Merge branch 'master' into Ashok-Lobo-5358843-files151to175

This commit is contained in:
Gary Moore
2021-09-21 18:33:15 -07:00
committed by GitHub
169 changed files with 868 additions and 1008 deletions

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4777(F): The domain controller failed to validate the credentials for an account.
**Applies to**
- Windows 10
- Windows Server 2016
Currently this event doesnt generate. It is a defined event, but it is never invoked by the operating system. [4776](event-4776.md) failure event is generated instead.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4778(S): A session was reconnected to a Window Station.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4778.png" alt="Event 4778 illustration" width="449" height="491" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4779(S): A session was disconnected from a Window Station.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4779.png" alt="Event 4779 illustration" width="449" height="504" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4780(S): The ACL was set on accounts which are members of administrators groups.
**Applies to**
- Windows 10
- Windows Server 2016
Every hour, the domain controller that holds the primary domain controller (PDC) Flexible Single Master Operation (FSMO) role compares the ACL on all security principal accounts (users, groups, and machine accounts) present for its domain in Active Directory and that are in administrative or security-sensitive groups and which have AdminCount attribute = 1 against the ACL on the [AdminSDHolder](/previous-versions/technet-magazine/ee361593(v=msdn.10)) object. If the ACL on the principal account differs from the ACL on the AdminSDHolder object, then the ACL on the principal account is reset to match the ACL on the AdminSDHolder object and this event is generated.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4781(S): The name of an account was changed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4781.png" alt="Event 4781 illustration" width="449" height="474" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4782(S): The password hash of an account was accessed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4782.png" alt="Event 4782 illustration" width="449" height="407" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4793(S): The Password Policy Checking API was called.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4793.png" alt="Event 4793 illustration" width="449" height="419" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4794(S, F): An attempt was made to set the Directory Services Restore Mode administrator password.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4794.png" alt="Event 4794 illustration" width="449" height="418" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4798(S): A user's local group membership was enumerated.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4798.png" alt="Event 4798 illustration" width="438" height="402" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4799(S): A security-enabled local group membership was enumerated.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4799.png" alt="Event 4799 illustration" width="438" height="402" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4800(S): The workstation was locked.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4800.png" alt="Event 4800 illustration" width="449" height="364" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4801(S): The workstation was unlocked.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4801.png" alt="Event 4801 illustration" width="449" height="364" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4802(S): The screen saver was invoked.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4802.png" alt="Event 4802 illustration" width="449" height="363" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4803(S): The screen saver was dismissed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4803.png" alt="Event 4803 illustration" width="449" height="363" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4816(S): RPC detected an integrity violation while decrypting an incoming message.
**Applies to**
- Windows 10
- Windows Server 2016
This message generates if RPC detected an integrity violation while decrypting an incoming message.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4817(S): Auditing settings on object were changed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4817.png" alt="Event 4817 illustration" width="616" height="480" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4818(S): Proposed Central Access Policy does not grant the same access permissions as the current Central Access Policy.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4818.png" alt="Event 4818 illustration" width="727" height="725" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4819(S): Central Access Policies on the machine have been changed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4819.png" alt="Event 4819 illustration" width="449" height="540" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4826(S): Boot Configuration Data loaded.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4826.png" alt="Event 4826 illustration" width="438" height="494" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4864(S): A namespace collision was detected.
**Applies to**
- Windows 10
- Windows Server 2016
This event is generated when a namespace collision was detected.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4865(S): A trusted forest information entry was added.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4865.png" alt="Event 4865 illustration" width="449" height="502" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4866(S): A trusted forest information entry was removed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4866.png" alt="Event 4866 illustration" width="449" height="502" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4867(S): A trusted forest information entry was modified.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4867.png" alt="Event 4867 illustration" width="449" height="502" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4902(S): The Per-user audit policy table was created.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4902.png" alt="Event 4902 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/07/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4904(S): An attempt was made to register a security event source.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4904.png" alt="Event 4904 illustration" width="449" height="462" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4905(S): An attempt was made to unregister a security event source.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4905.png" alt="Event 4905 illustration" width="449" height="458" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4906(S): The CrashOnAuditFail value has changed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4906.png" alt="Event 4906 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4907(S): Auditing settings on object were changed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4907.png" alt="Event 4907 illustration" width="643" height="542" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4908(S): Special Groups Logon table modified.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4908.png" alt="Event 4908 illustration" width="449" height="361" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4909(-): The local policy settings for the TBS were changed.
**Applies to**
- Windows 10
- Windows Server 2016
Currently this event doesnt generate. It is a defined event, but it is never invoked by the operating system.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4910(-): The group policy settings for the TBS were changed.
**Applies to**
- Windows 10
- Windows Server 2016
Currently this event doesnt generate. It is a defined event, but it is never invoked by the operating system.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4911(S): Resource attributes of the object were changed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4911.png" alt="Event 4911 illustration" width="545" height="541" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4912(S): Per User Audit Policy was changed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4912.png" alt="Event 4912 illustration" width="471" height="478" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4913(S): Central Access Policy on the object was changed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4913.png" alt="Event 4913 illustration" width="648" height="557" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4928(S, F): An Active Directory replica source naming context was established.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4928.png" alt="Event 4928 illustration" width="449" height="419" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4929(S, F): An Active Directory replica source naming context was removed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4929.png" alt="Event 4929 illustration" width="500" height="374" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4930(S, F): An Active Directory replica source naming context was modified.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4930.png" alt="Event 4930 illustration" width="448" height="333" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4931(S, F): An Active Directory replica destination naming context was modified.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4931.png" alt="Event 4931 illustration" width="500" height="374" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4932(S): Synchronization of a replica of an Active Directory naming context has begun.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4932.png" alt="Event 4932 illustration" width="774" height="363" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4933(S, F): Synchronization of a replica of an Active Directory naming context has ended.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4933.png" alt="Event 4933 illustration" width="773" height="377" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4934(S): Attributes of an Active Directory object were replicated.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates when attributes of an Active Directory object were replicated.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4935(F): Replication failure begins.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4935.png" alt="Event 4935 illustration" width="448" height="312" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4936(S): Replication failure ends.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates when Active Directory replication failure ends.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4937(S): A lingering object was removed from a replica.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates when a [lingering object](https://support.microsoft.com/kb/910205) was removed from a replica.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4944(S): The following policy was active when the Windows Firewall started.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4944.png" alt="Event 4944 illustration" width="449" height="391" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4945(S): A rule was listed when the Windows Firewall started.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4945.png" alt="Event 4945 illustration" width="449" height="354" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4946(S): A change has been made to Windows Firewall exception list. A rule was added.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4946.png" alt="Event 4946 illustration" width="449" height="350" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4947(S): A change has been made to Windows Firewall exception list. A rule was modified.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4947.png" alt="Event 4947 illustration" width="449" height="361" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4948(S): A change has been made to Windows Firewall exception list. A rule was deleted.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4948.png" alt="Event 4948 illustration" width="449" height="361" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4949(S): Windows Firewall settings were restored to the default values.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4949.png" alt="Event 4949 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4950(S): A Windows Firewall setting has changed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4950.png" alt="Event 4950 illustration" width="449" height="354" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4951(F): A rule has been ignored because its major version number was not recognized by Windows Firewall.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4951.png" alt="Event 4951 illustration" width="449" height="364" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4952(F): Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall. The other parts of the rule will be enforced.
**Applies to**
- Windows 10
- Windows Server 2016
When you create or edit a Windows Firewall rule, the settings that you can include depend upon the version of Windows you use when creating the rule. As new settings are added to later versions of Windows or to service packs for existing versions of Windows, the version number of the rules processing engine is updated, and that version number is stamped into rules that are created by using that version of Windows. For example, Windows Vista produces firewall rules that are stamped with version "v2.0". Future versions of Windows might use "v2.1", or "v3.0" to indicate, respectively, minor or major changes and additions.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4953(F): Windows Firewall ignored a rule because it could not be parsed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4953.png" alt="Event 4953 illustration" width="449" height="375" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4954(S): Windows Firewall Group Policy settings have changed. The new settings have been applied.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4954.png" alt="Event 4954 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4956(S): Windows Firewall has changed the active profile.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4956.png" alt="Event 4956 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4957(F): Windows Firewall did not apply the following rule.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4957.png" alt="Event 4957 illustration" width="449" height="365" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4958(F): Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer.
**Applies to**
- Windows 10
- Windows Server 2016
Windows Firewall with Advanced Security processed a rule that contains parameters that cannot be resolved on the local computer. The rule is therefore not enforceable on the computer and so is excluded from the runtime state of the firewall. This is not necessarily an error. Examine the rule for applicability on the computers to which it was applied.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4964(S): Special groups have been assigned to a new logon.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4964.png" alt="Event 4964 illustration" width="448" height="419" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 4985(S): The state of a transaction has changed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-4985.png" alt="Event 4985 illustration" width="468" height="473" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5024(S): The Windows Firewall Service has started successfully.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5024.png" alt="Event 5024 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5025(S): The Windows Firewall Service has been stopped.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5025.png" alt="Event 5025 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5027(F): The Windows Firewall Service was unable to retrieve the security policy from the local storage. The service will continue enforcing the current policy.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5027.png" alt="Event 5027 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5028(F): The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5028.png" alt="Event 5028 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5029(F): The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy.
**Applies to**
- Windows 10
- Windows Server 2016
Windows logs an error if either the Windows Firewall service or its driver fails to start, or if they unexpectedly terminate. The error message indicates the cause of the service failure by including an error code in the text of the message.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5030(F): The Windows Firewall Service failed to start.
**Applies to**
- Windows 10
- Windows Server 2016
Windows logs this event if the Windows Firewall service fails to start, or if it unexpectedly terminates. The error message indicates the cause of the service failure by including an error code in the text of the message.

View File

@ -10,17 +10,12 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 09/08/2021
ms.technology: mde
---
# 5031(F): The Windows Firewall Service blocked an application from accepting incoming connections on the network.
**Applies to**
- Windows 10
- Windows Server 2016
- Windows Server 2012 R2
- Windows Server 2012
<img src="images/event-5031.png" alt="Event 5031 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5032(F): Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.
**Applies to**
- Windows 10
- Windows Server 2016
Windows Firewall with Advanced Security can be configured to notify the user when an application is blocked by the firewall, and ask if the application should continue to be blocked in the future.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5033(S): The Windows Firewall Driver has started successfully.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5033.png" alt="Event 5033 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5034(S): The Windows Firewall Driver was stopped.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5034.png" alt="Event 5034 illustration" width="449" height="317" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5035(F): The Windows Firewall Driver failed to start.
**Applies to**
- Windows 10
- Windows Server 2016
Windows logs this event if Windows Firewall driver fails to start, or if it unexpectedly terminates. The error message indicates the cause of the failure by including an error code in the text of the message.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5037(F): The Windows Firewall Driver detected critical runtime error. Terminating.
**Applies to**
- Windows 10
- Windows Server 2016
Windows logs this event if Windows Firewall driver fails to start, or if it unexpectedly terminates. The error message indicates the cause of the failure by including an error code in the text of the message.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5038(F): Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
**Applies to**
- Windows 10
- Windows Server 2016
The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5039(-): A registry key was virtualized.
**Applies to**
- Windows 10
- Windows Server 2016
This event should be generated when registry key was virtualized using [LUAFV](https://blogs.msdn.com/b/alexcarp/archive/2009/06/25/the-deal-with-luafv-sys.aspx).

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5051(-): A file was virtualized.
**Applies to**
- Windows 10
- Windows Server 2016
This event should be generated when file was virtualized using [LUAFV](https://blogs.msdn.com/b/alexcarp/archive/2009/06/25/the-deal-with-luafv-sys.aspx).

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5056(S): A cryptographic self-test was performed.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates in CNG Self-Test function. This function is a Cryptographic Next Generation (CNG) function.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5057(F): A cryptographic primitive operation failed.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates in case of CNG primitive operation failure.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5058(S, F): Key file operation.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5058.png" alt="Event 5058 illustration" width="833" height="502" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5059(S, F): Key migration operation.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5059.png" alt="Event 5059 illustration" width="491" height="489" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5060(F): Verification operation failed.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates when the Cryptographic Next Generation (CNG) verification operation fails.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5061(S, F): Cryptographic operation.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5061.png" alt="Event 5061 illustration" width="486" height="489" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5062(S): A kernel-mode cryptographic self-test was performed.
**Applies to**
- Windows 10
- Windows Server 2016
This event occurs rarely, and in some situations may be difficult to reproduce.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5063(S, F): A cryptographic provider operation was attempted.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates in BCryptUnregisterProvider() and BCryptRegisterProvider() functions. These are Cryptographic Next Generation (CNG) functions.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5064(S, F): A cryptographic context operation was attempted.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates in [BCryptCreateContext](/windows/win32/api/bcrypt/nf-bcrypt-bcryptcreatecontext)() and [BCryptDeleteContext](/windows/win32/api/bcrypt/nf-bcrypt-bcryptdeletecontext)() functions. These are Cryptographic Next Generation (CNG) functions.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5065(S, F): A cryptographic context modification was attempted.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates in [BCryptConfigureContext](/windows/win32/api/bcrypt/nf-bcrypt-bcryptconfigurecontext)() function. This is a Cryptographic Next Generation (CNG) function.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5066(S, F): A cryptographic function operation was attempted.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates in [BCryptAddContextFunction](/windows/win32/api/bcrypt/nf-bcrypt-bcryptaddcontextfunction)() and [BCryptRemoveContextFunction](/windows/win32/api/bcrypt/nf-bcrypt-bcryptremovecontextfunction)() functions. These are Cryptographic Next Generation (CNG) functions.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5067(S, F): A cryptographic function modification was attempted.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates in [BCryptConfigureContextFunction](/windows/win32/api/bcrypt/nf-bcrypt-bcryptconfigurecontextfunction)() function. This is a Cryptographic Next Generation (CNG) function.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5068(S, F): A cryptographic function provider operation was attempted.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates in BCryptAddContextFunctionProvider() and BCryptRemoveContextFunctionProvider() functions. These are Cryptographic Next Generation (CNG) functions.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5069(S, F): A cryptographic function property operation was attempted.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates in [BCryptSetContextFunctionProperty](/windows/win32/api/bcrypt/nf-bcrypt-bcryptsetcontextfunctionproperty)() function. This is a Cryptographic Next Generation (CNG) function.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5070(S, F): A cryptographic function property modification was attempted.
**Applies to**
- Windows 10
- Windows Server 2016
This event generates in [BCryptSetContextFunctionProperty](/windows/win32/api/bcrypt/nf-bcrypt-bcryptsetcontextfunctionproperty)() function. This is a Cryptographic Next Generation (CNG) function.

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5136(S): A directory service object was modified.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5136.png" alt="Event 5136 illustration" width="449" height="611" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5137(S): A directory service object was created.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5137.png" alt="Event 5137 illustration" width="449" height="532" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5138(S): A directory service object was undeleted.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5138.png" alt="Event 5138 illustration" width="671" height="573" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5139(S): A directory service object was moved.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5139.png" alt="Event 5139 illustration" width="505" height="547" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5140(S, F): A network share object was accessed.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5140.png" alt="Event 5140 illustration" width="449" height="557" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5141(S): A directory service object was deleted.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5141.png" alt="Event 5141 illustration" width="449" height="549" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5142(S): A network share object was added.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5142.png" alt="Event 5142 illustration" width="449" height="406" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5143(S): A network share object was modified.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5143.png" alt="Event 5143 illustration" width="740" height="547" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5144(S): A network share object was deleted.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5144.png" alt="Event 5144 illustration" width="449" height="412" hspace="10" align="left" />

View File

@ -7,7 +7,7 @@ ms.mktglfcycl: deploy
ms.sitesec: library
ms.localizationpriority: none
author: dansimp
ms.date: 04/19/2017
ms.date: 09/08/2021
ms.reviewer:
manager: dansimp
ms.author: dansimp
@ -16,10 +16,6 @@ ms.technology: mde
# 5145(S, F): A network share object was checked to see whether client can be granted desired access.
**Applies to**
- Windows 10
- Windows Server 2016
<img src="images/event-5145.png" alt="Event 5145 illustration" width="591" height="671" hspace="10" align="left" />

Some files were not shown because too many files have changed in this diff Show More