Windows management event channels
Scheduled and remote management, servicing, backup, virtualization and print channels, bound as one feed: Task Scheduler, WMI, WinRM, Windows Update, BITS, VSS, Hyper-V, MDM and provisioning, Server Manager, printing, licensing. Unread channels keep the severity the provider stated, capped at Warning. Measured clockwork telemetry is dropped by provider and event id. Twenty curated reasons over scheduled tasks, Windows Update, DFS Replication, printing, device management, locale and Hyper-V, plus a pinned band for every measured no-reason family.
Feed id: win.eventlog.management.
Channels
This feed binds 42 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.
| Channel | Ticket class |
|---|---|
DFS Replication | directory_services |
Microsoft-Client-Licensing-Platform/Admin | licensing |
Microsoft-Windows-Bits-Client/Operational | patching |
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin | device_management |
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Autopilot | device_management |
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Enrollment | device_management |
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Operational | device_management |
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Sync | device_management |
Microsoft-Windows-FileShareShadowCopyProvider/Operational | backup |
Microsoft-Windows-HostGuardianService-Client/Operational | virtualization |
Microsoft-Windows-Hyper-V-Compute-Admin | virtualization |
Microsoft-Windows-Hyper-V-Compute-Operational | virtualization |
Microsoft-Windows-Hyper-V-Hypervisor-Admin | virtualization |
Microsoft-Windows-Hyper-V-Hypervisor-Operational | virtualization |
Microsoft-Windows-Hyper-V-StorageVSP-Admin | virtualization |
Microsoft-Windows-Hyper-V-VMMS-Admin | virtualization |
Microsoft-Windows-Hyper-V-VMMS-Networking | virtualization |
Microsoft-Windows-Hyper-V-VMMS-Operational | virtualization |
Microsoft-Windows-Hyper-V-Worker-Admin | virtualization |
Microsoft-Windows-Hyper-V-Worker-Operational | virtualization |
Microsoft-Windows-International/Operational | user_profiles |
Microsoft-Windows-LanguagePackSetup/Operational | patching |
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Admin | device_management |
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot | device_management |
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Diagnostics | device_management |
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService | device_management |
Microsoft-Windows-MUI/Operational | patching |
Microsoft-Windows-PrintBRM/Admin | printing |
Microsoft-Windows-PrintService/Admin | printing |
Microsoft-Windows-PrintService/Operational (disabled by default on client Windows; enable it on the host to produce data) | printing |
Microsoft-Windows-Provisioning-Diagnostics-Provider/Admin | device_management |
Microsoft-Windows-Provisioning-Diagnostics-Provider/AutoPilot | device_management |
Microsoft-Windows-Provisioning-Diagnostics-Provider/ManagementService | device_management |
Microsoft-Windows-Security-SPP-UX-Notifications/ActionCenter | licensing |
Microsoft-Windows-ServerManager-DeploymentProvider/Operational | patching |
Microsoft-Windows-ServerManager-MgmtProvider/Operational | |
Microsoft-Windows-TaskScheduler/Operational | scheduled_tasks |
Microsoft-Windows-VHDMP-Operational | virtualization |
Microsoft-Windows-VolumeSnapshot-Driver/Operational | backup |
Microsoft-Windows-WindowsUpdateClient/Operational | patching |
Microsoft-Windows-WinRM/Operational | rmm |
Microsoft-Windows-WMI-Activity/Operational | rmm |
Fields
| Field | Type | Unit | Meaning |
|---|---|---|---|
win.eventlog.management.job_name | string | BITS transfer job display name from Bits-Client 61 (name), e.g. the update-download job a servicing client created. The recurrence pivot for a transfer that keeps failing. | |
win.eventlog.management.task_name | string | Scheduled task path from the Task Scheduler failure ids (TaskName), e.g. \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker. The recurrence pivot for one task that keeps failing to start or to load. | |
win.eventlog.management.task_error_description | string | The internal operation Task Scheduler names beside the failure on ids 104 and 311 (ErrorDescription), e.g. the logon call or the elevation check that returned the code. | |
win.eventlog.management.task_engine_command | string | Host process Task Scheduler tried to start for a task engine, from TaskScheduler 311 (Command). | |
win.eventlog.management.update_service_id | string | Identifier of the update service a scan was run against, from WindowsUpdateClient 25 (serviceGuid), casefolded. Separates a local update server from the public update service. | |
win.eventlog.management.update_title | string | Display title of the update whose download failed, from WindowsUpdateClient 31 (updateTitle). | |
win.eventlog.management.printer_driver_name | string | Printer driver a failed install was for, from the PrintService driver ids (DriverName, Driver or ObjectName). The pivot that collapses one hash per driver name into one group. | |
win.eventlog.management.driver_install_stage | string | Stage of the driver install the spooler was in when it failed, from the PrintService driver ids (Label). | |
win.eventlog.management.driver_install_message | string | The spooler operation that returned the failure on a driver install, from the PrintService driver ids (Message). Separates a real add or import from a driver-store lookup. | |
win.eventlog.management.bitlocker_drive_role | string | Drive role a BitLocker compliance check was about, from DeviceManagement 2900 (Message1), e.g. the operating-system volume or a fixed data volume. | |
win.eventlog.management.bitlocker_fve_status | string | Raw BitLocker status bitmask the device management client reported beside a compliance failure (HexInt1). Promoted undecoded: no published value map was read for it. | |
win.eventlog.management.bitlocker_method_found | string | Encryption method the operating-system volume is actually using, from DeviceManagement 2902 (HexInt1). | |
win.eventlog.management.bitlocker_method_wanted | string | Encryption method the policy requires for the operating-system volume, from DeviceManagement 2902 (HexInt2). | |
win.eventlog.management.mdm_csp_uri | string | Configuration node a management command was addressed to, from the MDM ConfigurationManager ids (Message5). The pivot that says WHICH setting did not take effect. | |
win.eventlog.management.mdm_policy_area | string | Policy area a management setting belongs to, from the MDM PolicyManager ids (Message1). | |
win.eventlog.management.mdm_policy_name | string | Policy setting a management command tried to set, from the MDM PolicyManager ids (Message2). | |
win.eventlog.management.locale_registry_key | string | Registry key holding the locale settings a process could not read, from International 1001 (RegistryKey). Separates a machine-wide fault from a per-user one. | |
win.eventlog.management.vm_name | string | Virtual machine an event is about, from the Hyper-V ids (VmName). An administrator-chosen machine label and the pivot every virtualization reason here needs. | |
win.eventlog.management.vm_storage_request_ms | int | Milliseconds one guest storage request took to complete, from Hyper-V-StorageVSP 9 (Duration). | |
win.eventlog.management.vm_storage_opcode | int | SCSI operation code of the guest storage request, from Hyper-V-StorageVSP 9 (Command). Promoted as the number: no constant-name table is claimed for it here. | |
win.eventlog.management.vm_storage_transfer_bytes | int | Bytes the guest storage request was transferring, from Hyper-V-StorageVSP 9 (DataTransferLength). | |
win.eventlog.management.vhd_parent_guid_expected | string | Parent identity a differencing virtual disk expected, from VHDMP 7 (ExpectedParentLastWriteGUID1). | |
win.eventlog.management.vhd_parent_guid_actual | string | Parent identity the parent virtual disk actually carries, from VHDMP 7 (ParentLastWriteGUID). Differs from the expected one when the chain is broken. | |
win.eventlog.management.replica_retry_minutes | int | Minutes Hyper-V will wait before retrying replication for a virtual machine, from VMMS 32315 (Parameter0). |
Severity
A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.
Curated reasons
Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.
| Reason | Ticket class | Severity |
|---|---|---|
bitlocker_policy_noncompliant | device_management | Warning where the operating-system volume is the one out of compliance. Notice for a data volume or where the event cannot say which drive it is about. |
bits_transfer_failed | patching | Warning |
dfsr_partner_communication_failed | directory_services | Warning |
dfsr_replication_stopped | directory_services | Serious or Warning |
dfsr_sysvol_initial_sync_pending | directory_services | Warning |
hyperv_replication_failed | virtualization | Warning or Notice |
hyperv_vm_backup_checkpoint_failed | virtualization | Warning, Notice or Info |
hyperv_vm_start_failed | virtualization | Warning |
hyperv_vm_storage_request_slow | virtualization | Warning for a slow request. Minor where the request took more than thirty seconds. |
hyperv_vm_vhd_chain_corrupted | virtualization | Serious or Info |
mdm_policy_apply_failed | device_management | Warning, Notice or Info |
patch_download_failed | patching | Warning |
patch_scan_failed | patching | Warning or Info |
print_connection_reopen_failed | printing | Warning or Info |
printer_driver_install_failed | printing | Warning where an add or an import failed. Notice where the spooler was only asking the driver store whether it already held the driver. |
scheduled_task_engine_failed | scheduled_tasks | Warning or Info |
scheduled_task_load_failed | scheduled_tasks | Warning |
scheduled_task_sign_in_failed | scheduled_tasks | Warning |
scheduled_task_start_failed | scheduled_tasks | Warning where a named automation stopped running. Lower where the task ships with Windows and the program it points at was removed by Windows. |
win_locale_registry_read_failed | user_profiles | Warning |
bitlocker_policy_noncompliant
A device does not match the BitLocker encryption policy set for it: a drive is unencrypted, or encrypted with a method or scope the policy does not allow.
Severity: Warning where the operating-system volume is the one out of compliance. Notice for a data volume or where the event cannot say which drive it is about.
Impact: An unencrypted operating-system volume means every file on the machine is readable to anyone who takes it.
Channel: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin
Provider: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider
Event ids: 2900, 2902, 2903, 2905, 2906, 2910, 2914
Where to look next:
- Read the drive role first, then the drive status bits.
- Two of these event ids cannot say which drive they are about. Pair them with the device's own encryption state.
- This repeats at the management sync cadence, so one device produces many records for one finding.
Related reasons:
bitlocker_recovery_key_backup_failed:device_encryption_enable_failed: the automatic-encryption failure that can leave a device in this noncompliant state
Fields it can set: win.eventlog.management.bitlocker_drive_role, win.eventlog.management.bitlocker_fve_status, win.eventlog.management.bitlocker_method_found, win.eventlog.management.bitlocker_method_wanted
The management client is the authority on what the policy requires. The device's own state reading says what the volume is, without knowing the policy.
bits_transfer_failed
A Background Intelligent Transfer Service job reported an error on one transfer attempt.
Severity: Warning
Channel: Microsoft-Windows-Bits-Client/Operational
Provider: Microsoft-Windows-Bits-Client
Event ids: 61
Where to look next:
- Pivot on the job name and the result code to find a destination or a code that keeps repeating.
- For an update download, read the outcome from the Windows Update records in the Setup channel.
Related reasons:
patch_download_failed: a Windows Update download failure BITS problems can also cause
Fields it can set: win.eventlog.management.job_name
BITS retries a failed transfer, so these records come in runs. The stream is rate-bounded: one record per job and result code per device per hour, with the count of what an hour suppressed carried on the next hour's first record. A job and code that reappear hour after hour, with no completed transfer between them, is the shape worth reading.
dfsr_partner_communication_failed
DFS Replication could not reach a replication partner for a replication group.
Severity: Warning
Impact: Content does not converge with that partner while the link is down.
Channel: DFS Replication
Provider: DFSR
Event ids: 5002, 5008, 5012, 5014
Where to look next:
- Read the rate against the service's own reconnection records on the same host.
- A link that flaps and recovers is ordinary on a wide-area connection.
Related reasons:
dfsr_replication_stopped: A link that never comes back ends here.
The partner and the replication group are named in the message text rather than in fields, because these events carry no named payload.
dfsr_replication_stopped
DFS Replication stopped replicating a folder or a volume, or stopped because it could not read its own configuration.
Severity: Serious or Warning
Impact: Every member of that replication group keeps serving its own copy, and the copies diverge with nothing visible to the people using them.
Channel: DFS Replication
Provider: DFSR
Event ids: 1202, 2004, 2104, 4004, 4012
| Case | Severity | Ticket class | Event ids |
|---|---|---|---|
offline_too_long | Serious | directory_services | 4012 |
folder_stopped | Serious | directory_services | 2004, 2104, 4004 |
config_unreachable | Warning | directory_services | 1202 |
Where to look next:
- The offline-too-long case needs a deliberate resume. It will not restart by itself.
- A database recovery failure on a volume needs the replication database rebuilt.
- Check the folder's other members before resuming, so the copy that wins is the one you want.
Related reasons:
dfsr_partner_communication_failed: One link is failing, rather than replication being stopped.dfsr_sysvol_initial_sync_pending: A SYSVOL copy that has never synchronised at all.
The replicated folder, the partner and the directory server are named in the message text rather than in fields, because these events carry no named payload.
dfsr_sysvol_initial_sync_pending
A server holds a SYSVOL copy that has never completed its first synchronisation with a partner.
Severity: Warning
Impact: Policy and logon scripts are not served from that copy, and a domain controller promotion that was in progress has not finished.
Channel: DFS Replication
Provider: DFSR
Event ids: 4612, 4614
Where to look next:
- Check whether the named partner is reachable and replicating.
- This does not resolve on its own if the partner never answers.
Related reasons:
dfsr_replication_stopped: Replication that was working and has stopped.
The partner and the local path are named in the message text rather than in fields, because these events carry no named payload.
hyperv_replication_failed
Hyper-V could not replicate a virtual machine to its replica server.
Severity: Warning or Notice
Impact: The recovery copy of that machine stops being updated and gets older, with nothing visible to anyone using the machine.
Channel: Microsoft-Windows-Hyper-V-VMMS-Admin
Provider: Microsoft-Windows-Hyper-V-VMMS
Event ids: 29292, 29312, 32022, 32315, 32552, 33676
| Case | Severity | Ticket class | Event ids |
|---|---|---|---|
retrying | Warning | virtualization | 32315 |
unreachable | Warning | virtualization | 29292, 29312, 32022, 32552 |
state_conflict | Notice | virtualization | 33676 |
Where to look next:
- Check whether the replica server is reachable at all: the server and port are named in the message text.
- A stated retry means the host will try again on its own. Repeated unreachable records are the ones that matter.
Related reasons:
hyperv_vm_backup_checkpoint_failed: the same host's checkpoint failures, another sign VM protection is brokenhyperv_vm_vhd_chain_corrupted: a broken checkpoint chain that can also break replication
Fields it can set: win.eventlog.management.replica_retry_minutes, win.eventlog.management.vm_name
The machine keeps running throughout, so nobody finds out the copy is stale until they need it.
hyperv_vm_backup_checkpoint_failed
A backup of a virtual machine did not take a consistent snapshot.
Severity: Warning, Notice or Info
Impact: The backup either did not run or ran without being application-consistent, so the restore point it produced is weaker than it looks.
Channel: Microsoft-Windows-Hyper-V-VMMS-Admin, Microsoft-Windows-Hyper-V-Worker-Admin
Provider: Microsoft-Windows-Hyper-V-VMMS, Microsoft-Windows-Hyper-V-Worker, Microsoft-Windows-Hyper-V-Integration
Event ids: 3280, 4093, 10150, 10172, 18012
| Case | Severity | Ticket class |
|---|---|---|
serialisation_wait | Info | virtualization |
checkpoint_failed | Warning | virtualization |
guest_writer_failed | Warning | virtualization |
integration_service_disabled | Notice | virtualization |
Where to look next:
- Read the result code: a snapshot set already in progress is two jobs overlapping and is fixed by scheduling.
- A file-already-exists result is a stale checkpoint file left behind by an earlier failure.
- The integration-service line is a per-machine setting rather than a failure of this run.
Related reasons:
hyperv_vm_vhd_chain_corrupted: A broken disk chain is one reason a checkpoint cannot be created.
Fields it can set: win.eventlog.management.vm_name
A failed guest writer still usually leaves a crash-consistent copy, which is not the same as no backup at all.
hyperv_vm_start_failed
A virtual machine, or the worker process that runs one, did not start.
Severity: Warning
Impact: A workload that was supposed to be running is not, and on the memory ids the host did not have room for it.
Channel: Microsoft-Windows-Hyper-V-VMMS-Admin, Microsoft-Windows-Hyper-V-Worker-Admin
Provider: Microsoft-Windows-Hyper-V-VMMS, Microsoft-Windows-Hyper-V-Worker
Event ids: 3050, 3122, 15130, 15500
Where to look next:
- Check the host's free memory when the worker ids are the ones reporting.
- The machine name is the pivot: one machine failing every start is a different ticket from a host that is full.
Related reasons:
hyperv_vm_backup_checkpoint_failed: A different Hyper-V failure on the same machines.
Fields it can set: win.eventlog.management.vm_name
These templates carry no result code, so the machine name and the id are what the row offers.
hyperv_vm_storage_request_slow
A storage request a virtualization host made for one of its guests took longer than expected to complete.
Severity: Warning for a slow request. Minor where the request took more than thirty seconds.
Impact: Every guest on that host shares the same storage path, so a steady rate of these degrades all of them.
Channel: Microsoft-Windows-Hyper-V-StorageVSP-Admin
Provider: Microsoft-Windows-Hyper-V-StorageVSP
Event ids: 9
Where to look next:
- Read the rate before the duration: one slow request is a flake.
- The virtual disk the request was against is named in the message text.
Related reasons:
disk_latency_degraded: the host-level storage latency condition this guest slowness may share
Fields it can set: win.eventlog.management.vm_storage_opcode, win.eventlog.management.vm_storage_request_ms, win.eventlog.management.vm_storage_transfer_bytes
The duration measures one request rather than how long a condition has held.
hyperv_vm_vhd_chain_corrupted
A differencing virtual disk and its parent disagree on the parent identity, so the disk chain cannot be merged or checkpointed.
Severity: Serious or Info
Impact: Checkpoints and backups of that machine are not usable, and the chain grows while the merge keeps failing.
Channel: Microsoft-Windows-VHDMP-Operational, Microsoft-Windows-Hyper-V-VMMS-Admin
Provider: Microsoft-Windows-VHDMP, Microsoft-Windows-Hyper-V-VMMS
Event ids: 7, 16370, 19100
| Case | Severity | Ticket class |
|---|---|---|
chain_broken | Serious | virtualization |
file_in_use | Info | virtualization |
Where to look next:
- Stop taking checkpoints of that machine and repair the chain before anything merges it.
- Watch the volume the chain lives on: a merge that keeps failing is how it fills.
Related reasons:
hyperv_vm_backup_checkpoint_failed: The backup checkpoint that a broken chain stops from being taken.
Fields it can set: win.eventlog.management.vhd_parent_guid_actual, win.eventlog.management.vhd_parent_guid_expected, win.eventlog.management.vm_name
The machine keeps running while this holds, so nothing else reports it until a restore is attempted.
mdm_policy_apply_failed
A device management command did not take effect on the device.
Severity: Warning, Notice or Info
Impact: A setting the MSP believes is enforced is not enforced, and the management console will not say so.
Channel: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin, Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Sync, Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Enrollment
Provider: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider
Event ids: 201, 404, 454, 806, 821, 4022
| Case | Severity | Ticket class |
|---|---|---|
node_absent | Info | device_management |
throttled | Info | device_management |
access_denied | Warning | device_management |
other_result | Notice | device_management |
Where to look next:
- Read the status word before the wording: two of the common outcomes here are not failures.
- On a refusal, the configuration node path and the policy name say which setting is missing.
Related reasons:
bitlocker_policy_noncompliant: The device reporting that it does not match an encryption policy.
Fields it can set: win.eventlog.management.mdm_csp_uri, win.eventlog.management.mdm_policy_area, win.eventlog.management.mdm_policy_name
This family repeats at the management sync cadence, so one unresolved setting produces many records.
patch_download_failed
Windows Update could not download an update the device needed.
Severity: Warning
Impact: That update is not installed and will not be until a later attempt succeeds.
Channel: Microsoft-Windows-WindowsUpdateClient/Operational
Provider: Microsoft-Windows-WindowsUpdateClient
Event ids: 31
Where to look next:
- Read the code beside the update title: disk space and memory are the usual causes.
- A device failing every download is a different ticket from one that cannot reach the service.
Related reasons:
patch_scan_failed: The device could not find out what it needed in the first place.
Fields it can set: win.eventlog.management.update_title
The client retries on its own cycle, so a single record is not proof the update is stuck.
patch_scan_failed
A Windows Update scan did not complete, so the device was offered no updates on that cycle.
Severity: Warning or Info
Impact: A device that keeps failing its scans stops being patched, with no symptom a user would notice.
Channel: Microsoft-Windows-WindowsUpdateClient/Operational
Provider: Microsoft-Windows-WindowsUpdateClient
Event ids: 25
| Case | Severity | Ticket class |
|---|---|---|
service_unreachable | Warning | patching |
bad_criteria | Info | patching |
other_failure | Warning | patching |
Where to look next:
- Read the code and the update service identifier together: they separate an unreachable service from a caller defect.
- The rate matters more than one record: a host failing every cycle is the ticket.
Related reasons:
patch_download_failed: The updates were found and the download failed.
Fields it can set: win.eventlog.management.update_service_id
The update client retries on its own cycle, so single records are expected on a healthy device.
print_connection_reopen_failed
The print spooler could not read one profile's saved printer connections when it restarted.
Severity: Warning or Info
Impact: On a real user's profile, their mapped printers are gone until they reconnect or sign in again.
Channel: Microsoft-Windows-PrintService/Operational
Provider: Microsoft-Windows-PrintService
Event ids: 603
| Case | Severity | Ticket class |
|---|---|---|
user_profile | Warning | printing |
service_profile | Info | printing |
Where to look next:
- The same user on the same host at every spooler restart is the signal, rather than a single record.
Related reasons:
printer_driver_install_failed: a driver failure that can also leave printer connections unusable
Built-in service accounts produce this line as a matter of course, because they have no printer connections saved.
printer_driver_install_failed
A printer driver did not install, and the stage and code say which part of the install failed.
Severity: Warning where an add or an import failed. Notice where the spooler was only asking the driver store whether it already held the driver.
Impact: The print queue that needed the driver does not work, and on a print server that affects everyone who prints to it.
Channel: Microsoft-Windows-PrintService/Admin, Microsoft-Windows-PrintService/Operational
Provider: Microsoft-Windows-PrintService
Event ids: 213, 215, 217, 219, 225, 600, 601, 869
Where to look next:
- Read the stage and the operation name first, then the code.
- An access-denied result is a permissions problem on the driver store. A rejected signature is a driver the machine will not accept at all.
- Pivot on the driver name to tell one broken driver from a broken deployment.
Related reasons:
print_connection_reopen_failed: the reconnect failure users see after a driver problemrds_redirected_printer_setup_failed: the same driver dependency failing for a redirected session printer
Fields it can set: win.eventlog.management.driver_install_message, win.eventlog.management.driver_install_stage, win.eventlog.management.printer_driver_name
One install attempt can report from several of these ids, on both print channels.
scheduled_task_engine_failed
Task Scheduler could not start the host process a scheduled task runs inside.
Severity: Warning or Info
Impact: Where the cause is not an absent session, nothing scheduled runs on that machine while it holds.
Channel: Microsoft-Windows-TaskScheduler/Operational
Provider: Microsoft-Windows-TaskScheduler
Event ids: 311
| Case | Severity | Ticket class |
|---|---|---|
no_user_session | Info | scheduled_tasks |
engine_unavailable | Warning | scheduled_tasks |
Where to look next:
- Read the result code before the wording: a not-logged-on code means a per-user engine had no session to start in.
- Any other cause is worth checking against whether the machine's other scheduled work is running.
Related reasons:
scheduled_task_start_failed: One task did not start, rather than the engine that runs them.
Fields it can set: win.eventlog.management.task_engine_command, win.eventlog.management.task_error_description
A per-user task engine only starts when that user has a session, so this line is expected on a machine nobody is signed in to.
scheduled_task_load_failed
A scheduled task definition could not be read at service start, so the task is not in the schedule at all.
Severity: Warning
Impact: The task is gone rather than failing, so nothing else reports that its work has stopped.
Channel: Microsoft-Windows-TaskScheduler/Operational
Provider: Microsoft-Windows-TaskScheduler
Event ids: 146, 151
Where to look next:
- Re-register the task from source.
- Check the other tasks registered by the same tool, which often go together.
Related reasons:
scheduled_task_start_failed: The task is in the schedule and its runs are failing.
Fields it can set: win.eventlog.management.task_name
The two event ids report one load attempt twice, so they arrive as a pair for the same task.
scheduled_task_sign_in_failed
Task Scheduler could not log on as the account a scheduled task stores, so the task did not run.
Severity: Warning
Impact: Every task registered to that account is in the same state, and none of them is running.
Channel: Microsoft-Windows-TaskScheduler/Operational
Provider: Microsoft-Windows-TaskScheduler
Event ids: 104
Where to look next:
- Re-register the task with a current credential.
- Pivot on the account rather than the task: one changed password stops every task that stores it.
Related reasons:
scheduled_task_start_failed: The task started and the launch failed, rather than the logon.
Fields it can set: win.eventlog.management.task_error_description
A service-account password change is the usual cause, and the tasks stop silently.
scheduled_task_start_failed
A scheduled task did not run, and the result code says whether the program was missing, the identity was refused, or the action itself failed.
Severity: Warning where a named automation stopped running. Lower where the task ships with Windows and the program it points at was removed by Windows.
Impact: Whatever that task does is not being done. On a backup pre-job or a patch orchestration task, that is a gap nothing else reports.
Channel: Microsoft-Windows-TaskScheduler/Operational
Provider: Microsoft-Windows-TaskScheduler
Event ids: 101, 103, 202, 203
| Case | Severity | Ticket class |
|---|---|---|
missing_action | Debug to Warning | scheduled_tasks |
access_denied | Warning | scheduled_tasks |
other_failure | Warning | scheduled_tasks |
Where to look next:
- Read the result code first, then the task path.
- A missing program on a management, backup or patch task is a broken automation nobody will notice any other way.
- Pivot on the task path to see whether one task fails every time it is triggered.
Related reasons:
scheduled_task_load_failed: The task never entered the scheduler at all, rather than failing to start.scheduled_task_sign_in_failed: The stored run-as credential was refused.
Fields it can set: win.eventlog.management.task_name
The four event ids report one launch from four places, so a single failed run can produce more than one of them.
win_locale_registry_read_failed
A process could not open the registry key holding the machine or user locale settings, and fell back to a default.
Severity: Warning
Impact: Nothing is unavailable while this fires. It points at profile or permission damage on that host.
Channel: Microsoft-Windows-International/Operational
Provider: Microsoft-Windows-International
Event ids: 1001
Where to look next:
- Read the registry key path: it separates a machine-wide fault from one user's profile.
- The rate is the whole signal, since one process in a loop produces thousands of records.
Related reasons:
win_user_profile_load_failed: the broader profile-load failure this registry damage can also cause
Fields it can set: win.eventlog.management.locale_registry_key
The calling process continues with a default locale, so this is evidence of damage rather than an outage.
Ask this feed a question
Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.