user, as a literal from the channel. The machine-store rows are infrastructure certificates and the user-store rows usually are not.
win.eventlog.identity_security.applocker_policy_namestringApplication-control policy collection an audit finding came from, from AppLocker 8003 (PolicyName), e.g. the executable or the library collection.
win.eventlog.identity_security.applocker_rule_namestringRule that would have denied the file, from the same id (RuleName). A placeholder value means no rule matched at all.
win.eventlog.identity_security.applocker_rule_idstringIdentifier of that rule, from the same id (RuleId). An all-zero identifier is what says no rule matched, which is the ordinary audit finding.
win.eventlog.identity_security.applocker_file_pathstringResolved path of the file the audit finding is about, from the same id (FullFilePath). Promoted deliberately: the whole value of the row is knowing which program it was, and the payload environment-variable form is not promoted beside it.
win.eventlog.identity_security.sensor_connection_error_codeintError the endpoint sensor reported for a failed contact, from errorCode or Int1. Usually a WinHTTP transport error (12007: the name did not resolve), not an HTTP status; the raw number, not decoded.
win.eventlog.identity_security.sensor_request_typestringWhich request to the token service failed, from SENSE 405 and 406 (requestType).
win.eventlog.identity_security.sensor_contact_failuresintHow many times the sensor contacted its service in the reported window, from SENSE 5 and 67 (UInt1).
win.eventlog.identity_security.sensor_contact_successesintHow many of those contacts succeeded, from SENSE 67 (UInt3). Read beside the attempt count: some succeeding is what separates a sensor that is reporting from one that is dark.

Severity​

A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.

Curated reasons​

Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.

ReasonTicket classSeverity
applocker_audit_would_blocksecurity_auditNotice
applocker_unsupported_windows_editionsecurity_auditNotice
bitlocker_recovery_key_backup_failedencryptionError or Info
bitlocker_secure_boot_unavailableencryptionNotice
cert_expiredcertificatesWarning
cert_expiringcertificatesWarning
code_integrity_catalog_load_failedsecurity_auditNotice or Info
code_integrity_driver_revokedsecurity_auditWarning
code_integrity_image_hash_missingsecurity_auditWarning or Notice
code_integrity_policy_audit_would_blocksecurity_auditNotice
code_integrity_policy_blockedsecurity_auditWarning
code_integrity_signing_level_blockedsecurity_auditWarning
crypto_key_operation_failedcertificatesNotice or Debug
defender_sensor_connection_failedendpoint_protectionWarning or Info
device_encryption_enable_failedencryptionWarning
device_registration_faileddevice_managementWarning or Notice
dpapi_unprotect_failedcertificatesNotice
entra_device_certificate_update_faileddevice_managementWarning
entra_sign_in_failedauthNotice for a wrong credential or an unreachable service, Warning for a refusal the event does not explain.
entra_token_acquisition_failedauthInfo where the library is asking for a sign-in, Notice for a transport failure, Warning where a tenant setting refused the request.
exploit_mitigation_audit_would_blocksecurity_auditInfo
exploit_mitigation_blockedsecurity_auditNotice or Verbose
exploit_mitigation_shadow_stack_mismatchsecurity_auditNotice on the documented compatibility path, Warning where nothing on the event explains the mismatch.
group_policy_domain_controller_unresolveddevice_managementWarning or Notice
group_policy_extension_apply_faileddevice_managementMinor or Info
group_policy_file_share_unhardeneddevice_managementNotice
group_policy_processing_faileddevice_managementNotice on a device that moves and loses the corporate network, Warning otherwise.
laps_password_backup_failedauthWarning
ntlm_authentication_usedauthWarning or Notice
vbs_key_isolation_failedcertificatesNotice or Info
windows_hello_key_registration_failedauthNotice or Info
windows_hello_provisioning_blockedauthNotice or Info

applocker_audit_would_block​

An application-control policy running in audit mode would have blocked this file under enforcement.

Severity: Notice

Impact: Nothing was blocked and the file ran. Someone must decide about every file like this before the policy can move to enforcement.

Channel: Microsoft-Windows-AppLocker/EXE and DLL

Provider: Microsoft-Windows-AppLocker

Event ids: 8003

CaseSeverityTicket class
no_matching_ruleNoticesecurity_audit
rule_matchedNoticesecurity_audit

Where to look next:

  • Collect every instance of this row.
  • Together they form the work list for moving an application-control policy from audit to enforced.
  • One instance alone tells an engineer nothing.

Related reasons:

Fields it can set: win.eventlog.identity_security.applocker_file_path, win.eventlog.identity_security.applocker_policy_name, win.eventlog.identity_security.applocker_rule_id, win.eventlog.identity_security.applocker_rule_name

applocker_unsupported_windows_edition​

An application-control policy reached a device whose Windows edition cannot enforce it.

Severity: Notice

Impact: The policy is inert on that device and every application-control decision it would have made is not made. Someone believes this device is protected.

Channel: Microsoft-Windows-AppLocker/MSI and Script

Provider: Microsoft-Windows-AppLocker

Event ids: 8009

Where to look next:

  • Give the device a Windows edition that can enforce the policy, or remove it from the policy's scope.

Related reasons:

bitlocker_recovery_key_backup_failed​

BitLocker reported that a recovery-key backup or retrieval operation failed for a volume.

Severity: Error or Info

Impact: The event does not establish whether another protector or backup copy exists. Check the destination and the volume's recovery-key records.

Channel: Microsoft-Windows-BitLocker/BitLocker Management

Provider: Microsoft-Windows-BitLocker-API

Event ids: 829, 846, 868, 872, 875, 898

CaseSeverityTicket class
consumer_accountInfo
directory_backupErrorencryption

Where to look next:

  • Read the backup target and operation in the event message.
  • Check whether the configured destination is reachable.
  • Confirm the volume's recovery-key records before treating the failure as an escrow gap.

Related reasons:

Fields it can set: win.eventlog.identity_security.bitlocker_backup_target, win.eventlog.identity_security.bitlocker_volume_mount_point

bitlocker_secure_boot_unavailable​

BitLocker reported that Secure Boot integrity data could not be used for a volume.

Severity: Notice

Impact: The event identifies an integrity-validation failure. It does not establish the resulting key-binding method or indicate that a boot-chain attack occurred.

Channel: Microsoft-Windows-BitLocker/BitLocker Management

Provider: Microsoft-Windows-BitLocker-API

Event ids: 810, 811, 812, 813, 834, 835, 878, 881, 893

CaseSeverityTicket class
secure_boot_disabledNoticeencryption
measurement_invalidNoticeencryption
measurement_unreadableNoticeencryption

Where to look next:

  • Read the reason arm: Secure Boot disabled, a missing or unreadable UEFI variable, or an invalid TCG log.
  • Check Secure Boot and firmware integrity state on the affected device.
  • Use the device and firmware documentation for the reported condition.

Related reasons:

Fields it can set: win.eventlog.identity_security.bitlocker_secure_boot_reason

cert_expired​

A certificate in the machine or the user store has expired.

Severity: Warning

Impact: Whatever that certificate authenticates has stopped working, and the event does not say what that is.

Channel: Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational, Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational

Provider: Microsoft-Windows-CertificateServicesClient-Lifecycle-System, Microsoft-Windows-CertificateServicesClient-Lifecycle-User

Event ids: 1002, 1003

Where to look next:

  • Read the certificate subject.
  • A domain controller certificate expiring is a different problem from a vendor application signing certificate expiring.
  • The subject line is the only way to tell them apart.

Related reasons:

  • cert_expiring: a certificate about to expire rather than one that already has

Fields it can set: win.eventlog.identity_security.cert_not_valid_after, win.eventlog.identity_security.cert_store, win.eventlog.identity_security.cert_subject

cert_expiring​

A certificate in the machine or the user store is about to expire.

Also reported by: Windows Application event log

Severity: Warning

Impact: Whatever that certificate authenticates stops working on the expiry date.

Channel: Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational, Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational

Provider: Microsoft-Windows-CertificateServicesClient-Lifecycle-System, Microsoft-Windows-CertificateServicesClient-Lifecycle-User

Event ids: 1002, 1003

Where to look next:

  • Read the certificate subject.
  • A domain controller certificate expiring is a different problem from a vendor application signing certificate expiring.
  • The subject line is the only way to tell them apart.

Related reasons:

  • cert_expired: a certificate that has already expired rather than one about to

Fields it can set: win.eventlog.identity_security.cert_not_valid_after, win.eventlog.identity_security.cert_store, win.eventlog.identity_security.cert_subject

code_integrity_catalog_load_failed​

Windows could not read a signature catalog, so the files that catalog vouches for have no signature until it is replaced.

Severity: Notice or Info

Impact: Files the catalog vouches for lose their signature. That is one path to a file failing its integrity check on the next load.

Channel: Microsoft-Windows-CodeIntegrity/Operational

Provider: Microsoft-Windows-CodeIntegrity

Event ids: 3010, 3024

CaseSeverityTicket class
resource_pressureInfosecurity_audit
unreadableNoticesecurity_audit

Where to look next:

  • Read the status code.
  • A resource-exhaustion code means the machine was under memory pressure at the time and it will likely pass next time.
  • A name-not-found code means the catalog is missing, so check servicing.

Related reasons:

Fields it can set: win.eventlog.identity_security.code_integrity_catalog

code_integrity_driver_revoked​

A driver on this device is on the platform vendor's revoked-driver list, and the kernel refused to load it.

Severity: Warning

Impact: The driver did not load and the file is still on disk. Whatever installed it put a known-bad driver on the device.

Channel: Microsoft-Windows-CodeIntegrity/Operational

Provider: Microsoft-Windows-CodeIntegrity

Event ids: 3023

Where to look next:

  • Find what installed the driver and remove it.
  • When a management or diagnostics agent shipped the revoked driver, update that agent.
  • When nothing else explains the driver, investigate further.

Related reasons:

Fields it can set: win.eventlog.identity_security.code_integrity_file, win.eventlog.identity_security.code_integrity_secure_required

code_integrity_image_hash_missing​

Windows found no signature on a file it was asked to load, so it could not verify the file's integrity.

Severity: Warning or Notice

Impact: A kernel driver with no verifiable hash does not load and the subsystem behind it stops working. A user-mode library leaves the calling process running.

Channel: Microsoft-Windows-CodeIntegrity/Operational

Provider: Microsoft-Windows-CodeIntegrity

Event ids: 3002, 3004

CaseSeverityTicket class
driverWarningsecurity_audit
user_modeNoticesecurity_audit

Where to look next:

  • Read the requested signing level and the file name.
  • A kernel driver with an unverifiable hash is worth a ticket.
  • A user-mode scanning library reflects the vendor's packaging and needs no action.

Related reasons:

Fields it can set: win.eventlog.identity_security.code_integrity_file, win.eventlog.identity_security.code_integrity_requested_level, win.eventlog.identity_security.code_integrity_secure_required

code_integrity_policy_audit_would_block​

A configured Code Integrity policy recorded that enforcement would have refused a file, under audit mode.

Severity: Notice

Impact: Nothing was denied; the file ran. An engineer moving this policy to enforcement needs this record to know what enforcement would then refuse.

Channel: Microsoft-Windows-CodeIntegrity/Operational

Provider: Microsoft-Windows-CodeIntegrity

Event ids: 3076

Where to look next:

  • Read the policy name first.
  • This is a heads-up: nothing failed on this device.

Related reasons:

Fields it can set: win.eventlog.identity_security.code_integrity_file_sha256, win.eventlog.identity_security.code_integrity_file_user_writable, win.eventlog.identity_security.code_integrity_policy_id, win.eventlog.identity_security.code_integrity_policy_name, win.eventlog.identity_security.code_integrity_requested_level, win.eventlog.identity_security.code_integrity_requested_level_name, win.eventlog.identity_security.code_integrity_validated_level, win.eventlog.identity_security.code_integrity_validated_level_name

code_integrity_policy_blocked​

A configured Code Integrity policy refused a file under enforcement.

Severity: Warning

Impact: The file did not load, so whatever needs it is broken now.

Channel: Microsoft-Windows-CodeIntegrity/Operational

Provider: Microsoft-Windows-CodeIntegrity

Event ids: 3077

Where to look next:

  • Read the policy name first.
  • The driver failed to load, so whatever needs that driver is broken now.

Related reasons:

Fields it can set: win.eventlog.identity_security.code_integrity_file_sha256, win.eventlog.identity_security.code_integrity_file_user_writable, win.eventlog.identity_security.code_integrity_policy_id, win.eventlog.identity_security.code_integrity_policy_name, win.eventlog.identity_security.code_integrity_requested_level, win.eventlog.identity_security.code_integrity_requested_level_name, win.eventlog.identity_security.code_integrity_validated_level, win.eventlog.identity_security.code_integrity_validated_level_name

code_integrity_signing_level_blocked​

An application-control policy or a code-signing requirement on this device blocked a file from loading.

Severity: Warning

Impact: The file did not run. Every load attempt fails the same way until the file is signed or the policy changes.

Channel: Microsoft-Windows-CodeIntegrity/Operational

Provider: Microsoft-Windows-CodeIntegrity

Event ids: 3033, 3066, 3086

Where to look next:

  • Check whether the blocked file belongs on the device.
  • If it does, review the application-control policy or signing requirement that refused it.
  • If it does not, treat the load attempt as unwanted software.

Related reasons:

Fields it can set: win.eventlog.identity_security.code_integrity_file, win.eventlog.identity_security.code_integrity_requested_level, win.eventlog.identity_security.code_integrity_requested_level_name, win.eventlog.identity_security.code_integrity_validated_level, win.eventlog.identity_security.code_integrity_validated_level_name

Not collected: Windows also logs this event when one of its own protected system processes refuses a third-party library (requested levels 7, 8, 12 and 14). Only Microsoft-signed code can pass that check, the vendor cannot obtain that signature, nothing is broken and no setting changes it, so those rows are dropped before collection.

crypto_key_operation_failed​

A key operation failed against one of the Windows key-storage providers.

Severity: Notice or Debug

Impact: Usually none: the caller falls back. Where the hardware key store is the one refusing, Windows Hello, device registration and BitLocker key protectors all sit on top of it.

Channel: Microsoft-Windows-Crypto-NCrypt/Operational

Provider: Microsoft-Windows-Crypto-NCrypt

Event ids: 1, 2, 3, 4, 5, 6, 8, 10, 12

CaseSeverityTicket class
key_absent_probeDebugcertificates
platform_module_not_readyNoticecertificates
other_failureNoticecertificates

Where to look next:

  • Read the provider name and the process together.
  • An application probing the software provider for a key it does not have is routine.
  • A hardware provider reporting the device as not ready flags a hardware or provisioning problem.

Related reasons:

Fields it can set: win.eventlog.identity_security.crypto_operation_type, win.eventlog.identity_security.crypto_provider

defender_sensor_connection_failed​

The endpoint detection sensor cannot reach its cloud service, or cannot get a token to talk to it.

Severity: Warning or Info

Impact: The device stops reporting to the security console while it lasts, and the console still shows it as onboarded.

Channel: Microsoft-Windows-SENSE/Operational

Provider: Microsoft-Windows-SENSE

Event ids: 5, 67, 101, 405, 406, 409

CaseSeverityTicket class
partialInfoendpoint_protection
name_resolutionWarningendpoint_protection
contact_failedWarningendpoint_protection

Where to look next:

  • Read the error code.
  • A name-resolution code reports a proxy or naming problem on this network.
  • A rejection from the token service reports an onboarding or licensing problem.
  • Either way, the sensor stays dark.

Fields it can set: win.eventlog.identity_security.sensor_connection_error_code, win.eventlog.identity_security.sensor_contact_failures, win.eventlog.identity_security.sensor_contact_successes, win.eventlog.identity_security.sensor_request_type

device_encryption_enable_failed​

The device qualifies for automatic device encryption, tried to turn it on and failed.

Severity: Warning

Impact: The system volume stays unencrypted. The customer likely believes that device is encrypted.

Channel: Microsoft-Windows-BitLocker/BitLocker Management

Provider: Microsoft-Windows-BitLocker-API

Event ids: 4103

Where to look next:

  • Compare against the ids that report success.
  • A host producing this repeatedly has an unencrypted system volume.

Related reasons:

device_registration_failed​

The device tried to register itself with the directory and failed.

Severity: Warning or Notice

Impact: The device has no directory identity, so every policy that keys on device state stops applying to it. The device still works for its user.

Channel: Microsoft-Windows-User Device Registration/Admin

Provider: Microsoft-Windows-User Device Registration

Event ids: 204, 220, 221, 233, 252, 258, 304, 307

CaseSeverityTicket class
directory_unreachableNoticedevice_management
directory_refusedWarningdevice_management
quota_exceededWarningdevice_management
duplicate_identityWarningdevice_management
attempt_failedWarningdevice_management

Where to look next:

  • Work bottom up.
  • If the name or controller lookup ids appear, the registration failure above them is only a symptom, and the arm says which half to work: nothing answered, or the directory answered and refused.
  • A refusal points at the computer object, the rights on it, or the credentials presented, so a connectivity check will find nothing.
  • If only the outcome pair fires, check the service connection point in the directory.

Related reasons:

Fields it can set: win.eventlog.identity_security.directory_error_code, win.eventlog.identity_security.directory_error_subcode, win.eventlog.identity_security.http_status, win.eventlog.identity_security.registration_attribute

dpapi_unprotect_failed​

Windows could not decrypt a protected blob, such as a saved credential or a certificate private key.

Severity: Notice

Impact: The owning application usually re-creates the blob on its next use. Where it cannot, that saved credential or private key is gone.

Channel: Microsoft-Windows-Crypto-DPAPI/Operational

Provider: Microsoft-Windows-Crypto-DPAPI

Event ids: 8196, 8198, 8202, 8204, 8205

CaseSeverityTicket class
credential_mismatchNoticecertificates
bad_key_stateNoticecertificates
unprotect_incompleteNoticecertificates

Where to look next:

  • Ask whether a user reports lost saved credentials or a failing certificate store.
  • Without that report, treat this event as background noise.

Related reasons:

Fields it can set: win.eventlog.identity_security.dpapi_failure_reason, win.eventlog.identity_security.dpapi_master_key_guid

entra_device_certificate_update_failed​

The device failed to refresh the certificate that proves its identity to the directory.

Severity: Warning

Impact: Left alone, the device eventually cannot prove it is registered, and every conditional-access policy that depends on device state stops seeing it.

Channel: Microsoft-Windows-AAD/Operational

Provider: Microsoft-Windows-AAD

Event ids: 1131, 1256

Where to look next:

  • Check whether the device can reach the registration service.
  • Check whether its key still exists in the trusted platform module.
  • This shape precedes a device silently dropping out of compliance.

Related reasons:

Fields it can set: win.eventlog.identity_security.correlation_id

entra_sign_in_failed​

The cloud authentication plugin refused a sign-in on this device.

Severity: Notice for a wrong credential or an unreachable service, Warning for a refusal the event does not explain.

Impact: The user is not signed in. A wrong credential is a user event; an unreachable service is a connectivity problem outside authentication.

Channel: Microsoft-Windows-AAD/Operational

Provider: Microsoft-Windows-AAD

Event ids: 1085, 1086, 1160, 1161, 1162

CaseSeverityTicket class
unreachableNoticeauth
credentialNoticeauth
unexplainedNotice to Warningauth

Where to look next:

  • Read the status before anything else.
  • The wrong-password code reports a user event.
  • The network-unreachable code reports a connectivity problem outside authentication.

Related reasons:

entra_token_acquisition_failed​

The device failed to get a token for a cloud resource.

Severity: Info where the library is asking for a sign-in, Notice for a transport failure, Warning where a tenant setting refused the request.

Impact: The resource behind that token is unavailable to the user until the cause is fixed. A tenant configuration error affects every device in the tenant.

Channel: Microsoft-Windows-AAD/Operational

Provider: Microsoft-Windows-AAD

Event ids: 1084, 1094, 1097, 1098, 1112, 1155, 1202, 1215

CaseSeverityTicket class
interaction_requiredInfoauth
configurationWarningauth
transportNoticeauth
unclassifiedNotice to Warningauth

Where to look next:

  • Group by the error message across a day on one host.
  • A transport error points to a network or proxy problem.
  • A grant or consent error points to a tenant configuration problem, and no work on the device fixes that.
  • An interaction-required message reports normal sign-in flow.

Related reasons:

Fields it can set: win.eventlog.identity_security.correlation_id, win.eventlog.identity_security.entra_error_message

exploit_mitigation_audit_would_block​

Exploit protection recorded that enforcement would have stopped a process, under audit mode.

Severity: Info

Channel: Microsoft-Windows-Security-Mitigations/KernelMode

Provider: Microsoft-Windows-Security-Mitigations

Event ids: 1, 3, 11

Where to look next:

  • This is a heads-up: nothing was denied on this device.
  • An engineer moving this mitigation to enforcement needs this record to know what it would hit.

Related reasons:

Fields it can set: win.eventlog.identity_security.mitigation_process

exploit_mitigation_blocked​

Exploit protection stopped a process from an action its policy forbids, under enforcement.

Severity: Notice or Verbose

Channel: Microsoft-Windows-Security-Mitigations/KernelMode

Provider: Microsoft-Windows-Security-Mitigations

Event ids: 2, 4, 6, 10, 12, 32, 34, 36

CaseSeverityTicket classEvent ids
designed_sandboxVerbosesecurity_audit2, 4, 6, 10, 12, 32, 34, 36
unexpected_callerNoticesecurity_audit2, 4, 6, 10, 12, 32, 34, 36

Where to look next:

  • Pivot on the image path, because the event count carries no meaning by itself.
  • A path producing these events for weeks is normal.
  • A path appearing for the first time flags an application that just broke, and this mitigation caused the break.

Related reasons:

Fields it can set: win.eventlog.identity_security.mitigation_process

The enforcing records on the kernel-mode id that arrives at volume are rate-bounded: three per image path per device per day, with the count of what a day suppressed carried on the next day's first record. Read the paths, not the counts.

exploit_mitigation_shadow_stack_mismatch​

A process returned to a different address from the one the hardware shadow stack recorded, and the platform either allowed it to continue or refused the operation.

Severity: Notice on the documented compatibility path, Warning where nothing on the event explains the mismatch.

Impact: Where the operation was refused, whatever the process was attempting did not happen. Where it continued, nothing changed.

Channel: Microsoft-Windows-Security-Mitigations/KernelMode

Provider: Microsoft-Windows-Security-Mitigations

Event ids: 25, 28

CaseSeverityTicket classEvent ids
not_enforcedNotice to Warningsecurity_audit25
blockedWarningsecurity_audit28

Where to look next:

  • Read the image name and the nonenforcement reason together.
  • A recognized application with a known compatibility reason is the ordinary case.
  • The same reason on a process with no business rewriting return addresses is worth investigating.

Related reasons:

Fields it can set: win.eventlog.identity_security.mitigation_process, win.eventlog.identity_security.shadow_stack_control_pc_image, win.eventlog.identity_security.shadow_stack_nonenforcement_reason

group_policy_domain_controller_unresolved​

The machine could not find or could not reach a domain controller.

Severity: Warning or Notice

Impact: Everything downstream of that step fails: no policy applies, and the device cannot register either.

Channel: Microsoft-Windows-GroupPolicy/Operational

Provider: Microsoft-Windows-GroupPolicy

Event ids: 7017, 7320, 7326

CaseSeverityTicket class
domain_unresolvedNoticedevice_management
access_deniedWarningdevice_management
discovery_failedNoticedevice_management

Where to look next:

  • A no-such-domain code means the domain itself failed to resolve, which is a name-resolution or connectivity problem.
  • An access-denied code means the machine account is the problem.
  • Read this alongside device registration: a device that cannot find a controller cannot register either.

Related reasons:

Fields it can set: win.eventlog.identity_security.gp_dc_discovery_ms

group_policy_extension_apply_failed​

A Group Policy client-side extension could not apply the settings from a policy object.

Also reported by: Windows Application event log

Severity: Minor or Info

Impact: None of that policy object's items were delivered to the affected user or machine on this refresh.

Channel: Microsoft-Windows-GroupPolicy/Operational

Provider: Microsoft-Windows-GroupPolicy

Event ids: 6016, 7016

CaseSeverityTicket class
deferredInfodevice_management
share_unreachableMinordevice_management
extension_failedMinordevice_management

Where to look next:

  • Read the extension name and the code together.
  • A network path error on the drive-maps or folder-redirection extension means the machine could not reach the policy share.
  • An access-denied error on the security extension means the policy object itself has a permissions problem.

Related reasons:

Fields it can set: win.eventlog.identity_security.gp_extension_id, win.eventlog.identity_security.gp_extension_name

group_policy_file_share_unhardened​

The machine reads Group Policy files from a file share without mutual authentication or integrity protection.

Severity: Notice

Impact: An attacker on the network path between the machine and the policy share could tamper with policy content in transit. Nothing has gone wrong yet.

Channel: Microsoft-Windows-GroupPolicy/Operational

Provider: Microsoft-Windows-GroupPolicy

Event ids: 9001

Where to look next:

  • Compare the hosts producing this event against the domain's hardened-paths policy.
  • Deliver the mismatched devices as a list for a security review.

Related reasons:

Fields it can set: win.eventlog.identity_security.gp_integrity_enforced, win.eventlog.identity_security.gp_mutual_auth_enforced

group_policy_processing_failed​

Group Policy failed to apply for that boot or that logon.

Severity: Notice on a device that moves and loses the corporate network, Warning otherwise.

Impact: That machine enforces none of the customer's expected settings for that session, and runs whatever policy it last cached.

Channel: Microsoft-Windows-GroupPolicy/Operational

Provider: Microsoft-Windows-GroupPolicy

Event ids: 7000, 7001

CaseSeverityTicket class
no_networkNotice to Warningdevice_management
other_failureWarningdevice_management

Where to look next:

  • Read the connectivity flag first.
  • A portable device booting away from the corporate network produces exactly this event.
  • The same event on a desktop is a real problem.

Related reasons:

Fields it can set: win.eventlog.identity_security.gp_connectivity_failure, win.eventlog.identity_security.gp_elapsed_seconds, win.eventlog.identity_security.gp_is_machine

laps_password_backup_failed​

The device manages its local administrator password and the backup of that password is failing.

Severity: Warning

Impact: The password rotates on schedule and nobody can retrieve it, so a local sign-in that needs it will fail. The compliance claim that the password is escrowed is not true.

Channel: Microsoft-Windows-LAPS/Operational

Provider: Microsoft-Windows-LAPS

Event ids: 10005, 10026, 10028, 10032, 10059

CaseSeverityTicket class
tenant_not_enabledWarningauth
authenticationWarningauth
backup_failedWarningauth

Where to look next:

  • Read the response body on the id that carries it.
  • A tenant-side not-enabled message means someone deployed the policy to devices before configuring the tenant.
  • Every device carrying that policy rotates a password no one can retrieve.

Related reasons:

ntlm_authentication_used​

This machine used the legacy NTLM authentication protocol, as a client or as a server.

Severity: Warning or Notice

Impact: Nothing failed. Where the first version of the protocol was used, the credential on that session carried a weakness the vendor has documented for a decade.

Channel: Microsoft-Windows-NTLM/Operational

Provider: Microsoft-Windows-NTLM

Event ids: 4020, 4021, 4022, 4023

CaseSeverityTicket class
legacy_versionWarningauth
outboundNoticeauth
inboundNoticeauth

Where to look next:

  • Use this as the audit trail for retiring the protocol.
  • Focus on rows carrying the first version of the protocol and rows showing an anonymous principal.

Related reasons:

Fields it can set: win.eventlog.identity_security.ntlm_channel_binding, win.eventlog.identity_security.ntlm_mic_status, win.eventlog.identity_security.ntlm_usage_reason, win.eventlog.identity_security.ntlm_version

vbs_key_isolation_failed​

The isolated key environment that virtualization-based security provides is failing on this device.

Severity: Notice or Info

Impact: Keys that should be held in hardware-isolated memory are not. Every caller keeps working, so nothing is unavailable.

Channel: Microsoft-Windows-Crypto-NCrypt/Operational

Provider: Microsoft-Windows-Crypto-NCrypt

Event ids: 13, 26

CaseSeverityTicket class
unavailableInfocertificates
isolation_failedNoticecertificates

Where to look next:

  • Check whether virtualization-based security should be on for this device.
  • Where the platform states the feature cannot be enabled, the hardware or firmware cannot support it and retrying will not change the outcome.

Related reasons:

Fields it can set: win.eventlog.identity_security.crypto_function, win.eventlog.identity_security.vbs_can_be_enabled, win.eventlog.identity_security.vbs_restart_attempts, win.eventlog.identity_security.vbs_restart_successes

windows_hello_key_registration_failed​

A Windows Hello key or container operation failed after provisioning had already passed its prerequisites.

Severity: Notice or Info

Impact: That user's Windows Hello credential is not usable on this device until it is enrolled again. Signing in with a password is unaffected.

Channel: Microsoft-Windows-User Device Registration/Admin, Microsoft-Windows-HelloForBusiness/Operational

Provider: Microsoft-Windows-User Device Registration, Microsoft-Windows-HelloForBusiness

Event ids: 303, 310, 311, 317, 385, 6010, 7002, 7611

CaseSeverityTicket class
no_attestation_hardwareInfoauth
user_cancelledInfoauth
key_operation_failedNoticeauth

Where to look next:

  • Read the key status.
  • The attestation-capability status is a hardware fact only.
  • A container error or a key error means the user's Windows Hello credential is gone, so re-enroll it.

Related reasons:

Fields it can set: win.eventlog.identity_security.whfb_key_status

windows_hello_provisioning_blocked​

Windows Hello for Business will not set up on this device for this user.

Severity: Notice or Info

Impact: The user signs in with a password instead. Where a policy does ask for the feature, a passwordless rollout is quietly not happening.

Channel: Microsoft-Windows-User Device Registration/Admin, Microsoft-Windows-HelloForBusiness/Operational

Provider: Microsoft-Windows-User Device Registration, Microsoft-Windows-HelloForBusiness

Event ids: 359, 360, 6045, 6055, 7054, 7200, 7201, 7203

CaseSeverityTicket classEvent ids
not_configuredInfoauth
remote_sessionInfoauth
prerequisite_unmetNoticeauth7054, 7200, 7201, 7203
declinedNoticeauth

Where to look next:

  • Read the checklist, where each No reports one configuration fact.
  • If the policy is enabled, the device is joined, and the feature still will not launch, the remaining No is the ticket.

Related reasons:

Fields it can set: win.eventlog.identity_security.whfb_device_joined, win.eventlog.identity_security.whfb_hardware_met, win.eventlog.identity_security.whfb_policy_enabled, win.eventlog.identity_security.whfb_primary_refresh_token, win.eventlog.identity_security.whfb_user_remote

Ask this feed a question​

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.