Windows identity and security event channels
Identity, secrets, code integrity and policy channels, bound as one feed: LAPS, BitLocker, Code Integrity, AppLocker, Group Policy, certificate and key stores, biometrics and passkeys, device registration and Entra join, logon and profile. Curated reasons over the code-integrity families, with the unread remainder still capped at Warning.
Feed id: win.eventlog.identity_security.
Channels
This feed binds 33 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.
| Channel | Ticket class |
|---|---|
Microsoft-Windows-AAD/Operational | auth |
Microsoft-Windows-AppLocker/EXE and DLL | security_audit |
Microsoft-Windows-AppLocker/MSI and Script | security_audit |
Microsoft-Windows-AppLocker/Packaged app-Deployment | security_audit |
Microsoft-Windows-AppLocker/Packaged app-Execution | security_audit |
Microsoft-Windows-Authentication User Interface/Operational | auth |
Microsoft-Windows-Biometrics/Operational | auth |
Microsoft-Windows-BitLocker/BitLocker Management | |
Microsoft-Windows-CAPI2/Operational (disabled by default on client Windows; enable it on the host to produce data) | certificates |
Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational | certificates |
Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational | certificates |
Microsoft-Windows-CodeIntegrity/Operational | security_audit |
Microsoft-Windows-Crypto-DPAPI/Operational | certificates |
Microsoft-Windows-Crypto-NCrypt/KeyMgmt | certificates |
Microsoft-Windows-Crypto-NCrypt/Operational | certificates |
Microsoft-Windows-EnrollmentPolicyWebService/Admin | certificates |
Microsoft-Windows-EnrollmentWebService/Admin | certificates |
Microsoft-Windows-GroupPolicy/Operational | device_management |
Microsoft-Windows-HelloForBusiness/Operational | auth |
Microsoft-Windows-LAPS/Operational | auth |
Microsoft-Windows-LiveId/Operational | auth |
Microsoft-Windows-NTLM/Operational | auth |
Microsoft-Windows-Security-Mitigations/KernelMode | security_audit |
Microsoft-Windows-Security-Mitigations/UserMode | security_audit |
Microsoft-Windows-SENSE/Operational | endpoint_protection |
Microsoft-Windows-SmartCard-Audit/Authentication | auth |
Microsoft-Windows-SmartCard-DeviceEnum/Operational | auth |
Microsoft-Windows-UAC/Operational | security_audit |
Microsoft-Windows-User Device Registration/Admin | device_management |
Microsoft-Windows-User Profile Service/Operational | user_profiles |
Microsoft-Windows-WebAuthN/Operational | auth |
Microsoft-Windows-Winlogon/Operational | auth |
Microsoft-Windows-Workplace Join/Admin | device_management |
Fields
| Field | Type | Unit | Meaning |
|---|---|---|---|
win.eventlog.identity_security.code_integrity_requested_level | int | Signing level Code Integrity required of the file, from the CodeIntegrity load and policy ids (RequestedPolicy or Requested Signing Level depending on the id). The raw number, which is what every rule keys on. | |
win.eventlog.identity_security.code_integrity_requested_level_name | string | Bounded meaning token for that level (signing_level_unchecked, signing_level_unsigned, signing_level_policy_trusted, signing_level_developer, signing_level_authenticode, signing_level_store_protected, signing_level_store, signing_level_antimalware, signing_level_microsoft, signing_level_ngen, signing_level_windows, signing_level_windows_tcb). Display beside the number; a level outside the published set leaves this unset. | |
win.eventlog.identity_security.code_integrity_validated_level | int | Signing level the file actually carried, from the same ids (ValidatedPolicy or Validated Signing Level). Read beside the requested level: the pair is what says how far short the signature fell. | |
win.eventlog.identity_security.code_integrity_validated_level_name | string | Bounded meaning token for the validated level, from the same set as the requested one. A level outside the published set leaves this unset. | |
win.eventlog.identity_security.code_integrity_policy_name | string | Name of the Code Integrity policy that refused a file, from CodeIntegrity 3076 and 3077 (PolicyName). The first thing to read on those ids: it says which policy is in force. | |
win.eventlog.identity_security.code_integrity_policy_id | string | Identifier of that policy, from the same ids (PolicyID). Separates two revisions of one policy name. | |
win.eventlog.identity_security.code_integrity_file_user_writable | bool | Whether the refused file sits somewhere an ordinary user can write, from CodeIntegrity 3076 and 3077 (UserWriteable). The single most decision-relevant field on those ids. | |
win.eventlog.identity_security.code_integrity_file_sha256 | string | SHA-256 of the refused file, from CodeIntegrity 3076 and 3077 (SHA256 Hash). File content, not file location, so it identifies the binary without naming where it lives. | |
win.eventlog.identity_security.code_integrity_secure_required | string | Secure-load requirement flag the loader carried, from CodeIntegrity 3002, 3004 and 3023 (SecureRequired). Promoted as the provider wrote it: no published value map was read for it. | |
win.eventlog.identity_security.code_integrity_file | string | Bare file name of the image Code Integrity refused, from the CodeIntegrity load ids (FileNameBuffer, last path segment only). The recurrence pivot for one file that keeps being refused. | |
win.eventlog.identity_security.code_integrity_catalog | string | Signature catalog Code Integrity could not read, from CodeIntegrity 3010 (FileNameBuffer, which on that id is a bare catalog file name). Ties the failure back to the servicing package that delivers the catalog. | |
win.eventlog.identity_security.mitigation_process | string | Bare file name of the process an exploit mitigation fired on, from the Security-Mitigations ids (ProcessPath, last path segment only). The pivot the count is not: a path appearing for the first time is what flags an application that just broke. | |
win.eventlog.identity_security.shadow_stack_nonenforcement_reason | int | Why Windows let a process continue after a shadow stack return-address mismatch, from Security-Mitigations 25 (NonenforcementReason). Promoted as the number: no published value map was read for it. | |
win.eventlog.identity_security.shadow_stack_control_pc_image | string | Bare file name of the module a mismatched return address points into, from Security-Mitigations 25 (ControlPcImageName, last path segment only). The most diagnostic field on that id. | |
win.eventlog.identity_security.entra_error_message | string | The authentication library own sentence describing that error, from the same ids (ErrorMessage). Publisher text, and the only thing that tells a transport failure from a tenant configuration failure. | |
win.eventlog.identity_security.correlation_id | string | Correlation identifier the cloud authentication plugin stamped on one attempt (CorrelationID). New on every attempt, so it joins a device-side record to a tenant-side one and never groups. | |
win.eventlog.identity_security.http_status | int | HTTP status a service returned to a device-side operation, from User Device Registration 204 (HttpStatus). Separates a refusal the service made from one the network made. | |
win.eventlog.identity_security.directory_error_code | int | The SECOND code on a registration failure, from the User Device Registration ids that carry both (ErrorCode beside ExitCode). The exit code is the outcome a ticket is about and rides the result family; this one is the detail underneath it. The two lookup ids carry no exit code, so their ErrorCode is the acting code and rides the result family instead of appearing here. | |
win.eventlog.identity_security.directory_error_subcode | string | Sub-code the registration service named beside a failure (ErrorSubcode), e.g. two devices claiming one name. The only field that separates the duplicate-identity case from a generic failure. | |
win.eventlog.identity_security.registration_attribute | string | Device-object attribute a registration update was trying to write, from User Device Registration 252 (Attribute). | |
win.eventlog.identity_security.whfb_policy_enabled | string | Whether a policy asks for Windows Hello for Business on this device, from User Device Registration 360 (NgcPolicyEnabled). The field that separates a deliberate absence from a failed rollout. | |
win.eventlog.identity_security.whfb_user_remote | string | Whether the user is connected over a remote desktop session, from the same checklist (UserIsRemote). Windows Hello does not provision over one by design. | |
win.eventlog.identity_security.whfb_device_joined | string | Whether the device is joined to the directory, from the same checklist (DeviceIsJoined). | |
win.eventlog.identity_security.whfb_hardware_met | string | Whether the device meets the Windows Hello for Business hardware requirements, from the same checklist (NgcHardwarePolicyMet). | |
win.eventlog.identity_security.whfb_primary_refresh_token | string | Whether the user signed in with cloud credentials, from the same checklist (AADPrt). Presence of the token, never the token. | |
win.eventlog.identity_security.whfb_key_status | string | Key status the provider decoded itself, from User Device Registration 385 (KeyStatusSymbolicName), e.g. a platform module with no attestation capability. Better than any table because the provider ships the name. | |
win.eventlog.identity_security.dpapi_failure_reason | int | Reason code the data-protection subsystem gave for an unprotect that did not complete, from Crypto-DPAPI 8198 (ReasonForFailure). Promoted as the number: no published value map was read for it. | |
win.eventlog.identity_security.dpapi_master_key_guid | string | Identifier of the master key an unprotect was against, from Crypto-DPAPI 8202 and 8204 (MasterKeyGUID). A key identifier, never key material. | |
win.eventlog.identity_security.crypto_provider | string | Key-storage provider a key operation ran against, from the Crypto-NCrypt operational ids (ProviderName). The axis the band turns on: the same status word means opposite things on the software and the hardware provider. | |
win.eventlog.identity_security.crypto_operation_type | int | Operation type the key-storage call carried, from the same ids (OperationType). Promoted as the number: no published value map was read for it. | |
win.eventlog.identity_security.crypto_function | string | Key-isolation function that failed, from Crypto-NCrypt 13 (Function). Names the call rather than the caller. | |
win.eventlog.identity_security.vbs_can_be_enabled | int | Whether the platform states that virtualization-based key protection can be enabled at all, from Crypto-NCrypt 26 (CanBeEnabled). Zero means the hardware or firmware cannot support it and retrying will not change the outcome. | |
win.eventlog.identity_security.vbs_restart_attempts | int | Running count of virtualization-based key protection restart attempts, from Crypto-NCrypt 26 (TotalAttemptedRestarts). A counter, so it belongs on the row and never in a grouping key. | |
win.eventlog.identity_security.vbs_restart_successes | int | Running count of those attempts that succeeded, from the same id (TotalSuccessfulRestarts). Read beside the attempt count: the pair is the whole story. | |
win.eventlog.identity_security.gp_connectivity_failure | bool | Whether Group Policy attributes a failed pass to the network, from GroupPolicy 7000 and 7001 (IsConnectivityFailure). The field that separates a machine off the corporate network from one that cannot reach its own domain. | |
win.eventlog.identity_security.gp_is_machine | int | Whether a policy pass was the computer boot pass or a user logon pass, from the same ids (IsMachine). | |
win.eventlog.identity_security.gp_elapsed_seconds | int | Seconds the failed policy pass took, from the same ids. The provider misspells the field name and this is the corrected spelling. | |
win.eventlog.identity_security.gp_extension_name | string | Client-side extension that reported a failure code, from GroupPolicy 6016 and 7016 (CSEExtensionName). The diagnostic: a failure in the security extension is a different problem from one in the drive-maps extension. | |
win.eventlog.identity_security.gp_extension_id | string | Identifier of that extension, from the same ids (CSEExtensionId). The stable pivot when the display name is localized. | |
win.eventlog.identity_security.gp_dc_discovery_ms | int | Milliseconds Group Policy spent trying to discover a domain controller before giving up, from GroupPolicy 7326 (DCDiscoveryTimeInMilliSeconds). | |
win.eventlog.identity_security.gp_mutual_auth_enforced | bool | Whether the machine requires mutual authentication when it reads policy from a file share, from GroupPolicy 9001 (MutualAuthenticationEnforced). | |
win.eventlog.identity_security.gp_integrity_enforced | bool | Whether the machine requires integrity protection on that same read, from the same id (IntegrityEnforced). Read beside the mutual-authentication flag: the pair is the whole finding. | |
win.eventlog.identity_security.ntlm_version | string | Version of the legacy authentication protocol that was used, from the NTLM client ids (NtlmVersion). The first version is broken and this is the field that finds it. | |
win.eventlog.identity_security.ntlm_usage_reason | string | Why the legacy protocol was used rather than Kerberos, from the outbound ids (NtlmUsageReason). Publisher-decoded text, e.g. a target name Kerberos could not resolve or an application that called it directly. | |
win.eventlog.identity_security.ntlm_channel_binding | string | Channel-binding state of the exchange, from the same ids (ChannelBindingStatus). | |
win.eventlog.identity_security.ntlm_mic_status | string | Message-integrity-check state of the exchange, from the same ids. The provider spells this field name with a space, beside a version field that has none. | |
win.eventlog.identity_security.bitlocker_backup_target | string | Where a BitLocker recovery key backup was addressed, as a literal: a personal cloud account, the cloud directory where the provider names it, and the unqualified directory where it does not. The destination comes from the sentence the event id renders, not from BackendName. | |
win.eventlog.identity_security.bitlocker_volume_mount_point | string | Raw BitLocker volume mount point from event_data.VolumeMountPoint when present on a backup or success event. | |
win.eventlog.identity_security.bitlocker_secure_boot_reason | string | Why BitLocker could not use the measured boot state, as a literal per arm: the feature is off, the measurement log is invalid, or the measurement could not be read. A literal from the event id. | |
win.eventlog.identity_security.cert_subject | string | Subject of the certificate that expired or is about to, from the certificate lifecycle ids (SubjectName). The only field that separates a domain controller certificate from a vendor application signing certificate. | |
win.eventlog.identity_security.cert_not_valid_after | int | Instant the certificate stops being valid, from the same ids (NotValidAfter). In a grouping key it is what stops a renewed certificate from being suppressed as a duplicate of the old one. | |
win.eventlog.identity_security.cert_store | string | Which store the certificate is in, machine or user, as a literal from the channel. The machine-store rows are infrastructure certificates and the user-store rows usually are not. | |
win.eventlog.identity_security.applocker_policy_name | string | Application-control policy collection an audit finding came from, from AppLocker 8003 (PolicyName), e.g. the executable or the library collection. | |
win.eventlog.identity_security.applocker_rule_name | string | Rule that would have denied the file, from the same id (RuleName). A placeholder value means no rule matched at all. | |
win.eventlog.identity_security.applocker_rule_id | string | Identifier of that rule, from the same id (RuleId). An all-zero identifier is what says no rule matched, which is the ordinary audit finding. | |
win.eventlog.identity_security.applocker_file_path | string | Resolved path of the file the audit finding is about, from the same id (FullFilePath). Promoted deliberately: the whole value of the row is knowing which program it was, and the payload environment-variable form is not promoted beside it. | |
win.eventlog.identity_security.sensor_connection_error_code | int | Error the endpoint sensor reported for a failed contact, from errorCode or Int1. Usually a WinHTTP transport error (12007: the name did not resolve), not an HTTP status; the raw number, not decoded. | |
win.eventlog.identity_security.sensor_request_type | string | Which request to the token service failed, from SENSE 405 and 406 (requestType). | |
win.eventlog.identity_security.sensor_contact_failures | int | How many times the sensor contacted its service in the reported window, from SENSE 5 and 67 (UInt1). | |
win.eventlog.identity_security.sensor_contact_successes | int | How many of those contacts succeeded, from SENSE 67 (UInt3). Read beside the attempt count: some succeeding is what separates a sensor that is reporting from one that is dark. |
Severity
A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.
Curated reasons
Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.
| Reason | Ticket class | Severity |
|---|---|---|
applocker_audit_would_block | security_audit | Notice |
applocker_unsupported_windows_edition | security_audit | Notice |
bitlocker_recovery_key_backup_failed | encryption | Error or Info |
bitlocker_secure_boot_unavailable | encryption | Notice |
cert_expired | certificates | Warning |
cert_expiring | certificates | Warning |
code_integrity_catalog_load_failed | security_audit | Notice or Info |
code_integrity_driver_revoked | security_audit | Warning |
code_integrity_image_hash_missing | security_audit | Warning or Notice |
code_integrity_policy_audit_would_block | security_audit | Notice |
code_integrity_policy_blocked | security_audit | Warning |
code_integrity_signing_level_blocked | security_audit | Warning |
crypto_key_operation_failed | certificates | Notice or Debug |
defender_sensor_connection_failed | endpoint_protection | Warning or Info |
device_encryption_enable_failed | encryption | Warning |
device_registration_failed | device_management | Warning or Notice |
dpapi_unprotect_failed | certificates | Notice |
entra_device_certificate_update_failed | device_management | Warning |
entra_sign_in_failed | auth | Notice for a wrong credential or an unreachable service, Warning for a refusal the event does not explain. |
entra_token_acquisition_failed | auth | Info where the library is asking for a sign-in, Notice for a transport failure, Warning where a tenant setting refused the request. |
exploit_mitigation_audit_would_block | security_audit | Info |
exploit_mitigation_blocked | security_audit | Notice or Verbose |
exploit_mitigation_shadow_stack_mismatch | security_audit | Notice on the documented compatibility path, Warning where nothing on the event explains the mismatch. |
group_policy_domain_controller_unresolved | device_management | Warning or Notice |
group_policy_extension_apply_failed | device_management | Minor or Info |
group_policy_file_share_unhardened | device_management | Notice |
group_policy_processing_failed | device_management | Notice on a device that moves and loses the corporate network, Warning otherwise. |
laps_password_backup_failed | auth | Warning |
ntlm_authentication_used | auth | Warning or Notice |
vbs_key_isolation_failed | certificates | Notice or Info |
windows_hello_key_registration_failed | auth | Notice or Info |
windows_hello_provisioning_blocked | auth | Notice or Info |
applocker_audit_would_block
An application-control policy running in audit mode would have blocked this file under enforcement.
Severity: Notice
Impact: Nothing was blocked and the file ran. Someone must decide about every file like this before the policy can move to enforcement.
Channel: Microsoft-Windows-AppLocker/EXE and DLL
Provider: Microsoft-Windows-AppLocker
Event ids: 8003
| Case | Severity | Ticket class |
|---|---|---|
no_matching_rule | Notice | security_audit |
rule_matched | Notice | security_audit |
Where to look next:
- Collect every instance of this row.
- Together they form the work list for moving an application-control policy from audit to enforced.
- One instance alone tells an engineer nothing.
Related reasons:
applocker_unsupported_windows_edition: a device whose Windows edition cannot enforce the policy at all
Fields it can set: win.eventlog.identity_security.applocker_file_path, win.eventlog.identity_security.applocker_policy_name, win.eventlog.identity_security.applocker_rule_id, win.eventlog.identity_security.applocker_rule_name
applocker_unsupported_windows_edition
An application-control policy reached a device whose Windows edition cannot enforce it.
Severity: Notice
Impact: The policy is inert on that device and every application-control decision it would have made is not made. Someone believes this device is protected.
Channel: Microsoft-Windows-AppLocker/MSI and Script
Provider: Microsoft-Windows-AppLocker
Event ids: 8009
Where to look next:
- Give the device a Windows edition that can enforce the policy, or remove it from the policy's scope.
Related reasons:
applocker_audit_would_block: a policy that is running, in audit mode
bitlocker_recovery_key_backup_failed
BitLocker reported that a recovery-key backup or retrieval operation failed for a volume.
Severity: Error or Info
Impact: The event does not establish whether another protector or backup copy exists. Check the destination and the volume's recovery-key records.
Channel: Microsoft-Windows-BitLocker/BitLocker Management
Provider: Microsoft-Windows-BitLocker-API
Event ids: 829, 846, 868, 872, 875, 898
| Case | Severity | Ticket class |
|---|---|---|
consumer_account | Info | |
directory_backup | Error | encryption |
Where to look next:
- Read the backup target and operation in the event message.
- Check whether the configured destination is reachable.
- Confirm the volume's recovery-key records before treating the failure as an escrow gap.
Related reasons:
bitlocker_secure_boot_unavailable: the integrity binding rather than the key escrowdevice_encryption_enable_failed: encryption that never started, rather than a key that was not escrowed
Fields it can set: win.eventlog.identity_security.bitlocker_backup_target, win.eventlog.identity_security.bitlocker_volume_mount_point
bitlocker_secure_boot_unavailable
BitLocker reported that Secure Boot integrity data could not be used for a volume.
Severity: Notice
Impact: The event identifies an integrity-validation failure. It does not establish the resulting key-binding method or indicate that a boot-chain attack occurred.
Channel: Microsoft-Windows-BitLocker/BitLocker Management
Provider: Microsoft-Windows-BitLocker-API
Event ids: 810, 811, 812, 813, 834, 835, 878, 881, 893
| Case | Severity | Ticket class |
|---|---|---|
secure_boot_disabled | Notice | encryption |
measurement_invalid | Notice | encryption |
measurement_unreadable | Notice | encryption |
Where to look next:
- Read the reason arm: Secure Boot disabled, a missing or unreadable UEFI variable, or an invalid TCG log.
- Check Secure Boot and firmware integrity state on the affected device.
- Use the device and firmware documentation for the reported condition.
Related reasons:
bitlocker_recovery_key_backup_failed: the recovery key escrow rather than the integrity measurement
Fields it can set: win.eventlog.identity_security.bitlocker_secure_boot_reason
cert_expired
A certificate in the machine or the user store has expired.
Severity: Warning
Impact: Whatever that certificate authenticates has stopped working, and the event does not say what that is.
Channel: Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational, Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational
Provider: Microsoft-Windows-CertificateServicesClient-Lifecycle-System, Microsoft-Windows-CertificateServicesClient-Lifecycle-User
Event ids: 1002, 1003
Where to look next:
- Read the certificate subject.
- A domain controller certificate expiring is a different problem from a vendor application signing certificate expiring.
- The subject line is the only way to tell them apart.
Related reasons:
cert_expiring: a certificate about to expire rather than one that already has
Fields it can set: win.eventlog.identity_security.cert_not_valid_after, win.eventlog.identity_security.cert_store, win.eventlog.identity_security.cert_subject
cert_expiring
A certificate in the machine or the user store is about to expire.
Also reported by: Windows Application event log
Severity: Warning
Impact: Whatever that certificate authenticates stops working on the expiry date.
Channel: Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational, Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational
Provider: Microsoft-Windows-CertificateServicesClient-Lifecycle-System, Microsoft-Windows-CertificateServicesClient-Lifecycle-User
Event ids: 1002, 1003
Where to look next:
- Read the certificate subject.
- A domain controller certificate expiring is a different problem from a vendor application signing certificate expiring.
- The subject line is the only way to tell them apart.
Related reasons:
cert_expired: a certificate that has already expired rather than one about to
Fields it can set: win.eventlog.identity_security.cert_not_valid_after, win.eventlog.identity_security.cert_store, win.eventlog.identity_security.cert_subject
code_integrity_catalog_load_failed
Windows could not read a signature catalog, so the files that catalog vouches for have no signature until it is replaced.
Severity: Notice or Info
Impact: Files the catalog vouches for lose their signature. That is one path to a file failing its integrity check on the next load.
Channel: Microsoft-Windows-CodeIntegrity/Operational
Provider: Microsoft-Windows-CodeIntegrity
Event ids: 3010, 3024
| Case | Severity | Ticket class |
|---|---|---|
resource_pressure | Info | security_audit |
unreadable | Notice | security_audit |
Where to look next:
- Read the status code.
- A resource-exhaustion code means the machine was under memory pressure at the time and it will likely pass next time.
- A name-not-found code means the catalog is missing, so check servicing.
Related reasons:
code_integrity_image_hash_missing: a file whose signature could not be found, which this can cause
Fields it can set: win.eventlog.identity_security.code_integrity_catalog
code_integrity_driver_revoked
A driver on this device is on the platform vendor's revoked-driver list, and the kernel refused to load it.
Severity: Warning
Impact: The driver did not load and the file is still on disk. Whatever installed it put a known-bad driver on the device.
Channel: Microsoft-Windows-CodeIntegrity/Operational
Provider: Microsoft-Windows-CodeIntegrity
Event ids: 3023
Where to look next:
- Find what installed the driver and remove it.
- When a management or diagnostics agent shipped the revoked driver, update that agent.
- When nothing else explains the driver, investigate further.
Related reasons:
code_integrity_policy_blocked: a configured policy refusing a file, rather than a published revocation
Fields it can set: win.eventlog.identity_security.code_integrity_file, win.eventlog.identity_security.code_integrity_secure_required
code_integrity_image_hash_missing
Windows found no signature on a file it was asked to load, so it could not verify the file's integrity.
Severity: Warning or Notice
Impact: A kernel driver with no verifiable hash does not load and the subsystem behind it stops working. A user-mode library leaves the calling process running.
Channel: Microsoft-Windows-CodeIntegrity/Operational
Provider: Microsoft-Windows-CodeIntegrity
Event ids: 3002, 3004
| Case | Severity | Ticket class |
|---|---|---|
driver | Warning | security_audit |
user_mode | Notice | security_audit |
Where to look next:
- Read the requested signing level and the file name.
- A kernel driver with an unverifiable hash is worth a ticket.
- A user-mode scanning library reflects the vendor's packaging and needs no action.
Related reasons:
code_integrity_catalog_load_failed: the catalog that would have carried the signature failing to loadcode_integrity_signing_level_blocked: a signature that was found and did not qualify
Fields it can set: win.eventlog.identity_security.code_integrity_file, win.eventlog.identity_security.code_integrity_requested_level, win.eventlog.identity_security.code_integrity_secure_required
code_integrity_policy_audit_would_block
A configured Code Integrity policy recorded that enforcement would have refused a file, under audit mode.
Severity: Notice
Impact: Nothing was denied; the file ran. An engineer moving this policy to enforcement needs this record to know what enforcement would then refuse.
Channel: Microsoft-Windows-CodeIntegrity/Operational
Provider: Microsoft-Windows-CodeIntegrity
Event ids: 3076
Where to look next:
- Read the policy name first.
- This is a heads-up: nothing failed on this device.
Related reasons:
code_integrity_driver_revoked: a driver refused because the vendor revoked itcode_integrity_policy_blocked: the same policy in enforcement, actually refusing the filecode_integrity_signing_level_blocked: a signing level requirement refusing a file, rather than a named policy
Fields it can set: win.eventlog.identity_security.code_integrity_file_sha256, win.eventlog.identity_security.code_integrity_file_user_writable, win.eventlog.identity_security.code_integrity_policy_id, win.eventlog.identity_security.code_integrity_policy_name, win.eventlog.identity_security.code_integrity_requested_level, win.eventlog.identity_security.code_integrity_requested_level_name, win.eventlog.identity_security.code_integrity_validated_level, win.eventlog.identity_security.code_integrity_validated_level_name
code_integrity_policy_blocked
A configured Code Integrity policy refused a file under enforcement.
Severity: Warning
Impact: The file did not load, so whatever needs it is broken now.
Channel: Microsoft-Windows-CodeIntegrity/Operational
Provider: Microsoft-Windows-CodeIntegrity
Event ids: 3077
Where to look next:
- Read the policy name first.
- The driver failed to load, so whatever needs that driver is broken now.
Related reasons:
code_integrity_driver_revoked: a driver refused because the vendor revoked itcode_integrity_policy_audit_would_block: the same policy in audit mode, only recording what it would docode_integrity_signing_level_blocked: a signing level requirement refusing a file, rather than a named policy
Fields it can set: win.eventlog.identity_security.code_integrity_file_sha256, win.eventlog.identity_security.code_integrity_file_user_writable, win.eventlog.identity_security.code_integrity_policy_id, win.eventlog.identity_security.code_integrity_policy_name, win.eventlog.identity_security.code_integrity_requested_level, win.eventlog.identity_security.code_integrity_requested_level_name, win.eventlog.identity_security.code_integrity_validated_level, win.eventlog.identity_security.code_integrity_validated_level_name
code_integrity_signing_level_blocked
An application-control policy or a code-signing requirement on this device blocked a file from loading.
Severity: Warning
Impact: The file did not run. Every load attempt fails the same way until the file is signed or the policy changes.
Channel: Microsoft-Windows-CodeIntegrity/Operational
Provider: Microsoft-Windows-CodeIntegrity
Event ids: 3033, 3066, 3086
Where to look next:
- Check whether the blocked file belongs on the device.
- If it does, review the application-control policy or signing requirement that refused it.
- If it does not, treat the load attempt as unwanted software.
Related reasons:
code_integrity_image_hash_missing: the file carrying no signature at all, rather than one that did not qualifycode_integrity_policy_blocked: a named Code Integrity policy refusing a file, rather than a level requirement
Fields it can set: win.eventlog.identity_security.code_integrity_file, win.eventlog.identity_security.code_integrity_requested_level, win.eventlog.identity_security.code_integrity_requested_level_name, win.eventlog.identity_security.code_integrity_validated_level, win.eventlog.identity_security.code_integrity_validated_level_name
Not collected: Windows also logs this event when one of its own protected system processes refuses a third-party library (requested levels 7, 8, 12 and 14). Only Microsoft-signed code can pass that check, the vendor cannot obtain that signature, nothing is broken and no setting changes it, so those rows are dropped before collection.
crypto_key_operation_failed
A key operation failed against one of the Windows key-storage providers.
Severity: Notice or Debug
Impact: Usually none: the caller falls back. Where the hardware key store is the one refusing, Windows Hello, device registration and BitLocker key protectors all sit on top of it.
Channel: Microsoft-Windows-Crypto-NCrypt/Operational
Provider: Microsoft-Windows-Crypto-NCrypt
Event ids: 1, 2, 3, 4, 5, 6, 8, 10, 12
| Case | Severity | Ticket class |
|---|---|---|
key_absent_probe | Debug | certificates |
platform_module_not_ready | Notice | certificates |
other_failure | Notice | certificates |
Where to look next:
- Read the provider name and the process together.
- An application probing the software provider for a key it does not have is routine.
- A hardware provider reporting the device as not ready flags a hardware or provisioning problem.
Related reasons:
dpapi_unprotect_failed: a protected blob rather than a key-storage operationvbs_key_isolation_failed: the isolated key environment itself rather than one key operation
Fields it can set: win.eventlog.identity_security.crypto_operation_type, win.eventlog.identity_security.crypto_provider
defender_sensor_connection_failed
The endpoint detection sensor cannot reach its cloud service, or cannot get a token to talk to it.
Severity: Warning or Info
Impact: The device stops reporting to the security console while it lasts, and the console still shows it as onboarded.
Channel: Microsoft-Windows-SENSE/Operational
Provider: Microsoft-Windows-SENSE
Event ids: 5, 67, 101, 405, 406, 409
| Case | Severity | Ticket class |
|---|---|---|
partial | Info | endpoint_protection |
name_resolution | Warning | endpoint_protection |
contact_failed | Warning | endpoint_protection |
Where to look next:
- Read the error code.
- A name-resolution code reports a proxy or naming problem on this network.
- A rejection from the token service reports an onboarding or licensing problem.
- Either way, the sensor stays dark.
Fields it can set: win.eventlog.identity_security.sensor_connection_error_code, win.eventlog.identity_security.sensor_contact_failures, win.eventlog.identity_security.sensor_contact_successes, win.eventlog.identity_security.sensor_request_type
device_encryption_enable_failed
The device qualifies for automatic device encryption, tried to turn it on and failed.
Severity: Warning
Impact: The system volume stays unencrypted. The customer likely believes that device is encrypted.
Channel: Microsoft-Windows-BitLocker/BitLocker Management
Provider: Microsoft-Windows-BitLocker-API
Event ids: 4103
Where to look next:
- Compare against the ids that report success.
- A host producing this repeatedly has an unencrypted system volume.
Related reasons:
bitlocker_recovery_key_backup_failed: a recovery-key backup that failed for a named destination
device_registration_failed
The device tried to register itself with the directory and failed.
Severity: Warning or Notice
Impact: The device has no directory identity, so every policy that keys on device state stops applying to it. The device still works for its user.
Channel: Microsoft-Windows-User Device Registration/Admin
Provider: Microsoft-Windows-User Device Registration
Event ids: 204, 220, 221, 233, 252, 258, 304, 307
| Case | Severity | Ticket class |
|---|---|---|
directory_unreachable | Notice | device_management |
directory_refused | Warning | device_management |
quota_exceeded | Warning | device_management |
duplicate_identity | Warning | device_management |
attempt_failed | Warning | device_management |
Where to look next:
- Work bottom up.
- If the name or controller lookup ids appear, the registration failure above them is only a symptom, and the arm says which half to work: nothing answered, or the directory answered and refused.
- A refusal points at the computer object, the rights on it, or the credentials presented, so a connectivity check will find nothing.
- If only the outcome pair fires, check the service connection point in the directory.
Related reasons:
entra_device_certificate_update_failed: a registered device failing to refresh its identity certificategroup_policy_domain_controller_unresolved: the same directory being unreachable, reported from policy processing
Fields it can set: win.eventlog.identity_security.directory_error_code, win.eventlog.identity_security.directory_error_subcode, win.eventlog.identity_security.http_status, win.eventlog.identity_security.registration_attribute
dpapi_unprotect_failed
Windows could not decrypt a protected blob, such as a saved credential or a certificate private key.
Severity: Notice
Impact: The owning application usually re-creates the blob on its next use. Where it cannot, that saved credential or private key is gone.
Channel: Microsoft-Windows-Crypto-DPAPI/Operational
Provider: Microsoft-Windows-Crypto-DPAPI
Event ids: 8196, 8198, 8202, 8204, 8205
| Case | Severity | Ticket class |
|---|---|---|
credential_mismatch | Notice | certificates |
bad_key_state | Notice | certificates |
unprotect_incomplete | Notice | certificates |
Where to look next:
- Ask whether a user reports lost saved credentials or a failing certificate store.
- Without that report, treat this event as background noise.
Related reasons:
crypto_key_operation_failed: a key-storage operation failing rather than a protected blob
Fields it can set: win.eventlog.identity_security.dpapi_failure_reason, win.eventlog.identity_security.dpapi_master_key_guid
entra_device_certificate_update_failed
The device failed to refresh the certificate that proves its identity to the directory.
Severity: Warning
Impact: Left alone, the device eventually cannot prove it is registered, and every conditional-access policy that depends on device state stops seeing it.
Channel: Microsoft-Windows-AAD/Operational
Provider: Microsoft-Windows-AAD
Event ids: 1131, 1256
Where to look next:
- Check whether the device can reach the registration service.
- Check whether its key still exists in the trusted platform module.
- This shape precedes a device silently dropping out of compliance.
Related reasons:
device_registration_failed: the device failing to register in the first placeentra_token_acquisition_failed: a user token rather than the device's own identity certificate
Fields it can set: win.eventlog.identity_security.correlation_id
entra_sign_in_failed
The cloud authentication plugin refused a sign-in on this device.
Severity: Notice for a wrong credential or an unreachable service, Warning for a refusal the event does not explain.
Impact: The user is not signed in. A wrong credential is a user event; an unreachable service is a connectivity problem outside authentication.
Channel: Microsoft-Windows-AAD/Operational
Provider: Microsoft-Windows-AAD
Event ids: 1085, 1086, 1160, 1161, 1162
| Case | Severity | Ticket class |
|---|---|---|
unreachable | Notice | auth |
credential | Notice | auth |
unexplained | Notice to Warning | auth |
Where to look next:
- Read the status before anything else.
- The wrong-password code reports a user event.
- The network-unreachable code reports a connectivity problem outside authentication.
Related reasons:
entra_token_acquisition_failed: a token that was not obtained, rather than a credential refused
entra_token_acquisition_failed
The device failed to get a token for a cloud resource.
Severity: Info where the library is asking for a sign-in, Notice for a transport failure, Warning where a tenant setting refused the request.
Impact: The resource behind that token is unavailable to the user until the cause is fixed. A tenant configuration error affects every device in the tenant.
Channel: Microsoft-Windows-AAD/Operational
Provider: Microsoft-Windows-AAD
Event ids: 1084, 1094, 1097, 1098, 1112, 1155, 1202, 1215
| Case | Severity | Ticket class |
|---|---|---|
interaction_required | Info | auth |
configuration | Warning | auth |
transport | Notice | auth |
unclassified | Notice to Warning | auth |
Where to look next:
- Group by the error message across a day on one host.
- A transport error points to a network or proxy problem.
- A grant or consent error points to a tenant configuration problem, and no work on the device fixes that.
- An interaction-required message reports normal sign-in flow.
Related reasons:
entra_device_certificate_update_failed: the device's own identity certificate rather than a user tokenentra_sign_in_failed: a credential refused, rather than a token not obtained
Fields it can set: win.eventlog.identity_security.correlation_id, win.eventlog.identity_security.entra_error_message
exploit_mitigation_audit_would_block
Exploit protection recorded that enforcement would have stopped a process, under audit mode.
Severity: Info
Channel: Microsoft-Windows-Security-Mitigations/KernelMode
Provider: Microsoft-Windows-Security-Mitigations
Event ids: 1, 3, 11
Where to look next:
- This is a heads-up: nothing was denied on this device.
- An engineer moving this mitigation to enforcement needs this record to know what it would hit.
Related reasons:
exploit_mitigation_blocked: the same mitigation under enforcement, actually stopping the processexploit_mitigation_shadow_stack_mismatch: a memory-integrity anomaly rather than a policy block
Fields it can set: win.eventlog.identity_security.mitigation_process
exploit_mitigation_blocked
Exploit protection stopped a process from an action its policy forbids, under enforcement.
Severity: Notice or Verbose
Channel: Microsoft-Windows-Security-Mitigations/KernelMode
Provider: Microsoft-Windows-Security-Mitigations
Event ids: 2, 4, 6, 10, 12, 32, 34, 36
| Case | Severity | Ticket class | Event ids |
|---|---|---|---|
designed_sandbox | Verbose | security_audit | 2, 4, 6, 10, 12, 32, 34, 36 |
unexpected_caller | Notice | security_audit | 2, 4, 6, 10, 12, 32, 34, 36 |
Where to look next:
- Pivot on the image path, because the event count carries no meaning by itself.
- A path producing these events for weeks is normal.
- A path appearing for the first time flags an application that just broke, and this mitigation caused the break.
Related reasons:
exploit_mitigation_audit_would_block: the same mitigation in audit mode, only recording what it would doexploit_mitigation_shadow_stack_mismatch: a memory-integrity anomaly rather than a policy block
Fields it can set: win.eventlog.identity_security.mitigation_process
The enforcing records on the kernel-mode id that arrives at volume are rate-bounded: three per image path per device per day, with the count of what a day suppressed carried on the next day's first record. Read the paths, not the counts.
exploit_mitigation_shadow_stack_mismatch
A process returned to a different address from the one the hardware shadow stack recorded, and the platform either allowed it to continue or refused the operation.
Severity: Notice on the documented compatibility path, Warning where nothing on the event explains the mismatch.
Impact: Where the operation was refused, whatever the process was attempting did not happen. Where it continued, nothing changed.
Channel: Microsoft-Windows-Security-Mitigations/KernelMode
Provider: Microsoft-Windows-Security-Mitigations
Event ids: 25, 28
| Case | Severity | Ticket class | Event ids |
|---|---|---|---|
not_enforced | Notice to Warning | security_audit | 25 |
blocked | Warning | security_audit | 28 |
Where to look next:
- Read the image name and the nonenforcement reason together.
- A recognized application with a known compatibility reason is the ordinary case.
- The same reason on a process with no business rewriting return addresses is worth investigating.
Related reasons:
exploit_mitigation_blocked: a policy block rather than a memory-integrity anomaly
Fields it can set: win.eventlog.identity_security.mitigation_process, win.eventlog.identity_security.shadow_stack_control_pc_image, win.eventlog.identity_security.shadow_stack_nonenforcement_reason
group_policy_domain_controller_unresolved
The machine could not find or could not reach a domain controller.
Severity: Warning or Notice
Impact: Everything downstream of that step fails: no policy applies, and the device cannot register either.
Channel: Microsoft-Windows-GroupPolicy/Operational
Provider: Microsoft-Windows-GroupPolicy
Event ids: 7017, 7320, 7326
| Case | Severity | Ticket class |
|---|---|---|
domain_unresolved | Notice | device_management |
access_denied | Warning | device_management |
discovery_failed | Notice | device_management |
Where to look next:
- A no-such-domain code means the domain itself failed to resolve, which is a name-resolution or connectivity problem.
- An access-denied code means the machine account is the problem.
- Read this alongside device registration: a device that cannot find a controller cannot register either.
Related reasons:
device_registration_failed: the same directory being unreachable, reported from registrationgroup_policy_processing_failed: a pass that started and failed
Fields it can set: win.eventlog.identity_security.gp_dc_discovery_ms
group_policy_extension_apply_failed
A Group Policy client-side extension could not apply the settings from a policy object.
Also reported by: Windows Application event log
Severity: Minor or Info
Impact: None of that policy object's items were delivered to the affected user or machine on this refresh.
Channel: Microsoft-Windows-GroupPolicy/Operational
Provider: Microsoft-Windows-GroupPolicy
Event ids: 6016, 7016
| Case | Severity | Ticket class |
|---|---|---|
deferred | Info | device_management |
share_unreachable | Minor | device_management |
extension_failed | Minor | device_management |
Where to look next:
- Read the extension name and the code together.
- A network path error on the drive-maps or folder-redirection extension means the machine could not reach the policy share.
- An access-denied error on the security extension means the policy object itself has a permissions problem.
Related reasons:
group_policy_processing_failed: the whole policy pass failing rather than one extension
Fields it can set: win.eventlog.identity_security.gp_extension_id, win.eventlog.identity_security.gp_extension_name
group_policy_file_share_unhardened
The machine reads Group Policy files from a file share without mutual authentication or integrity protection.
Severity: Notice
Impact: An attacker on the network path between the machine and the policy share could tamper with policy content in transit. Nothing has gone wrong yet.
Channel: Microsoft-Windows-GroupPolicy/Operational
Provider: Microsoft-Windows-GroupPolicy
Event ids: 9001
Where to look next:
- Compare the hosts producing this event against the domain's hardened-paths policy.
- Deliver the mismatched devices as a list for a security review.
Related reasons:
smb_security_setting_nondefault: a related SMB hardening setting worth checking on the same device
Fields it can set: win.eventlog.identity_security.gp_integrity_enforced, win.eventlog.identity_security.gp_mutual_auth_enforced
group_policy_processing_failed
Group Policy failed to apply for that boot or that logon.
Severity: Notice on a device that moves and loses the corporate network, Warning otherwise.
Impact: That machine enforces none of the customer's expected settings for that session, and runs whatever policy it last cached.
Channel: Microsoft-Windows-GroupPolicy/Operational
Provider: Microsoft-Windows-GroupPolicy
Event ids: 7000, 7001
| Case | Severity | Ticket class |
|---|---|---|
no_network | Notice to Warning | device_management |
other_failure | Warning | device_management |
Where to look next:
- Read the connectivity flag first.
- A portable device booting away from the corporate network produces exactly this event.
- The same event on a desktop is a real problem.
Related reasons:
group_policy_domain_controller_unresolved: no controller found at all, so no pass startedgroup_policy_extension_apply_failed: one extension failing rather than the whole pass
Fields it can set: win.eventlog.identity_security.gp_connectivity_failure, win.eventlog.identity_security.gp_elapsed_seconds, win.eventlog.identity_security.gp_is_machine
laps_password_backup_failed
The device manages its local administrator password and the backup of that password is failing.
Severity: Warning
Impact: The password rotates on schedule and nobody can retrieve it, so a local sign-in that needs it will fail. The compliance claim that the password is escrowed is not true.
Channel: Microsoft-Windows-LAPS/Operational
Provider: Microsoft-Windows-LAPS
Event ids: 10005, 10026, 10028, 10032, 10059
| Case | Severity | Ticket class |
|---|---|---|
tenant_not_enabled | Warning | auth |
authentication | Warning | auth |
backup_failed | Warning | auth |
Where to look next:
- Read the response body on the id that carries it.
- A tenant-side not-enabled message means someone deployed the policy to devices before configuring the tenant.
- Every device carrying that policy rotates a password no one can retrieve.
Related reasons:
bitlocker_recovery_key_backup_failed: the same escrow-failure pattern for BitLocker recovery keys
ntlm_authentication_used
This machine used the legacy NTLM authentication protocol, as a client or as a server.
Severity: Warning or Notice
Impact: Nothing failed. Where the first version of the protocol was used, the credential on that session carried a weakness the vendor has documented for a decade.
Channel: Microsoft-Windows-NTLM/Operational
Provider: Microsoft-Windows-NTLM
Event ids: 4020, 4021, 4022, 4023
| Case | Severity | Ticket class |
|---|---|---|
legacy_version | Warning | auth |
outbound | Notice | auth |
inbound | Notice | auth |
Where to look next:
- Use this as the audit trail for retiring the protocol.
- Focus on rows carrying the first version of the protocol and rows showing an anonymous principal.
Related reasons:
ntlm_validation_failed: an NTLM authentication that was refused rather than one that succeeded
Fields it can set: win.eventlog.identity_security.ntlm_channel_binding, win.eventlog.identity_security.ntlm_mic_status, win.eventlog.identity_security.ntlm_usage_reason, win.eventlog.identity_security.ntlm_version
vbs_key_isolation_failed
The isolated key environment that virtualization-based security provides is failing on this device.
Severity: Notice or Info
Impact: Keys that should be held in hardware-isolated memory are not. Every caller keeps working, so nothing is unavailable.
Channel: Microsoft-Windows-Crypto-NCrypt/Operational
Provider: Microsoft-Windows-Crypto-NCrypt
Event ids: 13, 26
| Case | Severity | Ticket class |
|---|---|---|
unavailable | Info | certificates |
isolation_failed | Notice | certificates |
Where to look next:
- Check whether virtualization-based security should be on for this device.
- Where the platform states the feature cannot be enabled, the hardware or firmware cannot support it and retrying will not change the outcome.
Related reasons:
crypto_key_operation_failed: one key operation failing rather than the environment behind it
Fields it can set: win.eventlog.identity_security.crypto_function, win.eventlog.identity_security.vbs_can_be_enabled, win.eventlog.identity_security.vbs_restart_attempts, win.eventlog.identity_security.vbs_restart_successes
windows_hello_key_registration_failed
A Windows Hello key or container operation failed after provisioning had already passed its prerequisites.
Severity: Notice or Info
Impact: That user's Windows Hello credential is not usable on this device until it is enrolled again. Signing in with a password is unaffected.
Channel: Microsoft-Windows-User Device Registration/Admin, Microsoft-Windows-HelloForBusiness/Operational
Provider: Microsoft-Windows-User Device Registration, Microsoft-Windows-HelloForBusiness
Event ids: 303, 310, 311, 317, 385, 6010, 7002, 7611
| Case | Severity | Ticket class |
|---|---|---|
no_attestation_hardware | Info | auth |
user_cancelled | Info | auth |
key_operation_failed | Notice | auth |
Where to look next:
- Read the key status.
- The attestation-capability status is a hardware fact only.
- A container error or a key error means the user's Windows Hello credential is gone, so re-enroll it.
Related reasons:
windows_hello_provisioning_blocked: provisioning that never started because a prerequisite was not met
Fields it can set: win.eventlog.identity_security.whfb_key_status
windows_hello_provisioning_blocked
Windows Hello for Business will not set up on this device for this user.
Severity: Notice or Info
Impact: The user signs in with a password instead. Where a policy does ask for the feature, a passwordless rollout is quietly not happening.
Channel: Microsoft-Windows-User Device Registration/Admin, Microsoft-Windows-HelloForBusiness/Operational
Provider: Microsoft-Windows-User Device Registration, Microsoft-Windows-HelloForBusiness
Event ids: 359, 360, 6045, 6055, 7054, 7200, 7201, 7203
| Case | Severity | Ticket class | Event ids |
|---|---|---|---|
not_configured | Info | auth | |
remote_session | Info | auth | |
prerequisite_unmet | Notice | auth | 7054, 7200, 7201, 7203 |
declined | Notice | auth |
Where to look next:
- Read the checklist, where each No reports one configuration fact.
- If the policy is enabled, the device is joined, and the feature still will not launch, the remaining No is the ticket.
Related reasons:
windows_hello_key_registration_failed: provisioning that was attempted and whose key operation then failed
Fields it can set: win.eventlog.identity_security.whfb_device_joined, win.eventlog.identity_security.whfb_hardware_met, win.eventlog.identity_security.whfb_policy_enabled, win.eventlog.identity_security.whfb_primary_refresh_token, win.eventlog.identity_security.whfb_user_remote
Ask this feed a question
Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.